Job Description
Summary
Are you passionate about cybersecurity, IT risk, and control assurance? Deloitte India is hiring an Assistant Manager – Cyber Risk (CRISC) for its Cyber Strategy & Transformation team based in Pune. In this cyber consulting role, you’ll lead control testing and risk assessments across cloud, SOX, and IT/IS systems. Ideal for professionals with 2–6 years of cybersecurity and IT risk experience, this opportunity offers impactful client-facing projects in a global consulting environment. CRISC, CISA, or ISO 27001 certifications are mandatory, making this a high-visibility role for cyber-savvy professionals looking to grow within Deloitte’s world-class security and risk practice.
Job Details at a Glance
| Job Title | Assistant Manager – Cyber Risk (CRISC) |
|---|---|
| Department | Cyber Strategy & Transformation – Risk Advisory |
| Entity | Deloitte Touche Tohmatsu India LLP |
| Job Location | Pune (Hybrid + Frequent Client Travel) |
| Experience Required | 2–6 Years in Cybersecurity / IT Risk / Control Testing |
| Certifications | CRISC / CISA / ISO 27001 (Mandatory), CISSP (Preferred) |
| Job Requisition ID | 86425 |
| Shift Type | Standard Business Hours |
| Tools / Frameworks | ISO 27001, NIST, COBIT, SOX, Cloud Risk, Data Controls |
Role Overview
As an Assistant Manager – Cyber Risk, you will conduct comprehensive assessments of cybersecurity controls, test IT/IS systems, evaluate SOX compliance, and collaborate with global banking and financial services clients. You’ll take a lead role in designing test plans, reviewing IT risk frameworks, and ensuring best practices are applied in line with global cyber standards.
Key Responsibilities
IT Risk and Control Testing
- Design and execute risk-based IT and Information Security control testing strategies
- Review SOX, Key, Cloud, and Data Management IT/IS controls
- Conduct walkthroughs and evidence collection with stakeholders
Risk Management & Compliance
- Perform security architecture reviews and identify gaps in existing controls
- Develop and execute test plans and scripts for DE (Design Effectiveness) and OE (Operational Effectiveness)
- Maintain up-to-date knowledge of industry standards, frameworks (e.g., ISO 27001, NIST, COBIT), and regulatory compliance
Documentation & Reporting
- Prepare detailed testing documentation, workpapers, and recommendations
- Develop reusable templates for control testing methodologies
- Create and maintain risk dashboards and internal audit reports
Stakeholder Collaboration
- Work with cross-functional teams and client representatives for control validation
- Influence stakeholders across business units and within Three Lines of Defense
- Contribute to defining and refining the client’s internal control frameworks
Required Skills & Experience
- 2–6 years of experience in Cybersecurity, Risk Management, Control Assurance, or IT Audit
- Strong command of Risk Management frameworks like ISO 27001, NIST, COBIT
- Familiarity with internal controls concepts (preventive, detective, anti-fraud, etc.)
- Experience working with global banking or financial services clients
- Excellent communication skills, both written and verbal
- Experience in regulated environments with stakeholder management across departments
- Proficiency in MS Excel, documentation tools, and reporting platforms
Preferred Certifications
✅ CRISC (Certified in Risk and Information Systems Control) – Mandatory
✅ CISA / ISO 27001 – Mandatory
✅ CISSP – Preferred
✅ Other certifications in cybersecurity, data protection, or audit – a plus
Why Deloitte?
- Work on global cyber transformation projects with top financial clients
- Be part of a purpose-driven, inclusive, and diverse work environment
- Opportunity to travel, grow, and lead in a high-impact consulting career
- Access to Deloitte’s cutting-edge technology labs and learning platforms
- Join a culture focused on innovation, leadership, and career mobility
Apply Now
Ready to elevate your cybersecurity career with Deloitte?
👉 Apply Now via Deloitte Careers Portal
Join a future-forward team that values expertise, innovation, and impact.