29 Sep
|
Deloitte Shared Services India
|
Delhi
29 Sep
Deloitte Shared Services India
Delhi
Experience: 6-9 Years
Role: Cyber Strategy, GRC & Risk Advisory
Travel: Willingness to travel and undertake extended client assignments across Saudi Arabia and UAE.
Job Overview
We are looking for an experienced Cybersecurity professional to join our Cyber Strategy & Transformation team. The role involves leading cybersecurity advisory, Governance, Risk & Compliance (GRC), cyber risk management, security governance, and transformation engagements across diverse client environments.
Key Responsibilities
- Lead and independently manage Cybersecurity Advisory, GRC, Cyber Risk Management, and Cyber Transformation engagements.
- Lead cybersecurity risk assessments and Cyber Risk Management Framework (CRMF) engagements across IT, OT, Cloud, IoT, and emerging technology environments.
- Conduct and manage cybersecurity maturity assessments, security control reviews, compliance assessments, audits, and third-party risk assessments.
- Lead ISO/IEC 27001 implementation, gap assessments, internal assessments, certification readiness, and continual improvement initiatives.
- Develop and enhance cyber risk methodologies, governance frameworks, policies, standards, procedures, and risk treatment frameworks.
- Assess cybersecurity controls against ISO/IEC 27001, NIST CSF, CIS Controls, and applicable regulatory requirements.
- Identify cybersecurity risks, control gaps, compliance deficiencies, and areas for improvement, providing practical and business-aligned remediation recommendations.
- Facilitate client workshops, stakeholder interviews, risk discussions, and executive-level presentations.
- Develop and present cybersecurity roadmaps, risk reports,
governance frameworks, and executive PowerPoint presentations.
- Review risk registers, assessment reports, governance documentation, management presentations, and other client deliverables for quality and consistency.
- Manage engagement workstreams, timelines, resources, stakeholder expectations, and overall deliverable quality.
- Mentor and guide junior consultants while providing technical direction and reviewing work products.
- Collaborate with Information Security, Risk, Compliance, Internal Audit, Technology, and Business teams to deliver cybersecurity outcomes.
- Support proposals, RFPs, solution design, client pursuits, thought leadership, and business development initiatives.
- Stay updated on emerging cybersecurity threats, regulations, industry standards, and leading practices.
- Leverage AI-enabled tools and automation to improve engagement efficiency and develop awareness of AI governance, AI security risks, and evolving AI regulations.
Required Skills & Experience
- 6-9 years of relevant experience in Cybersecurity, Cyber Risk, GRC, Technology Risk, IT Audit, Information Security, or Cybersecurity Consulting.
- Strong experience in Cybersecurity Advisory, GRC, Cyber Risk Management, and Security Governance.
- Hands-on experience leading cybersecurity assessments, risk assessments, maturity assessments, compliance reviews, audits, and governance initiatives.
- Strong knowledge of:
- ISO/IEC 27001
- NIST Cybersecurity Framework (CSF)
- CIS Controls
- Cyber Risk Management
- Security Controls
- Governance & Compliance
- Experience developing cyber risk methodologies, policies, standards, procedures, governance frameworks, and risk treatment approaches.
- Solid client-facing experience with stakeholder management, workshops, presentations, and executive-level communication.
- Experience managing project workstreams, timelines, deliverables, and junior team members.
- Strong analytical, problem-solving, report writing, and presentation skills.
- Proficiency in creating executive-level PowerPoint presentations, risk dashboards, strategic roadmaps, and management reports.
Preferred Experience
- Experience with Big 4, management consulting, or cybersecurity consulting firms.
- Experience across IT, OT, Cloud, IoT, and emerging technologies.
- Experience with ISO 27001 implementation, certification readiness, and internal assessments.
- Experience with third-party risk assessments and cybersecurity compliance programs.
- Exposure to cybersecurity transformation and maturity improvement programs.
- Experience with AI Governance / AI Security initiatives.
Preferred Certifications
- CISSP
- CISM
- CISA
- CRISC
- ISO/IEC 27001 Lead Implementer
- ISO/IEC 27001 Lead Auditor
Added Advantage:
- ISO/IEC 42001
- NIST AI RMF
- AI Governance / AI Security certifications
📌 TPRM (Delhi)
🏢 Deloitte Shared Services India
📍 Delhi