Vista previa de la oferta
USI- EH27- MF- Canada- L25- IT Security- Hyderabad
Other
We are seeking a skilled IT Security professional to support vendor risk and client assurance activities for Deloitte Technology Canada. In this role, you will help assess third-party security and operational risk, respond to client assurance requests, and support audit and contractual security review activities. The role requires experience working across security, legal, procurement, audit, and business stakeholders to help drive timely and effective risk management outcomes.
Work you'll do
As an IT Security professional on the Deloitte Technology Canada security team, you will be responsible for supporting vendor risk assessment and client assurance activities across third-party services, technology providers, and client-facing security obligations.
- Assess security, technology, and operational risks associated with third-party vendors and service providers.
- Complete client security questionnaires and coordinate responses to client audit requests.
- Review security clauses in master service agreements and statements of work in collaboration with Legal and business stakeholders.
- Support SOC 2 and SOC 1 audit activities, including evidence gathering and control validation.
- Coordinate with internal teams, vendors, clients, procurement, legal, and audit stakeholders to support timely completion of assurance activities.
The team
At Deloitte, we’re all about collaboration. And nowhere is this more apparent than among our 2,000-strong internal services team. With our combined specialist skills, we provide all the essential support and advice our client-facing colleagues need, right across the firm. This enables them to focus all of their efforts on delivering the best service possible to their clients. Covering seven distinct areas; Human Resources, Clients & Industries, Finance & Legal, Practice Support Services, Quality & Risk Services, IT Services, and Workplace Services & Real Estate, together we live, breathe and deliver the Deloitte experience.
Location: Hyderabad
Shift Timings: 2 PM to 11 PM IST
Qualifications
Required:
- Bachelor’s degree or equivalent
- Experience conducting vendor risk assessments for third-party providers
- Experience completing client security questionnaires and supporting client audit requests
- Experience reviewing security clauses in master service agreements and statements of work
- Experience supporting SOC 1 and SOC 2 audits, including audit evidence collection and control validation
- Experience with security and control frameworks such as NIST 800-53, ISO 27001, and information technology general controls
- Experience with cloud technologies and cloud security controls
Preferred:
- Industry certification such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Public Accountant (CPA), or similar
- Experience working with cross-functional stakeholders across security, legal, procurement, audit, and business teams
- Experience supporting assurance activities in a large enterprise environment