At a Glance
- Tasks: Lead cyber risk assessments and collaborate with teams to enhance security measures.
- Company: Deloitte is a global leader in technology and consulting, driving progress through innovation.
- Benefits: Enjoy hybrid working, professional development, and a supportive culture that prioritises wellbeing.
- Other info: Flexible working options available across multiple locations including Gatwick and London.
- Why this job: Join a diverse team making a real impact in cybersecurity while growing your skills.
- Qualifications: Experience in cybersecurity risk management and knowledge of relevant standards like ISO 27001 required.
The predicted salary is between 43200 - 72000 £ per year.
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
The Technical Cyber Risk Assessment Manager will be responsible for the following:
- Develop an understanding of Deloitte's global line of business and its priorities, becoming an advocate for addressing cyber risk.
- Demonstrate familiarity with the Three Lines of Defense (3LOD) model.
- Possess knowledge of risk management practices and the ability to conduct technical risk assessments.
- Work with the Global Technology Infrastructure team to integrate system cybersecurity assessments into their processes to ensure consistent implementation of security controls.
- Work with the Cybersecurity Architecture team and apply reference architectures for security solutions design and implementation.
- Work with the Cyber Defense group and the Security Operations Center to evaluate the effectiveness of the security controls and architectures in relationship to actual intrusions seen on the Deloitte network, reported threats at peer organizations, and overall cybersecurity threats in the internet ecosystem.
- Notify leadership of potential or existing threats and assist in the development of risk mitigating strategies.
- Monitor security blogs, articles, and reports and remain current on related laws, regulations, and industry standards to keep up to date on the latest security risks, threats, and technology trends.
- Perform technology security risk assessments.
- Leverage security shared services (VRA, VM, Pen Testing) and provide oversight and assurance of cybersecurity controls in development and deployment all the way through the system go-live.
- Hold great working relationships with the Security Architecture team, Shared Security Service teams, Global Business Services organizations, and Member Firm Services organizations.
- Proven experience writing clear, accurate, and user-friendly technical documentation for diverse audiences and purposes.
- Communicate detailed cybersecurity findings and analyses to leadership, subject matter experts (SMEs), and stakeholders, ensuring clarity and comprehensiveness in communication.
Do you possess the following?
- Proven related experience in cybersecurity risk management in organizations of a similar scale.
- Experience in the identification and evaluation of risk, as well as using GRC tools and guidance developed for Risk mitigation.
- Practical knowledge of information security standards and risk assessment frameworks such as ISO 27001, SOC 2, NIST 800-32.
- Strong knowledge of cyber controls, policies, and procedures.
- Experience of delivering metrics for senior level audiences.
- Demonstrate analytical and problem-solving skills.
- Ability to communicate risks associated with complicated security-related concepts to technical and non-technical audiences.
- Proficient in the use of PowerBI or a similar dashboarding application.
- Knowledge of security systems (including working with SIEM data).
- SQL or database knowledge would be desirable.
- Relevant certifications such as CISSP, CISM, or CRISC (or equivalent) are preferred.
- Proven experience in managing and delivering technical projects and teams.
Collaboration is central to everything we do at Deloitte. From IT to HR, marketing and more, our teams help to support the wider business in everything they do. Bringing your individual skills and specialist knowledge, you can make a far-reaching impact.
Our hybrid working policy allows you to work flexibly through our hybrid working policy. Depending on the requirements of your role, you’ll have the opportunity to work in your local office, virtual collaboration spaces, client sites and remotely.
Making an impact is more than just what we do: it’s why we’re here. We want you to bring your true self to work every day. And you’ll never stop growing, whatever your level.
Technical Cyber Risk Assessment Manager in Reading employer: Deloitte LLP
Deloitte is an exceptional employer that fosters a collaborative and inclusive work culture, empowering employees to thrive in their careers while balancing personal well-being. With a commitment to professional growth, Deloitte offers extensive development opportunities and a hybrid working policy that allows flexibility in the Gatwick, London, Reading, or St. Albans locations. Join us to make a meaningful impact in the field of cybersecurity and be part of a team that values integrity, innovation, and diversity.
StudySmarter Expert Advice🤫
We think this is how you could land Technical Cyber Risk Assessment Manager in Reading
✨Tip Number 1
Familiarise yourself with Deloitte's values and culture. Understanding how they approach decision-making and teamwork will help you align your responses during interviews, showcasing that you're a good fit for their environment.
✨Tip Number 2
Network with current or former employees of Deloitte, especially those in cybersecurity roles. They can provide insights into the company’s expectations and the nuances of the Technical Cyber Risk Assessment Manager position.
✨Tip Number 3
Stay updated on the latest trends in cybersecurity and risk management. Being able to discuss recent developments or case studies during your interview will demonstrate your passion and knowledge in the field.
✨Tip Number 4
Prepare to discuss your experience with GRC tools and risk assessment frameworks like ISO 27001 or NIST. Be ready to provide examples of how you've applied these in previous roles, as this will be crucial for the position.
We think you need these skills to ace Technical Cyber Risk Assessment Manager in Reading
Some tips for your application 🫡
Tailor Your CV:Make sure your CV highlights relevant experience in cybersecurity risk management. Use keywords from the job description, such as 'technical risk assessments' and 'cybersecurity controls', to demonstrate your fit for the role.
Craft a Compelling Cover Letter:In your cover letter, express your passion for cybersecurity and how your skills align with Deloitte's values. Mention specific experiences that showcase your ability to communicate complex information clearly to both technical and non-technical audiences.
Showcase Relevant Certifications:If you have certifications like CISSP, CISM, or CRISC, make sure to highlight them prominently in your application. This will demonstrate your commitment to professional development and expertise in the field.
Prepare for Technical Questions:Anticipate technical questions related to risk assessment frameworks and cybersecurity practices. Be ready to discuss your experience with tools like PowerBI and your understanding of security standards such as ISO 27001 during the interview process.
How to prepare for a job interview at Deloitte LLP
✨Understand the Three Lines of Defense
Familiarise yourself with the Three Lines of Defense model, as it's crucial for the role. Be prepared to discuss how this model applies to cyber risk management and how you can advocate for its implementation within Deloitte.
✨Showcase Your Technical Knowledge
Demonstrate your understanding of risk management practices and technical risk assessments. Be ready to provide examples from your past experiences where you've successfully identified and mitigated risks using frameworks like ISO 27001 or NIST.
✨Communicate Clearly
Since you'll be conveying complex cybersecurity findings to both technical and non-technical audiences, practice explaining intricate concepts in simple terms. This will showcase your ability to bridge the gap between different stakeholders.
✨Stay Current on Cybersecurity Trends
Keep up-to-date with the latest security risks, threats, and technology trends. During the interview, mention specific blogs, articles, or reports you've followed recently, and how they could influence Deloitte's cybersecurity strategies.