At a Glance
- Tasks: Lead cyber risk assessments and collaborate with teams to enhance security measures.
- Company: Deloitte is a global leader in technology and consulting, driving progress through diverse talent.
- Benefits: Enjoy hybrid working, personal development opportunities, and a supportive work culture.
- Why this job: Make a real impact in cybersecurity while growing your skills in a collaborative environment.
- Qualifications: Experience in cybersecurity risk management and knowledge of relevant standards are essential.
- Other info: Join a team that values inclusion, integrity, and continuous learning.
The predicted salary is between 43200 - 72000 £ per year.
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
The Technical Cyber Risk Assessment Manager will be responsible for the following:
- Develop an understanding of Deloitte's global line of business and its priorities, becoming an advocate for addressing cyber risk.
- Demonstrate familiarity with the Three Lines of Defense (3LOD) model.
- Possess knowledge of risk management practices and the ability to conduct technical risk assessments.
- Work with the Global Technology Infrastructure team to integrate system cybersecurity assessments into their processes to ensure consistent implementation of security controls.
- Work with the Cybersecurity Architecture team and apply reference architectures for security solutions design and implementation.
- Work with the Cyber Defense group and the Security Operations Center to evaluate the effectiveness of the security controls and architectures in relationship to actual intrusions seen on the Deloitte network, reported threats at peer organizations, and overall cybersecurity threats in the internet ecosystem.
- Notify leadership of potential or existing threats and assist in the development of risk mitigating strategies.
- Monitor security blogs, articles, and reports and remain current on related laws, regulations, and industry standards to keep up to date on the latest security risks, threats, and technology trends.
- Perform technology security risk assessments.
- Leverage security shared services (VRA, VM, Pen Testing) and provide oversight and assurance of cybersecurity controls in development and deployment all the way through the system go-live.
- Hold great working relationships with the Security Architecture team, Shared Security Service teams, Global Business Services organizations, and Member Firm Services organizations.
- Proven experience writing clear, accurate, and user-friendly technical documentation for diverse audiences and purposes.
- Communicate detailed cybersecurity findings and analyses to leadership, subject matter experts (SMEs), and stakeholders, ensuring clarity and comprehensiveness in communication.
Do you possess the following?
- Proven related experience in cybersecurity risk management in organizations of a similar scale.
- Experience in the identification and evaluation of risk, as well as using GRC tools and guidance developed for risk mitigation.
- Practical knowledge of information security standards and risk assessment frameworks such as ISO 27001, SOC 2, NIST 800-32.
- Strong knowledge of cyber controls, policies, and procedures.
- Experience of delivering metrics for senior level audiences.
- Demonstrate analytical and problem-solving skills.
- Ability to communicate risks associated with complicated security-related concepts to technical and non-technical audiences.
- Proficient in the use of PowerBI or a similar dashboarding application.
- Knowledge of security systems (including working with SIEM data).
- SQL or database knowledge would be desirable.
- Relevant certifications such as CISSP, CISM, or CRISC (or equivalent) are preferred.
- Proven experience in managing and delivering technical projects and teams.
Collaboration is central to everything we do at Deloitte. From IT to HR, marketing and more, our teams help to support the wider business in everything they do. Bringing your individual skills and specialist knowledge, you can make a far-reaching impact.
Regulation and controls are standard practice in our industry and Deloitte is no exception. These controls provide important legal protection for both you and the firm. We are subject to a number of audit regulations, one of which requires that certain colleagues abide by specific personal independence constraints.
Our hybrid working policy allows you to work flexibly through our hybrid working policy. Depending on the requirements of your role, you’ll have the opportunity to work in your local office, virtual collaboration spaces, client sites and remotely.
Making an impact is more than just what we do: it’s why we’re here. So we work hard to create an environment where you can experience a purpose you believe in, the freedom to be you, and the capacity to go further than ever before.
A career at Deloitte is an opportunity to develop in any direction you choose. Join us and you’ll experience a purpose you can believe in and an impact you can see.
Technical Cyber Risk Assessment Manager employer: Deloitte LLP
Contact Detail:
Deloitte LLP Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Technical Cyber Risk Assessment Manager
✨Tip Number 1
Familiarise yourself with Deloitte's values and culture. Understanding how they approach decision-making and collaboration will help you align your responses during interviews, showcasing that you're a good fit for their team.
✨Tip Number 2
Stay updated on the latest cybersecurity trends and threats. Being able to discuss current events or recent breaches in your interview can demonstrate your passion and knowledge in the field, making you stand out as a candidate.
✨Tip Number 3
Network with current or former Deloitte employees on platforms like LinkedIn. Engaging with them can provide insights into the company culture and the specific challenges faced in the Technical Cyber Risk Assessment Manager role.
✨Tip Number 4
Prepare to discuss your experience with risk management frameworks like ISO 27001 or NIST. Be ready to share specific examples of how you've applied these frameworks in past roles, as this will highlight your relevant expertise.
We think you need these skills to ace Technical Cyber Risk Assessment Manager
Some tips for your application 🫡
Understand the Role: Before applying, take the time to thoroughly read the job description for the Technical Cyber Risk Assessment Manager position. Make sure you understand the key responsibilities and required skills, as this will help you tailor your application.
Tailor Your CV: Customise your CV to highlight relevant experience in cybersecurity risk management, technical documentation, and risk assessment frameworks. Use specific examples that demonstrate your expertise and how it aligns with Deloitte's values and the role's requirements.
Craft a Compelling Cover Letter: Write a cover letter that not only outlines your qualifications but also reflects your understanding of Deloitte's mission and values. Explain why you are passionate about cybersecurity and how you can contribute to their goals.
Proofread and Edit: Before submitting your application, carefully proofread your CV and cover letter for any spelling or grammatical errors. Ensure that your documents are clear, concise, and professional, as attention to detail is crucial in this field.
How to prepare for a job interview at Deloitte LLP
✨Understand the Three Lines of Defense
Familiarise yourself with the Three Lines of Defense model, as it's crucial for the role. Be prepared to discuss how this model applies to cyber risk management and how you can advocate for its implementation within Deloitte.
✨Showcase Your Technical Knowledge
Demonstrate your understanding of risk management practices and technical risk assessments. Be ready to provide examples from your past experiences where you've successfully identified and mitigated cyber risks.
✨Communicate Clearly
Since you'll be conveying complex cybersecurity findings to diverse audiences, practice explaining technical concepts in simple terms. This will show your ability to bridge the gap between technical and non-technical stakeholders.
✨Stay Current on Cybersecurity Trends
Keep up-to-date with the latest security risks, threats, and technology trends. During the interview, mention specific blogs or reports you follow, and how this knowledge can benefit Deloitte's cybersecurity strategies.