Job Description
Summary
Deloitte India is hiring a Cybersecurity GRC Consultant in Pune. This role offers an exciting opportunity for professionals in Governance, Risk, and Compliance (GRC) to support cybersecurity frameworks, risk management, and regulatory compliance initiatives. As a Cybersecurity GRC Consultant, you will assist in implementing standards such as ISO 27001, NIST, SOC 2, and COBIT, perform risk assessments, and ensure alignment between business objectives and security best practices. This role is ideal for candidates with 1–5 years of experience in cybersecurity, IT audit, risk management, or compliance, looking to grow in a collaborative and fast-paced environment.
Job Details at a Glance
| Job Title | Cybersecurity GRC Consultant |
|---|---|
| Location | Pune, India |
| Shift / Work Mode | Office-based, frequent client travel |
| Experience Required | 1–5 Years |
| Education | Bachelor’s in IT, Cybersecurity, Computer Science, or related field |
| Key Skills & Tools | GRC, ISO 27001, NIST, SOC 2, ITGC, Risk Assessment, Compliance, Archer, ServiceNow GRC, Excel |
| Certifications (Optional) | ISO 27001 Foundation, CISA (Beginner), CompTIA Security+ |
| Job Requisition ID | 82679 |
| Entity | Deloitte Touche Tohmatsu India LLP |
Key Responsibilities
As a Cybersecurity GRC Consultant, your main responsibilities will include:
- Assist in designing, implementing, and maintaining GRC frameworks (ISO 27001, NIST, COBIT).
- Support cybersecurity policy creation, updates, and control documentation.
- Conduct IT and cybersecurity risk assessments and maintain risk registers.
- Support internal and external audits, including control testing and evidence collection.
- Perform initial third-party risk assessments and due diligence documentation.
- Track audit findings and monitor remediation efforts to closure.
- Prepare GRC dashboards and reports for stakeholders.
- Ensure compliance with global cybersecurity regulations (SOX, GDPR, DPDP, PCI-DSS).
- Collaborate with IT, legal, privacy, and compliance teams to strengthen cyber risk posture.
- Participate in security awareness campaigns and staff training initiatives.
- Work with GRC tools such as Archer, ServiceNow GRC, or Excel-based trackers to manage workflows.
Skills Required
Primary Skills:
- Governance, Risk & Compliance (GRC)
- Information Security Policies & Standards
- IT Risk Assessment
- ISO 27001 / NIST / SOC 2 Frameworks
- Regulatory Compliance (SOX, GDPR, PCI-DSS, DPDP)
- ITGC & Control Testing
- Documentation & Reporting
- Third-Party Risk Support
- Cybersecurity Awareness Support
Secondary Skills:
- Audit Remediation Tracking
- Vendor Due Diligence Support
- Data Privacy & Protection Awareness
- SLA / Contract Review
- KPI/KRI Reporting
- Change Risk Assessment Participation
- Business Continuity (BCP/DR) Awareness
- Knowledge of emerging regulations (DORA, DPDP, etc.)
Qualifications
- Education: Bachelor’s degree in IT, Cybersecurity, Computer Science, or related field.
- Experience: 1–5 years in GRC, IT audit, cybersecurity, or compliance.
- Knowledge: Foundational understanding of ISO 27001, NIST, SOC 2, COBIT, IT controls, and cybersecurity frameworks.
- Technical Skills: Familiarity with GRC tools (Archer, ServiceNow, Excel).
- Certifications: ISO 27001 Foundation, CISA (beginner), or CompTIA Security+ preferred.
- Soft Skills: Strong analytical, documentation, and communication abilities; willingness to learn in a fast-paced environment.
Why Join Deloitte
- Collaborate with global teams to strengthen cybersecurity and risk management.
- Gain exposure to cutting-edge GRC frameworks and regulatory compliance initiatives.
- Develop professionally through mentorship, training, and challenging projects.
- Work in an inclusive, supportive, and innovative environment.
Apply Now
Advance your career as a Cybersecurity GRC Consultant at Deloitte India. Apply now on Deloitte Careers and become part of a team shaping cybersecurity strategies while building your professional expertise.