At a Glance
- Tasks: Manage cyber risks and collaborate with teams to enhance security measures.
- Company: Join Deloitte, a global leader in technology and innovation.
- Benefits: Flexible hybrid working, competitive salary, and continuous professional development.
- Why this job: Make a real impact in cybersecurity while growing your career in a supportive environment.
- Qualifications: Degree in tech or related field; experience in cybersecurity risk management.
- Other info: Dynamic team culture focused on collaboration and personal growth.
The predicted salary is between 36000 - 60000 £ per year.
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
Deloitte drives progress. Using our vast range of expertise, we help our clients become leaders wherever they choose to compete. To do this, we invest in outstanding people. We build teams of future thinkers, with diverse talents and backgrounds, and empower them all to reach for and achieve more.
What brings us all together at Deloitte? It’s how we approach the thousands of decisions we make every day. How we behave, our beliefs and our attitudes. In other words: our values. Whatever we do, wherever we are in the world, we lead the way, serve with integrity, take care of each other, foster inclusion, and collaborate for measurable impact. These five shared values lead every decision we make and action we take, guiding us to deliver impact how and where it matters most.
The Cyber Risk & Exceptions Management, Analyst will be responsible for the following:
- Actively govern cyber risks in the Deloitte Technology Cyber Risk Register and partner effectively with Deloitte teams to facilitate cyber security risk reviews and analysis.
- Maintain the Deloitte Cyber Risk Framework, ensuring alignment with the Deloitte Enterprise Risk Framework.
- Collaborate with teams across Cyber to identify, assess, mitigate and manage cyber risks within their respective lines of business within the Deloitte Technology Cyber Risk Register.
- Empower Deloitte Technology teams to establish cyber risk ownership and agree on acceptable risk levels aligned with their risk appetite.
- Review, test, and constructively challenge Deloitte Technology cyber teams on their cyber security risk assessments, including risk mitigation and management responses to ensure risks have been effectively remediated.
- Service, prioritize, analyze, and process Global Cyber standard exception requests by reviewing policy requirements, security standards, system and Deloitte firm architecture, designs, and materials.
- Coordinate efforts to ensure all necessary information has been provided for the proper review of exceptions.
- Offer leadership and guidance to teams during the cyber security exceptions process.
- Make informed risk decisions based on Global exceptions being requested and the potential risk this poses to Deloitte firms.
- Create analysis presentations of exceptions and reports, highlighting and outlining potential risks to Deloitte firms to Cyber security, Risk, and Technology leadership teams.
- Perform and provide quality and timely performance of exception evaluations, recommendations, and reports.
- Participate in the development of security policies and standards exception management processes.
- Contribute to the continuous improvement of established security policies and standards exception management processes.
Relationship Management:
- Collaborate with teams across Deloitte Technology and Deloitte firms to reduce exposure to cyber risk across the enterprise.
- Evolve and manage relationships with cybersecurity, technology, legal, and risk leaders across Deloitte Technology and Deloitte firms.
- Develop and maintain relationships with primary exceptions management leaders across Deloitte firms.
- Serve as a trusted advisor to solution architects, developers, technical risk analysts and others on information security principles, policies, standards, and best practices.
- Work effectively with individuals at various levels of seniority within the cyber organization, fostering a collaborative and team-based approach to Cybersecurity data lake development and utilization.
Connect to your skills and professional experience:
- Bachelor’s degree: degree in a technology-related field, or equivalent education related experience.
- Relevant experience in cybersecurity risk management, governance, and exceptions management within organizations of a similar scale to Deloitte.
- Experience in the identification and evaluation of cyber risk, as well as using GRC tools and guidance developed for risk mitigation.
- Experience in security policies and standards exception management.
- Practical knowledge of information security standards and risk assessment frameworks such as ISO 27001, SOC 2, NIST 800-32.
- Strong knowledge of cyber controls, policies, and procedures.
- Demonstrate analytical and problem-solving skills.
- Ability to communicate risks associated with complicated security-related concepts to technical and non-technical audiences.
