Job Description
Summary
Deloitte India is seeking an experienced Manager – Risk Management in Pune within the Cyber Strategy & Transformation (CST) practice. This role is ideal for professionals specializing in cybersecurity governance, risk management, and compliance (GRC). As a Cybersecurity GRC Manager, you will lead enterprise-wide risk assessments, compliance audits, third-party risk management programs, and cybersecurity control frameworks. The position requires expertise in ISO 27001, NIST CSF, COBIT, COSO, and other global frameworks, along with experience in executive reporting, stakeholder management, and program delivery. This is an excellent opportunity to drive cyber resilience, regulatory compliance, and secure digital transformations for global organizations.
Job Details at a Glance
| Key Information | Details |
|---|---|
| Job Title | Manager – Risk Management |
| Location | Pune |
| Department / Domain | Cyber Strategy & Transformation (CST) |
| Experience Required | 8–14 years (3–5 years in leadership/client-facing roles) |
| Shift | Day Shift |
| Tools / Technologies | RSA Archer, ServiceNow GRC, MetricStream |
| Designation | Manager |
| Entity | Deloitte Touche Tohmatsu India LLP |
Key Responsibilities
- Lead the design, implementation, and management of enterprise GRC frameworks (ISO 27001, NIST CSF, COBIT, COSO) to ensure regulatory compliance and cyber risk mitigation.
- Drive risk assessments, compliance audits, and policy development across cybersecurity, IT, and business functions.
- Supervise GRC teams and mentor staff, fostering a culture of risk awareness and collaboration.
- Manage third-party risk management (TPRM) programs, including vendor assessments, contract reviews, and ongoing monitoring.
- Lead internal and external cybersecurity audits, coordinating evidence collection, issue remediation, and reporting.
- Develop executive dashboards, risk heatmaps, KPIs, and board-level reporting for leadership visibility.
- Provide guidance on emerging cybersecurity regulations and frameworks, translating requirements into actionable programs.
- Support business development by contributing to RFP/RFI responses, proposals, and client presentations.
- Collaborate with cross-functional stakeholders including Cybersecurity, IT, Legal, Audit, and Business Units.
Skills & Competencies
- Expertise in enterprise GRC, risk management, and compliance frameworks.
- Strong knowledge of Indian and global cybersecurity regulations (SOX, GDPR, HIPAA, PCI DSS, DPDP, DORA, SEC cyber disclosure).
- Experience with GRC platforms such as RSA Archer, ServiceNow GRC, and MetricStream.
- Excellent stakeholder management, communication, and executive presentation skills.
- Ability to lead teams, manage complex projects, and deliver outcomes under tight deadlines.
- Strong analytical and strategic thinking skills for cybersecurity and risk management initiatives.
Qualifications
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or related field.
- Advanced certifications preferred: CISA, CRISC, CISSP, ISO 27001 Lead Auditor/Implementer.
- 8–14 years of relevant experience, including 3–5 years in leadership or client-facing roles.
- Proven track record in GRC program execution, audit management, and risk assessment.
- Hands-on experience with cybersecurity frameworks, regulatory compliance, and TPRM programs.
Why Join Deloitte Cyber Strategy & Transformation?
- Lead enterprise cybersecurity programs across global organizations.
- Drive risk-aware culture and secure digital transformations.
- Collaborate with high-performing teams and cross-functional stakeholders.
- Access career growth, mentorship, and continuous learning opportunities.
Apply Now
Advance your career as a Manager – Risk Management at Deloitte India.
Apply now on the official Deloitte Careers page