Job Description
Job Requisition ID: 87019
Entity: Deloitte Touche Tohmatsu India LLP
Location: Pune, India
Date Posted: September 16, 2025
Job Summary
Deloitte is hiring an Associate Director – Governance, Risk, and Compliance (GRC) within the Cyber Strategy & Transformation practice. In this leadership role, you will be responsible for designing, leading, and optimizing enterprise-wide cybersecurity GRC programs across global clients. You will manage compliance with frameworks such as ISO 27001, NIST CSF, COBIT, COSO, and oversee enterprise risk management (ERM), third-party risk, regulatory compliance, and audit functions.
This position requires a blend of technical GRC expertise, regulatory knowledge, leadership skills, and client-facing experience to help organizations embed a risk-aware culture, mitigate cyber threats, and align with global compliance requirements.
Key Responsibilities
- Lead the design and implementation of enterprise-wide GRC strategies using ISO 27001, NIST CSF, COBIT, COSO, ITIL and other frameworks.
- Provide strategic oversight for GRC programs, compliance initiatives, and risk governance across geographies.
- Drive risk assessments, compliance audits, policy development, and regulatory alignment with standards like SOX, GDPR, HIPAA, PCI DSS, India DPDP, DORA, SEC Cyber.
- Oversee third-party risk management (TPRM), including vendor due diligence, assessments, contracts, and monitoring.
- Manage internal and external cybersecurity audits (planning, control testing, remediation, and reporting).
- Develop and present executive dashboards, KRIs, risk heatmaps, and board-level compliance reporting.
- Lead business development efforts, including RFP/RFI responses, client presentations, and proposal development.
- Optimize and manage GRC platforms (RSA Archer, ServiceNow GRC, MetricStream) for automation and reporting.
- Advise leadership on emerging cybersecurity regulations, compliance roadmaps, and impact assessments.
- Mentor, guide, and scale high-performing GRC teams, ensuring continuous learning and talent development.
- Promote cybersecurity awareness and embed a risk-aware culture across business and technology functions.
Required Qualifications
- Bachelor’s degree in IT, Computer Science, Cybersecurity, or related field; advanced degrees preferred.
- 8+ years of progressive experience in cybersecurity, GRC, risk management, or IT audit, including 3–5 years in leadership or client-facing roles.
- Strong expertise with NIST, ISO 27001, COBIT, COSO, ITIL, ITGC controls.
- Hands-on experience with regulatory compliance across Indian and global landscapes.
- Demonstrated ability to lead cross-functional GRC projects and deliver measurable outcomes.
- Experience with GRC tools (RSA Archer, ServiceNow GRC, MetricStream).
- Strong stakeholder management, communication, and presentation skills.
- Certifications such as CISA, CRISC, CISSP, ISO 27001 LA/LI highly preferred.
Preferred Skills
- Experience in cybersecurity awareness programs and change management.
- Knowledge of cloud security governance and data privacy frameworks.
- Familiarity with business continuity & disaster recovery (BC/DR) practices.
- Experience advising during cloud migrations, M&A, or new technology rollouts.
- Strong business acumen with ability to influence senior leadership and boards.
Location & Work Mode
- Base Location: Pune, India
- Work Mode: Work from Office
- Travel: Frequent travel to client locations
Leadership Expectations
As an Associate Director at Deloitte, you will be expected to:
- Lead with integrity, inclusion, and empathy.
- Drive strategic thinking and deliver client-focused business outcomes.
- Build and mentor diverse, high-performing teams.
- Manage change, quality, and risk with resilience and precision.
- Leverage technology and analytics for impactful solutions.
- Demonstrate strong executive presence and communication skills.
Why Deloitte?
- Work with global clients on large-scale cybersecurity transformation projects.
- Be part of a collaborative, innovative, and inclusive culture.
- Access to continuous learning programs, leadership pathways, and certifications.
- Opportunity to influence board-level cybersecurity strategies.
- Comprehensive employee well-being and career growth programs.
Apply Now
Make an impact that matters. Apply today for the Associate Director – GRC (Cyber Strategy & Transformation) role at Deloitte South Asia.