ISMS Consultant

  • Gurugram
  • Deloitte
Deloitte What impact will you make? Every day, your work will make an impact that matters, while you thrive in a dynamic culture of inclusion, collaboration and high performance. As the undisputed leader in professional services, Deloitte is where you’ll find unrivaled opportunities to succeed and realize your full potential Deloitte is where you’ll find unrivaled opportunities to succeed and realize your full potential. The Team Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks. Learn more about our Cyber Risk Practice. Work you’ll do As a part of our Risk Advisory team you’ll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations. You’ll: • Working knowledge in one or more security and privacy domains such as: security governance policies and procedures, risk management, compliance, access control, network security, security architecture, security incident response, disaster recovery, business continuity management, privacy and data protection • Experience in leveraging industry standards and frameworks such as ISO/IEC 17799, ISO/IEC 27001, COBIT, ITIL, etc. • Demonstrates in-depth knowledge of security and privacy controls and risk management process • Experience in data protection technologies such as encryption, data discovery, data masking, data redaction, etc. • Possesses certifications such as ISO27001 LA/ LI, ISO22301 LA/LI, CISSP, CISA, CISM certification- preferred The key skills required are as follows: • Advice on Governance, Risk and Compliance Frameworks. Experience in assessment and implementation of various Information Security Management System Framework such as ISO 27001, NIST CSF, NIST - 800 Series, PCI-DSS, SWIFT etc. • Experience in documenting the security policies/ procedures/ risk and controls matrix and defining KPI/ risk treatment plans/ security roadmaps. • Responsible to assist client in review / implement Information Security controls in areas as mentioned, but not limited to: • Infrastructure and Network Security, configuration of security devices • Privilege/ User identity and access management Risk Advisory Cyber Risk • Cloud security for different models such IaaS, PaaS and SaaS • Incident management process, SLA performance and monitoring • Business Continuity Planning, IT Disaster Recovery planning, Backup and restoration process • End point protection, Antivirus management • Asset Management • Information Handling, Data Protection and data privacy (including controls with respect to GDPR/ HIPPA) • Good understanding of various tools and technologies such as PIM, IDAM, SIEM, DLP, EDR/XDR, MFA, VPN, MDM. • Responsible for conducting vendors risk assessment and providing a holistic view of client’s risk exposure due to outsourcing • Manages day-to-day client relationships at mid and lower levels. Qualifications • B.E / B.Tech (Tier 1/2) in Computer Science, Information Technology or related fields • ISO 27001 LA/LI, ISO 31000 LA/LI, ISO 22301 LA/LI, CISA, ITIL, or equivalent certification preferred • CISSP, GSEC, GCIH, CEH, LPT, CCSK, eGRC tools like Archer, OpenPages or functional certifications would be preferred. Your role as a leader At Deloitte India, we believe in the importance of leadership at all levels. We expect our people to embrace and live our purpose by challenging themselves to identify issues that are most important for our clients, our people, and for society and make an impact that matters. In addition to living our purpose, across our organization: • Builds own understanding of our purpose and values; explores opportunities for impact • Demonstrates strong commitment to personal learning and development; acts as a brand ambassador to help attract top talent • Understands expectations and demonstrates personal accountability for keeping performance on track • Actively focuses on developing effective communication and relationship-building skills • Understands how their daily work contributes to the priorities of the team and the business Interested candidates can share their updated profile on ikainat.ext@deloitte.com Preferred: Immediate joiners or max 1 month notice period