02 Oct
|
Deloitte Shared Services India
|
Bengaluru
02 Oct
Deloitte Shared Services India
Bengaluru
Role Overview
We are looking for an Information Security professional with hands-on experience in ISO 27001-based ISMS implementation, information security risk assessments, control assessments, and security governance.
The candidate will support clients in assessing their information security posture, identifying gaps and risks, implementing security controls, and developing practical remediation solutions. The role also involves vendor risk assessments, information classification, security governance, and client stakeholder management.
Key Responsibilities
- Support ISO 27001-based ISMS implementation and sustenance.
- Assess client information security posture and identify gaps, risks, and control deficiencies.
- Conduct security assessments, risk assessments, and gap analyses across IT systems, applications, and networks.
- Assist clients in reviewing and implementing Information Security controls covering:
- Change Management
- Incident Management
- Backup Management
- User Identity & Access Management
- Antivirus Management
- SLA Performance & Monitoring
- Media Handling & Exchange of Information
- Physical & Environmental Security
- Media & Information Handling
- Conduct vendor/Third-Party Risk Assessments and assess outsourcing-related information security risks.
- Assist clients in developing and implementing Information Classification frameworks.
- Develop and recommend security measures, policies, procedures, and remediation actions.
- Perform compliance and control assessments against ISO 27001, NIST CSF, PCI-DSS, CIS Controls, and other applicable frameworks.
- Collaborate with cross-functional teams to implement cybersecurity best practices and address identified vulnerabilities.
- Manage day-to-day client relationships and stakeholder discussions.
- Prepare assessment reports, recommendations, presentations, and engagement deliverables.
- Work independently on assigned projects with limited supervision.
- Support proposal development, business development, and identification of additional client opportunities.
- Contribute to knowledge development, people development, and practice initiatives.
- Stay updated on emerging cyber threats, security trends, and regulatory requirements.
Mandatory Skills
- ISO 27001 / ISMS Implementation
- Information Security Risk Assessment
- Security Controls Assessment
- Gap Assessment / Risk Assessment
- Information Security Governance
- Cybersecurity Risk Management
- Working knowledge of NIST / PCI-DSS / CIS Controls
- Knowledge of IT General Controls (ITGC)
- Identity & Access Management
- Third-Party Risk Management / Vendor Risk Assessment
- Information Security policies, procedures, and standards
- Solid analytical, documentation, and communication skills
- Client/stakeholder management
Good to Have
- Information Classification
- Security Architecture Review
- Network Security
- Regulatory Compliance
- Security Governance
- Incident Management
- Change Management
- Backup & Recovery Controls
- Physical & Environmental Security
- Application/System Security Assessments
Preferred Certifications
- CISSP
- CISA
- CRISC
- CEH
- ISO 27001-related certifications
Education Bachelors degree in Computer Science, Information Security, Information Technology, or a related field, or equivalent experience.
📌 ISO (Bengaluru)
🏢 Deloitte Shared Services India
📍 Bengaluru