- Relevant certifications such as CISSP, CISM, or CRISC are preferred.
- Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate strategic information security topics, policies, and standards as well as risk-related concepts to technical and non-technical audiences at various hierarchical levels.
Collaboration is central to everything we do at Deloitte. From IT to HR, marketing and more, our teams help to support the wider business in everything they do. Bringing your individual skills and specialist knowledge, you can make a far-reaching impact. Come join us.
Regulation and controls are standard practice in our industry and Deloitte is no exception. These controls provide important legal protection for both you and the firm. We are subject to a number of audit regulations, one of which requires that certain colleagues abide by specific personal independence constraints (e.g., in relation to any financial interests and employment relationships).
You’ll be based in one of our UK offices with hybrid working. At Deloitte we understand the importance of balancing your career alongside your home life. That’s why we’ll support you to work flexibly through our hybrid working policy.
Making an impact is more than just what we do: it’s why we’re here. So we work hard to create an environment where you can experience a purpose you believe in, the freedom to be you, and the capacity to go further than ever before.
Your expertise is our capability, so we’ll make sure it never stops growing. Whether it’s from the complex work you do, or the people you collaborate with, you’ll learn every day. Through world-class development, you’ll gain invaluable technical and personal skills.
A career at Deloitte is an opportunity to develop in any direction you choose. Join us and you’ll experience a purpose you can believe in and an impact you can see.
Cyber Risk & Exceptions Management (Assistant Manager) in London employer: Deloitte LLP
Contact Detail:
Deloitte LLP Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Risk & Exceptions Management (Assistant Manager) in London
✨Tip Number 1
Network like a pro! Reach out to current employees at Deloitte on LinkedIn or through mutual connections. Ask them about their experiences and any tips they might have for the interview process. This can give you insider knowledge and make you stand out.
✨Tip Number 2
Prepare for your interview by researching Deloitte's values and recent projects. Show how your skills align with their mission to drive progress and foster inclusion. Tailor your answers to reflect their culture, and you'll be sure to impress!
✨Tip Number 3
Practice makes perfect! Conduct mock interviews with friends or use online platforms to refine your responses. Focus on articulating your experience in cybersecurity risk management clearly and confidently, as this is key for the role.
✨Tip Number 4
Don’t forget to follow up after your interview! A simple thank-you email expressing your appreciation for the opportunity can leave a lasting impression. Plus, it shows your enthusiasm for the role and the company.
We think you need these skills to ace Cyber Risk & Exceptions Management (Assistant Manager) in London
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Cyber Risk & Exceptions Management role. Highlight your relevant experience in cybersecurity risk management and governance, and don’t forget to mention any certifications you have like CISSP or CISM.
Showcase Your Skills: Use specific examples to demonstrate your analytical and problem-solving skills. Talk about how you've communicated complex security concepts to both technical and non-technical audiences, as this is key for the role.
Be Authentic: Let your personality shine through in your application. We want to see the true you! Share your passion for cybersecurity and how it aligns with Deloitte's values of integrity, collaboration, and making a measurable impact.
Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way to ensure it gets into the right hands. Plus, you’ll find all the details you need about the role and our culture there.
How to prepare for a job interview at Deloitte LLP
✨Know Your Cyber Risk Frameworks
Before the interview, brush up on key cyber risk frameworks like ISO 27001 and NIST 800-32. Be ready to discuss how these frameworks apply to the role and how you’ve used them in past experiences.
✨Showcase Your Analytical Skills
Prepare examples that highlight your analytical and problem-solving skills. Think of specific situations where you identified a cyber risk and how you managed it. This will demonstrate your ability to handle complex security-related concepts.
✨Communicate Clearly
Practice explaining technical concepts in simple terms. You might be asked to communicate risks to both technical and non-technical audiences, so being able to articulate your thoughts clearly is crucial.
✨Build Relationships
Deloitte values collaboration, so be prepared to discuss how you’ve built relationships with various stakeholders in previous roles. Share examples of how you’ve worked with teams across different functions to manage cyber risks effectively.