- Company Name
- Deloitte
- Job Title
- Global Cybersecurity Policies and Standards Analyst, Deloitte Global Technology
- Job Description
-
Job title: Global Cybersecurity Policies and Standards Analyst
Role Summary:
Lead the creation, review, and dissemination of Deloitte Global cybersecurity policies, standards, and baselines. Drive alignment with business objectives, risk appetite, and industry frameworks, while ensuring consistent application across the organization.
Expactations:
- 3+ years of experience in a global or Fortune 500 environment focused on security policies, standards, or governance.
- Strong understanding of ISO 27001/27002, NIST 800‑53, and the NIST Cybersecurity Framework.
- Ability to translate complex security requirements into clear guidance for both technical and non‑technical audiences.
- Proven collaboration with cross‑functional teams, stakeholders, and senior leadership.
- Fluent written and verbal communication, including developing presentations and Statements of Applicability.
Key Responsibilities:
- Research, develop, and maintain Deloitte Global security standards, baselines, and supporting documents.
- Work with subject‑matter experts to assess impact, resolve deployment challenges, and manage risk.
- Coordinate with internal stakeholders to apply policies, publish updates, and ensure change communication.
- Author policy documentation, presentations, talking points, and Statements of Applicability.
- Maintain compliance mapping of standards to ISO 27002 requirements.
- Partner with cybersecurity teams to ensure alignment and maturity of the Policies & Standards function.
- Explore and implement emerging technologies (e.g., AI/ML) to enhance policy development processes.
Required Skills:
- Policy and standard development in information security.
- Deep knowledge of ISO 27001/27002, NIST 800‑53, NIST CSF, and related frameworks.
- Expertise in at least one technical domain (networking, operating systems, cloud, AI, software development).
- Excellent written and verbal communication; ability to convey complex concepts to varied audiences.
- Strong stakeholder management, collaboration, persuasion, attention to detail, time management, and prioritization.
- Advanced proficiency in MS Office (Word, Excel, PowerPoint).
Required Education & Certifications:
- Bachelor’s degree in cybersecurity, information systems, computer science, or related field (or equivalent experience).
- 3+ years in the cybersecurity domain with a focus on policies and standards.
- Professional certifications (CISSP, CISM, CRISC, CISA, or similar) highly preferred.
- Knowledge of information security legal and regulatory requirements.