Manager-NSE Cyber Security Risk Specialist (T2)/CISO/ITS
Your opportunity
Join our innovative, creative, and inclusive CISO team - a world-class operation with extensive knowledge and experience. You will interface with business and technical teams to bring about change and influence across the entire world of Deloitte. Apply your skills to make things happen and be a part of a great team that is passionate about serving a great purpose.
Work you'll do:
As a Cybersecurity Risk Manager, you will lead the development, implementation, and oversight of the organization’s cybersecurity risk management program. You will be responsible for managing a team, driving risk assessment initiatives, ensuring regulatory compliance, and partnering with business and IT leaders to embed security into business processes. This role requires strong leadership, strategic thinking, and deep expertise in cybersecurity risk management frameworks and controls.
Location: Hyderabad
Work shift Timings: 02:00 PM to 11:00 PM
Role Requirement
- Strong experience in Information Security concepts, including Governance, Risk, and Compliance, with hands-on involvement in risk management activities such as conducting risk assessments.
- Demonstrated ability to independently perform risk assessments and provide guidance to teams.
- Solid understanding of compliance-related certifications (e.g., ISO, SOC, GDPR, Cyber Essentials) as well as regional regulatory requirements and audit processes.
- In-depth knowledge of security best practices, ensuring adherence to confidentiality, integrity, and availability principles.
- Responsible for the end-to-end cybersecurity risk ecosystem, ensuring a Risk framework that addresses the firm’s strategic CS operational risks.
- Familiarity with OWASP Top Ten vulnerabilities, related tools, and methodologies.
- Basic understanding of project management principles.
- Understanding of service desk tools and workflows.
- Ability to clearly articulate how process changes can lead to improvements.
- Represents the team effectively in meetings with both internal and external stakeholders.
- Strong critical thinking, analytical, and communication skills, with the ability to engage diverse audiences.
- Methodical and logical thinker, capable of problem-solving and identifying solutions with minimal supervision.
- Self-starter who can multitask and thrive in an agile environment.
Role & Responsibilities:
- Support the assessment of current technology infrastructure and applications to identify information security and compliance risk areas.
- Proactively identify security and compliance-related risks to support key business initiatives.
- Articulate remediation requirements in clear, audience-appropriate terms.
- Build business cases tailored to different audiences, including mid-level and senior management.
- Report regularly to the Deputy CISO and CISO on the status of all risk-related activities, including process metrics, issues, and remediation actions.
- Identify key stakeholders and audiences, build consensus, and handle objections to drive transformation.
- Conduct regular meetings and establish a shared vision within the team.
- Collaborate with the wider UK Information Security team, UK Deloitte Business Security, UK IT Services, NSE, and Global Information Security and Risk teams.
- Liaise with risk functions across the information security team and 2nd line functions to support risk governance, process improvement, and reporting obligations.
- Build training materials and conduct awareness sessions on changes to existing processes.
- Liaise with support teams as needed to facilitate training and awareness initiatives.
- Ensure all team members have access to learning and development opportunities to maximize performance.
- Demonstrate proactive responsibility by owning, following up, and resolving issues to positively impact team delivery and inspire others.
- Lead one of the USI councils, such as Continuous Service Improvement, Learning and Development, Process Risk Assessment, or Business Impact Analysis.
- Produce high-quality KPIs and KRIs for governing and managing risk findings.
- Develop management reports, including metric dashboards summarizing KPIs and KRIs, for submission to the firm’s security governance and risk committees.
· Prepare weekly/monthly reports capturing key business trends, highlights, lowlights, and metrics for Risk programs including status updates, recommended actions, and supporting evidence.
Tools and Technologies
- Service Now
- Ms Office (Word, PPT, Visio, Excel)
- RSA Archer or similar
- MS Teams
Qualifications
- Any full time Graduation in Computer Science/ Information Security/ any Engineering stream/ others
- 10 to 14 years’ experience in a similar role and Enterprise organisation
Technical Certifications
- Must have ISO27001, CISA, CRISC or equivalent
- Good to have ITIL v4 Foundation, CISSP, CISM, CCSP, PMP or equivalent desirable