Deloitte Cyber Strategy PRISM Analytics and Insights Manager in New York, New York
Cyber Risk Analytics and Reporting Manager
As the scale, sophistication and impact of today's cyber threats increase, our clients rely on Deloitte's Cyber Strategy teams to understand the current threat landscape and advise on how to best assess and reduce their cyber risk exposure.
The Cyber Security Strategy team is responsible for assisting clients to define their cyber roadmap, assess the maturity of their cyber program, quantify and report on existing cyber risks, implement solutions to govern and manage cyber risk, and transform their cyber program to take advantage of new technologies and business models.
The Cyber Risk Analytics and Reporting Manager is a newly created role within the Cyber Risk practice to establish cyber risk analytics and reporting program. The program provides risk-based insights for varied global audiences ranging from operational leaders to Board of Directors.
Work you'll do
Assist in building a global cyber risk analytics program to enable executive decision making and prioritized risk mitigation through reporting of meaningful insights
Drive the buildout and maturing of the cyber risk analytics program - including people, process and technology components
Work with executive and senior management stakeholders for solution requirements gathering and socialization
Work with cyber data source owners to establish sustainable processes and technical architecture for data acquisition
Manage a team of cyber risk and data analysts to support development of cyber risk analytics solution
Develop governance model, operating processes and run book for the ongoing management of the solution
Lead Cyber Risk Analytics and reporting program development and implementation
Must be able to collaborate internally and externally with the clients to ensure collection and distribution of complete, accurate, and timely information to stakeholders
Ensure a standard process is used throughout the enterprise for metrics development, creation, and analysis
Ensure that metrics data is consistently collected, analyzed, and reported to leadership and stakeholders
Actively solicit input from stakeholders and provide feedback to the leadership and program manager at every step of program development and operation
Lead periodic refinement of standards-based and best practices compliant security metrics
Enable design and deployment of the mechanisms and tools for data harvesting and determine key risk indicators
Deloitte Advisory's Cyber Risk team helps complex organizations more confidently pursue their growth, innovation and performance agendas through proactive management of the associated cyber risks. Our professionals provide advisory and implementation services that integrate risk, regulatory, and technology skills to help clients transform their legacy programs into proactive Secure.Vigilant.Resilient. TM cyber risk programs. Join the team developing the future state of cyber risk solutions. Learn more about Deloitte Advisory's Cyber Risk Services practice.
Bachelor's degree in Statistics, Mathematics, Computer Science, or related discipline
8+ years of experience and proven leadership in developing, reporting, and communicating analytic results
8+ year of cyber risk experience with good understanding of overall cyber security program and expertise in at least three cyber domains e.g. vulnerability management, threat intelligence, GRC, incident management, Security operations managements, data protection etc.
Knowledge of different cyber risk data types and experience in programmatic collection of cyber and technical data from IT data sources using programs such as Python, R, C#, PowerShell etc.
5+ years of experience in implementing and managing ETL, data management and analytics technologies such as SQL, SSIS, SSAS, HDFS etc.
2+ years' experience in implementing cloud analytics solution e.g., AWS, GCP
5+ years of experience in implementation and usage of business intelligence tools such as tableau, Power BI, QuickSight, Looker etc.
5+ years of experience developing Key Risk Indicators / Key Performance Indicators related to Information Security or IT Risk Management
Working knowledge of information security industry frameworks (e.g., ISO 27K, NIST Cyber Security Framework)
Knowledge of regulatory environment as it applies to information security
Drive meaningful risk-based insights from data and report across different stakeholders
Ability to travel 35%, on average, based on the work you do and the clients and industries/sectors you serve
4+ years of information technology and/or information security experience
Is a self-driven and motivated individual with proven ability to lead development of security programs involving multitude of areas and stakeholders
Is a great communicator (must have)
Is a great presenter and adept at several reporting and presentation tools (via Microsoft PowerPoint, Excel AND more advanced reporting solutions like Tableau, QlikView)
Is experienced in managing a team of in-house or contracted resources
Is experienced in collaborating with client management and technical stakeholders
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.