Associate Director – GRC | Cyber Strategy & Transformation | Pune

September 17, 2025

Job Description

Job Requisition ID: 87019
Entity: Deloitte Touche Tohmatsu India LLP
Location: Pune, India
Date Posted: September 16, 2025


Job Summary

Deloitte is hiring an Associate Director – Governance, Risk, and Compliance (GRC) within the Cyber Strategy & Transformation practice. In this leadership role, you will be responsible for designing, leading, and optimizing enterprise-wide cybersecurity GRC programs across global clients. You will manage compliance with frameworks such as ISO 27001, NIST CSF, COBIT, COSO, and oversee enterprise risk management (ERM), third-party risk, regulatory compliance, and audit functions.

This position requires a blend of technical GRC expertise, regulatory knowledge, leadership skills, and client-facing experience to help organizations embed a risk-aware culture, mitigate cyber threats, and align with global compliance requirements.


Key Responsibilities

  • Lead the design and implementation of enterprise-wide GRC strategies using ISO 27001, NIST CSF, COBIT, COSO, ITIL and other frameworks.
  • Provide strategic oversight for GRC programs, compliance initiatives, and risk governance across geographies.
  • Drive risk assessments, compliance audits, policy development, and regulatory alignment with standards like SOX, GDPR, HIPAA, PCI DSS, India DPDP, DORA, SEC Cyber.
  • Oversee third-party risk management (TPRM), including vendor due diligence, assessments, contracts, and monitoring.
  • Manage internal and external cybersecurity audits (planning, control testing, remediation, and reporting).
  • Develop and present executive dashboards, KRIs, risk heatmaps, and board-level compliance reporting.
  • Lead business development efforts, including RFP/RFI responses, client presentations, and proposal development.
  • Optimize and manage GRC platforms (RSA Archer, ServiceNow GRC, MetricStream) for automation and reporting.
  • Advise leadership on emerging cybersecurity regulations, compliance roadmaps, and impact assessments.
  • Mentor, guide, and scale high-performing GRC teams, ensuring continuous learning and talent development.
  • Promote cybersecurity awareness and embed a risk-aware culture across business and technology functions.

Required Qualifications

  • Bachelor’s degree in IT, Computer Science, Cybersecurity, or related field; advanced degrees preferred.
  • 8+ years of progressive experience in cybersecurity, GRC, risk management, or IT audit, including 3–5 years in leadership or client-facing roles.
  • Strong expertise with NIST, ISO 27001, COBIT, COSO, ITIL, ITGC controls.
  • Hands-on experience with regulatory compliance across Indian and global landscapes.
  • Demonstrated ability to lead cross-functional GRC projects and deliver measurable outcomes.
  • Experience with GRC tools (RSA Archer, ServiceNow GRC, MetricStream).
  • Strong stakeholder management, communication, and presentation skills.
  • Certifications such as CISA, CRISC, CISSP, ISO 27001 LA/LI highly preferred.

Preferred Skills

  • Experience in cybersecurity awareness programs and change management.
  • Knowledge of cloud security governance and data privacy frameworks.
  • Familiarity with business continuity & disaster recovery (BC/DR) practices.
  • Experience advising during cloud migrations, M&A, or new technology rollouts.
  • Strong business acumen with ability to influence senior leadership and boards.

Location & Work Mode

  • Base Location: Pune, India
  • Work Mode: Work from Office
  • Travel: Frequent travel to client locations

Leadership Expectations

As an Associate Director at Deloitte, you will be expected to:

  • Lead with integrity, inclusion, and empathy.
  • Drive strategic thinking and deliver client-focused business outcomes.
  • Build and mentor diverse, high-performing teams.
  • Manage change, quality, and risk with resilience and precision.
  • Leverage technology and analytics for impactful solutions.
  • Demonstrate strong executive presence and communication skills.

Why Deloitte?

  • Work with global clients on large-scale cybersecurity transformation projects.
  • Be part of a collaborative, innovative, and inclusive culture.
  • Access to continuous learning programs, leadership pathways, and certifications.
  • Opportunity to influence board-level cybersecurity strategies.
  • Comprehensive employee well-being and career growth programs.

Apply Now

Make an impact that matters. Apply today for the Associate Director – GRC (Cyber Strategy & Transformation) role at Deloitte South Asia.

👉 Apply on Deloitte Careers Portal