21 Aug
|
Deloitte Shared Services India
|
Bengaluru
21 Aug
Deloitte Shared Services India
Bengaluru
Cyber TPRM- DM
Experience: 6+ Years
Role: Cyber TPRM
Domain: Cybersecurity, Third Party Risk Management
Job Overview
We are looking for a Cyber TPRM qualified with strong experience in Third Party Risk Management, Technology Risk, cybersecurity assessments, control reviews, and risk advisory. The role will involve leading Cyber TPRM assessments and technology risk engagements, developing risk management frameworks, assessing third-party security posture, and working with clients and stakeholders to identify and mitigate cybersecurity risks.
Key Responsibilities
- Lead Cyber TPRM assessments, technology risk reviews, security audits, and advisory engagements.
- Assess third-party/vendor cybersecurity posture and identify technology and cyber risks.
- Develop and enhance TPRM policies, procedures, SOPs, governance frameworks, operating models, and playbooks.
- Manage the complete third-party risk lifecycle, including:
- Vendor onboarding
- Due diligence
- Risk assessment
- Risk tiering
- Contracting
- Ongoing monitoring
- Periodic reassessment
- Renewal and offboarding
- Define and implement cyber risk tiering, assessment criteria, escalation mechanisms, exception management, and reporting frameworks.
- Perform cybersecurity control assessments across cloud, infrastructure, applications, databases, and networks.
- Evaluate controls related to IAM, encryption, logging & monitoring, vulnerability management, patch management, backup security, and incident response.
- Conduct control maturity and compliance assessments against ISO 27001, NIST CSF, NIST SP 800-53, CIS Controls, PCI DSS, ISO 22301, ISO 27701, COBIT, SOC 2, and CSA CCM.
- Interpret regulatory requirements related to outsourcing, information security, data protection, and operational resilience.
- Perform quality reviews of engagement deliverables and ensure adherence to quality standards.
- Support RFPs, proposals, solution development, and business development activities.
- Mentor and guide team members across TPRM assessments, audits, and advisory engagements.
- Drive capability-building initiatives around Cyber GRC automation, analytics, continuous monitoring, and AI-enabled risk management.
Required Skills
- 6+ years of experience in Cybersecurity, Cyber TPRM, Third Party Risk Management, Technology Risk, IT Risk Consulting, or Information Security.
- Strong hands-on experience in Third Party Risk Management / Cyber TPRM.
- Experience conducting third-party/vendor security assessments and cyber risk assessments.
- Strong understanding of technology and cybersecurity controls.
- Experience in developing or implementing TPRM frameworks, policies, procedures, SOPs, and governance models.
- Strong knowledge of vendor risk lifecycle management and risk tiering methodologies.
- Experience with control assessments, maturity assessments, risk identification, remediation, and exception management.
- Strong understanding of cybersecurity frameworks including ISO 27001, NIST CSF, CIS Controls, PCI DSS, and ISO 22301.
- Experience assessing security controls across cloud, applications, infrastructure, databases, and networks.
- Strong client-facing, stakeholder management, analytical, reporting, and team leadership skills.
Preferred Certifications
- CISA
- CRISC
- CISSP
- ISO 27001 Lead Auditor
- ISO 27001 Lead Implementer
- ISO 22301 Lead Auditor / Lead Implementer
- ISO 42001
Education
- Bachelors degree in Engineering, Computer Science, Information Technology, Cybersecurity, or a related discipline.
- A Masters degree (MBA/M.Tech/MS) is an added advantage.
📌 TPRM (Bengaluru)
🏢 Deloitte Shared Services India
📍 Bengaluru