Assistant Manager – Cybersecurity Governance, Risk - Deloitte Support Services India Private Limited
In your capacity as an Assistant Manager within the Global Cybersecurity Governance, Risk & Compliance (GRC) Audit & Certification (A&C) team at Deloitte Technology (DT), you support DT in achieving and sustaining compliance with external standards, including ISO 27001:2022, SOC 2, and other relevant information security frameworks and standards
Work you’ll do
Role Description
- Your core responsibilities include:
- Prepare audit scope and statement of applicability for internal and external audits.
- Plan and coordinate internal and external audits.
- Identify appropriate controls and establish control ownership.
- Define guidance on control implementation and operation to meet audit requirements.
- Review design and effectiveness of our Information Security Management System.
- Engage with owners of policy, risk owners, controls and control operators to gather evidence.
- Support definition and implementation of policy, process, and procedure to improve operations.
- Interface and engage with various service assurance teams and internal stakeholders for audits.
- Collaborate with auditors to review evidence and finalize the audit report and findings.
- Facilitate remediation plans and closure of identified issues with operational teams.
- Create and secure buy-in for the management response for identified issues.
- In addition to the above-mentioned key responsibilities, you are also expected to:
- Synergize with second line of defense to perform root-cause-analysis and identify improvements.
- Performing risk assessment and identifying systemic risks at application level.
- Contribute to continuous improvement of ISMS and related processes.
- Provide input and insights for ISMS Management Review.
- Coordinate and contribute to internal governance forums like ISMS Security Forum.
- Generate insights and communicate effectiveness of control design and operation.
- Support technology aligned improvement initiatives to reduce operational risk
The Team
Digital Collaboration Delivery group develops custom products, applications and services for Deloitte professionals globally. As a team we are here to delight customers by embracing design thinking, agility, innovation, and a customer first focus. support.
Location: Hyderabad
Work shift Timings: 11 AM to 8 PM
Qualifications
- Bachelor’s degree or equivalent.
- Any ONE of the professional Certification as ISO 27001 Lead Auditor, CISA, CRISC, CISSP
Experience
- 7+ years of experience in information security management, risk management, and audits.
- Minimum of 4 years of experience in auditing at least one standard - ISO 27001, ISO 27017, SOC2.
- Demonstrated experience in conducting internal and external audits.
- Involvement with all stages of audit – from planning to closure.
- Experience with external auditors like BSI, TUV, and other global quality registrars is preferred.
- Experience with complex global operations for large enterprises is preferred.
- Experience with audit tools and automation