Deputy Manager – Cybersecurity (ISMS, GRC, ISO 27001) – Deloitte India | Delhi

September 1, 2025

Job Description

Summary

Join Deloitte India as a Deputy Manager – Cybersecurity (ISMS & GRC) based in Delhi. This is a high-impact leadership opportunity for cybersecurity professionals skilled in ISO 27001 implementation, information security governance, business continuity planning, and data privacy. If you’re passionate about securing enterprise environments and advising top-tier clients, this role empowers you to shape cybersecurity programs for some of the most influential organizations in the region.

As part of the Cyber Risk & Governance team, you’ll work on complex client environments across industries, advising on risk mitigation, regulatory compliance, and cybersecurity transformation. Deloitte offers a hybrid work model and values professionals who bring integrity, innovation, and inclusive leadership to the table.


Job Details at a Glance

Job TitleDeputy Manager – Cybersecurity (ISMS, GRC)
LocationDelhi, India
DepartmentCybersecurity – GRC & ISMS
EntityDeloitte Touche Tohmatsu India LLP
Experience Required5-10 years
EducationB.E. / B.Tech (Tier 1/2) – Computer Science, IT
Certifications (Preferred)ISO 27001 LA/LI, ISO 22301, ISO 31000, CISSP, CISA, CISM
Tools & FrameworksISO/IEC 27001, COBIT, ITIL, Data Loss Prevention, Archer
TravelOccasional travel to client locations
Work ModelHybrid (Office + Client Site Visits)
Job TypeFull-Time

Key Responsibilities

  • Lead the implementation and sustainment of ISO 27001 based Information Security Management Systems (ISMS).
  • Design and advise on Business Continuity Planning (BCP) and IT Disaster Recovery (ITDR) strategies.
  • Perform detailed cybersecurity risk assessments to identify vulnerabilities and define risk mitigation strategies.
  • Assist clients with data privacy, identity & access management, and data loss prevention initiatives.
  • Develop and implement Information Classification Frameworks for enterprise data governance.
  • Conduct vendor risk assessments, offering a holistic view of third-party cyber risks.
  • Conduct IT infrastructure audits, ensuring compliance with regulatory and industry standards.
  • Design and execute incident response plans, change management policies, and backup protocols.
  • Engage with clients on data masking, encryption, redaction, and secure media handling practices.
  • Serve as a subject matter expert or technical lead on cybersecurity and privacy transformation projects.
  • Provide mentorship to junior team members and contribute to practice development and proposal efforts.

Required Skills & Competencies

  • Strong working knowledge of ISO/IEC 27001, COBIT, ITIL, and related frameworks.
  • Experience with data protection technologies – encryption, masking, redaction.
  • Proficiency in tools such as Archer, OpenPages, or similar GRC platforms.
  • Understanding of data privacy laws, cybersecurity regulations, and risk management standards.
  • Excellent communication and stakeholder management skills.
  • Capability to manage client relationships, define scopes, and deliver engagement outcomes independently.
  • Strategic thinking with a business-first approach to cybersecurity.

Preferred Certifications

  • ISO 27001 Lead Auditor / Lead Implementer (LA/LI)
  • ISO 22301 LA/LI, ISO 31000 LA/LI
  • CISSP, CISA, CISM, GSEC, GCIH, CEH, LPT, CCSK

Why Join Deloitte Cybersecurity Team?

  • Global Exposure: Work with leading clients across industries and geographies.
  • Learning & Growth: Access to cutting-edge learning, certifications, and leadership programs.
  • Inclusive Culture: Thrive in a people-first culture that values diversity and collaboration.
  • Impact-Driven: Make a measurable impact on client security posture and regulatory readiness.
  • Hybrid Work Flexibility: Blend office presence with the autonomy to manage remote work.

Apply Now

Ready to accelerate your cybersecurity career at Deloitte?

👉 Click here to apply on the official Deloitte Careers Page
Explore your potential and become a trusted cybersecurity leader.