Consultant | Security Frameworks and Standards | Pune | Cyber Strategy & Transformation
- Job requisition ID : 112129
- Location: Pune
- Entity: Deloitte Touche Tohmatsu India LLP
The team
Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks: Learn more about Cyber | Deloitte
Your work profile
We are looking for cybersecurity professionals with exposure to Cyber Risk, Security Controls, Cyber Capability Development, and Security Technology Enablement to support cybersecurity transformation initiatives .
The role focuses on assessing cybersecurity capabilities, evaluating control effectiveness, identifying improvement opportunities, and supporting strategic initiatives that enhance cyber resilience, governance, and security maturity across the enterprise.
Key Skills Required
- Conduct cyber capability and security control assessments across technology environments.
- Review security controls against frameworks such as NIST CSF, ISO 27001, CIS Controls, and organizational standards.
- Support cyber maturity assessments and capability development roadmaps.
- Assist with control documentation, evidence management, remediation tracking, and improvement initiatives.
- Evaluate identity, endpoint, network, cloud, and application security capabilities.
- Assess the effectiveness of preventive, detective, and corrective security controls.
- Utilize Microsoft Sentinel, KQL, and security telemetry to support control validation, capability assessment, and security effectiveness reviews.
- Monitor security events, alerts, trends and emerging risk indicators to assess the effectiveness of detective security controls
- Contribute to cyber transformation programs focused on strengthening security posture and cyber resilience.
- Collaborate with technology, infrastructure, cloud, and business teams to implement cybersecurity improvements.
- Support cybersecurity metrics, reporting, dashboards, and executive-level insights.
- Maintain assessment findings, recommendations, and transformation deliverables.
- Knowledge of incident-response methodologies and common attack techniques to support security control reviews, control effectiveness assessments, and cyber capability improvement initiatives.
- 2-4 years of experience in Cybersecurity, Cyber Risk, Security Controls, Governance, Compliance, or Cyber Transformation.
- Understanding of cybersecurity control frameworks and industry standards.
- Exposure to NIST CSF, ISO 27001, CIS Controls, or equivalent frameworks.
- Working knowledge of Microsoft Sentinel and KQL for security analysis, control validation, and cyber capability assessments.
- Experience in security control reviews, risk assessments, or capability assessments.
- Knowledge of identity, endpoint, network, cloud, and application security domains.
- Strong documentation, reporting, and communication capabilities.
- B.E./B.Tech (Tier 1/2) or Master’s degree in Information Security, Computer Science, or a related field