Assistant Manager | Risk Management | Pune | Cyber Strategy & Transformation
Deloitte
· ✓ Verified company
📍 Pune, India · On-site · Full-time
About the role
Job Description – Cybersecurity Assessment | Third-Party Risk Management (TPRM) Role Overview We are looking for cybersecurity professionals to support Third-Party Risk Management (TPRM) activities, with a focus on assessing the cybersecurity posture of third-party suppliers, identifying risks and control gaps, and driving remediation in line with organizational policies and regulatory requirements. Key Responsibilities - Perform cybersecurity risk assessments of third-party suppliers across areas such as information security, infrastructure security, application security, data protection, IAM, vulnerability management, incident management, BCP/DR and cloud security. - Review and evaluate supplier responses to security questionnaires and assessment frameworks against defined control requirements. - Analyze supporting evidence such as SOC 1/SOC 2 reports, ISO 27001 certificates, penetration testing reports, policies, vulnerability reports, business continuity documentation and security assessments. - Identify control gaps, cybersecurity risks and potential areas of exposure; assess the inherent and residual risk associated with third parties. - Validate remediation plans and track open findings/issues through to closure. - Support risk-based decision making, including identification of compensating controls, risk acceptance and remediation requirements. - Perform assessments of third parties providing critical, high-risk or technology-enabled services. - Document assessment results, risk ratings, findings and recommendations in TPRM platforms/tools. - Engage with third-party stakeholders and internal teams to obtain clarifications, evidence and remediation updates. - Support escalation and reporting of overdue or high-risk findings to relevant stakeholders. - Contribute to continuous improvement of TPRM assessment methodologies, processes, control frameworks and assessment templates. - Support regulatory and audit requirements related to third-party cybersecurity and operational resilience. Required Skills & Experience - 5–10 years of experience in Cybersecurity, Information Security, IT Risk, Technology Risk or Third-Party Risk Management. - Hands-on experience in conducting TPRM / third-party cybersecurity assessments. - Good understanding of cybersecurity domains including: - Information Security Governance - IAM / Privileged Access Management - Vulnerability & Patch Management - Network & Infrastructure Security - Application / SDLC Security - Data Protection & Privacy - Cloud Security - Security Monitoring & Incident Response - Business Continuity & Disaster Recovery - Cryptography and Key Management - Experience assessing third parties against frameworks such as ISO 27001, NIST CSF, CIS Controls, SOC 2, PCI DSS or similar standards. - Ability to interpret SOC reports, audit reports, penetration testing reports and security certifications. - Strong understanding of risk assessment methodologies, control testing and risk rating approaches. - Strong analytical, documentation and stakeholder management skills. - Ability to independently manage multiple assessments and meet defined SLA / turnaround requirements. Preferred Qualifications - Certifications such as CISA, CISM, CRISC, CISSP, ISO 27001 Lead Auditor/Implementer or equivalent. - Experience working with TPRM/GRC platforms. - B.E./B.Tech (Tier 1/2) or Master’s degree in Information Security, Computer Science, or a related field - Experience in financial services / banking / insurance environments. - Knowledge of regulatory expectations around third-party risk and operational resilience. - Experience with cloud service provider and SaaS vendor assessments. Key Competencies - Cybersecurity & Technology Risk - Third-Party Risk Management - Risk & Control Assessment - Evidence Analysis - Risk Rating & Remediation - Regulatory & Compliance - Stakeholder Management - Strong written and verbal communication - Analytical and problem-solving skills