Skip to main content
D

Deloitte USI

IT Security- Vendor Risk: Analyst: Bangalore

Hyderabad, Telangana, IndiaContractPosted 3 days ago

Skills

CollaborationCybersecurity

Job description

We are seeking a skilled IT Security professional to support vendor risk and client assurance activities for Deloitte Technology Canada. In this role, you will help assess third-party security and operational risk, respond to client assurance requests, and support audit and contractual security review activities. The role requires experience working across security, legal, procurement, audit, and business stakeholders to help drive timely and effective risk management outcomes.

Work you'll do

As an IT Security professional on the Deloitte Technology Canada security team, you will be responsible for supporting vendor risk assessment and client assurance activities across third-party services, technology providers, and client-facing security obligations.

Assess security, technology, and operational risks associated with third-party vendors and service providers.

Complete client security questionnaires and coordinate responses to client audit requests.

Review security clauses in master service agreements and statements of work in collaboration with Legal and business stakeholders.

Support SOC 2 and SOC 1 audit activities, including evidence gathering and control validation.

Coordinate with internal teams, vendors, clients, procurement, legal, and audit stakeholders to support timely completion of assurance activities.

The team

At Deloitte, we’re all about collaboration. And nowhere is this more apparent than among our 2,000-strong internal services team. With our combined specialist skills, we provide all the essential support and advice our client-facing colleagues need, right across the firm. This enables them to focus all of their efforts on delivering the best service possible to their clients. Covering seven distinct areas; Human Resources, Clients & Industries, Finance & Legal, Practice Support Services, Quality & Risk Services, IT Services, and Workplace Services & Real Estate, together we live, breathe and deliver the Deloitte experience.

Location: Hyderabad

Shift Timings: 2 PM to 11 PM IST

Qualifications

Required:

Bachelor’s degree or equivalent

Experience conducting vendor risk assessments for third-party providers

Experience completing client security questionnaires and supporting client audit requests

Experience reviewing security clauses in master service agreements and statements of work

Experience supporting SOC 1 and SOC 2 audits, including audit evidence collection and control validation

Experience with security and control frameworks such as NIST 800-53, ISO 27001, and information technology general controls

Experience with cloud technologies and cloud security controls

Preferred:

Industry certification such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Public Accountant (CPA), or similar

Experience working with cross-functional stakeholders across security, legal, procurement, audit, and business teams

Experience supporting assurance activities in a large enterprise environment

Apply on Deloitte USI