Job Description
Summary
Deloitte India is hiring an Assistant Manager – Cyber TPRM (Third-Party Risk Management) for its Risk Advisory – Cyber team in Mumbai. This role requires 3–5+ years of experience in third-party risk management, IT audits, cloud security, and information risk management. Ideal candidates will bring security certifications (CISSP, CISA, CISM, ISO27001, CEH) and expertise in ISMS, vendor risk assessments, and ISO22301 audits. Join Deloitte, a global leader in professional services, and build a career where your cybersecurity expertise directly helps clients manage risk and compliance in a digital-first world.
Job Details
| Job Title | Assistant Manager – Cyber TPRM |
|---|---|
| Company | Deloitte Touche Tohmatsu India LLP |
| Location | Mumbai (Work from office) |
| Entity | Risk Advisory – Cyber |
| Designation | Assistant Manager |
| Experience Required | 3–5+ years in Cybersecurity / TPRM |
| Key Skills | ISMS, TPRM, IT Audit, Cloud Security, ISO22301 |
| Certifications Preferred | CISSP, CISA, CISM, CEH, CBCI, ISO27001 |
| Employment Type | Full-Time |
Responsibilities
As an Assistant Manager – Cyber TPRM, you will:
- Conduct ISMS and Third-Party Risk Assessments for clients.
- Liaise with compliance, audit, and regulatory teams to gather requirements.
- Perform risk assessments and audits across people, processes, and technology.
- Identify gaps, risks, and opportunities in client information security programs.
- Document audit findings, recommendations, and compensating controls in reports.
- Collaborate with engagement teams to develop vendor evaluation models.
- Manage full lifecycle of assessments/audits: planning, execution, reporting, and quality review.
- Guide junior team members and provide expertise on complex risk issues.
- Engage with clients to ensure timely delivery and stakeholder satisfaction.
Required Skills & Experience
- 3–5+ years of relevant experience in:
- Third-party/vendor risk management
- IT audits and cloud security
- Information risk management & infrastructure/application security
- Experience with ISO22301 implementation and audits.
- Strong knowledge of data protection, privacy risks, and control frameworks for TPRM.
- Excellent documentation, presentation, and client-facing communication skills.
- Highly motivated and adaptable in cross-functional, cross-cultural environments.
Preferred Certifications
- CISSP / CISA / CISM / CEH
- ISO27001 Lead Auditor/Implementer
- CBCI / CBCP / ISO22301 LI or LA
- Offensive Security Certified Professional (OSCP)
Why Join Deloitte?
- Work with global clients on cutting-edge cybersecurity and risk advisory projects.
- Opportunity to lead vendor security assessments and influence enterprise risk programs.
- Inclusive, collaborative culture that values diverse skills and leadership at every level.
- Career growth via Deloitte’s structured upskilling, certifications, and leadership development.
- Competitive salary, global exposure, and a people-first work environment.
Apply Now
Be part of Deloitte’s mission to deliver cyber resilience and secure digital transformation.