To work in the innovative and creative CISO Team, a world-class operation renowned for its extensive expertise and experience. Collaborate with both business and technical teams to drive change and exert influence across the entire Deloitte landscape. Utilize your skills to effect real-world impact. As a Cybersecurity GRC Analyst, you will be responsible for monitoring, managing, supporting and closing compliance issues while also support the team with GRC deliverables such as risk assessments, policy and standard oversight and support, metrics and reporting, audit support, etc.
Work you'll do
As a Cybersecurity GRC on the CISO team, you will be responsible for:
-
Supporting deployment of cybersecurity strategy by collaborating across Cybersecurity, risk, control, and business teams
-
Conducting security control reviews, risk assessments, and control issue tracking to support compliance and governance activities
-
Maintaining risk registers, policy exception workflows, metrics dashboards, and management reporting for leadership and governance forums
-
Partnering with UK and global Cybersecurity, Business Security, IT Services, and compliance stakeholders on risk and control initiatives
-
Supporting audit requests, policy and standards oversight, process documentation, and continuous improvement across the GRC function
The team
At Deloitte, we’re all about collaboration. And nowhere is this more apparent than among our 2,000-strong internal services team. With our combined specialist skills, we provide all the essential support and advice our client-facing colleagues need, right across the firm. This enables them to focus all of their efforts on delivering the best service possible to their clients. Covering seven distinct areas; Human Resources, Clients & Industries, Finance & Legal, Practice Support Services, Quality & Risk Services, IT Services, and Workplace Services & Real Estate, together we live, breathe and deliver the Deloitte experience.
Location: Hyderabad
Shift Timings: 02:00 PM to 11:00 PM
Qualifications
Required:
-
Full-time bachelor’s degree in Computer Science, Information Security, Engineering, or another discipline
-
Experience in information security, governance, risk, and compliance, or risk management
-
Experience conducting risk assessments, impact assessments, control reviews, and policy or standards updates
-
Knowledge of cybersecurity and information assurance frameworks including National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), International Organization for Standardization 27001 (ISO 27001), and Control Objectives for Information and Related Technologies (COBIT)
-
Experience with governance, risk, and compliance tools such as Archer or ServiceNow GRC
-
Experience developing security metrics, key performance indicators, key risk indicators, and management reporting
-
Experience supporting audit activities, risk registers, and security governance processes
Preferred:
-
6+ years of experience in governance, risk, and compliance work with risk and control responsibilities
-
Experience developing information risk management and assurance approaches
-
Experience developing cybersecurity risk management frameworks and methodologies
-
Industry certification such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified in Risk and Information Systems Control (CRISC)
-
Experience with Information Technology Infrastructure Library version 4 (ITIL v4) service management practices
-
Experience communicating cybersecurity risk and control concepts to technical and non-technical stakeholders