
Cyber Risk Manager, Deloitte Global Technology
- Toronto, ON
- $85,000-156,000 per year
- Permanent
- Full-time
Work Model: Hybrid
Reference code: 129421
Primary Location: Toronto, ON
All Available Locations: Toronto, ON; Edmonton, AB; Halifax, NS; Ottawa, ON; Regina, SKOur PurposeAt Deloitte, our Purpose is to make an impact that matters. We exist to inspire and help our people, organizations, communities, and countries to thrive by building a better future. Our work underpins a prosperous society where people can find meaning and opportunity. It builds consumer and business confidence, empowers organizations to find imaginative ways of deploying capital, enables fair, trusted, and functioning social and economic institutions, and allows our friends, families, and communities to enjoy the quality of life that comes with a sustainable future. And as the largest 100% Canadian-owned and operated professional services firm in our country, we are proud to work alongside our clients to make a positive impact for all Canadians.By living our Purpose, we will make an impact that matters.
- Have many careers in one Firm.
- Enjoy flexible, proactive, and practical benefits that foster a culture of well-being and connectedness.
- Learn from deep subject matter experts through mentoring and on the job coaching
- Develop and define key risk indicators to provide cyber risks insights to Deloitte Technology BISOs and executives.
- Gather requirements and build dashboards that accurately depict Deloitte Technology's cyber risk exposure.
- Drive organizational change and work with multiple business units of a large organization to effect change.
- Understand the Deloitte global line of business, gain familiarity with priorities, and become an advocate for the cyber risk within the BISO organization.
- Collaborate with BISOs as a cyber risk expert, to assist then to identify, assess, and manage cyber risks within their respective lines of business.
- Actively govern cyber risk in the Deloitte Technology risk register.
- Partner effectively with Deloitte Technology and BISO teams to facilitate cyber security risk reviews and analysis.
- Empower Deloitte Technology teams to establish cyber risk ownership and agree on acceptable risk levels aligned with their risk appetite.
- Review, test, and constructively challenge Deloitte Technology cyber teams on their cyber security risk assessments, including risk mitigation and management responses.
- Manage any new requirements for cyber risk dashboards and maintain existing dashboards.
- Work closely with Cyber risk reporting team to automate and digitize risk metrics, ensuring accurate representation of all Cyber Risk Data.
- Lead, coach, and mentor project teams to incorporate security into enterprise and client-facing applications.
- Collaborate with teams across Deloitte to reduce exposure to cyber risk across the enterprise.
- Serve as a trusted advisor to BISO, solution architects, developers, technical risk analysts and others on information security principles, standards, and best practices.
- Maintain the Deloitte Cyber risk framework, ensuring alignment with the Deloitte Enterprise risk framework.
- Support Deloitte Technology in documenting cyber risks within the Deloitte Technology risk register.
- Challenge and oversee cyber risk response, where the risk is not within appetite.
- 5+ years of related experience in cybersecurity risk management in organizations of a similar scale.
- Experience in the identification and evaluation of risk, as well as using GRC tools and guidance developed for Risk mitigation.
- Practical knowledge of information security standards and risk assessment frameworks such as ISO 27001, SOC 2, NIST 800-32
- Strong knowledge of cyber controls, policies, and procedures.
- Experience of delivering metrics for senior level audiences.
- Demonstrate analytical and problem-solving skills.
- Ability to communicate risks associated with complicated security-related concepts to technical and non-technical audiences.
- Proficient in the use of PowerBI or a similar dashboarding application.
- Knowledge of security systems (including working with SIEM data).
- SQL or database knowledge would be desirable.
- Relevant certifications such as CISSP, CISM, or CRISC are preferred.
- Proven experience in managing and delivering technical projects and teams.