As a Manager, Strategy, Growth & Transformation specializing in Strategy in Deloitte's Cyber for AI practice, you will lead client engagements that help enterprises understand the cybersecurity and enterprise risks of adopting AI and define how they will govern, manage and secure it. You will translate business, risk and regulatory objectives into cybersecurity controls, governance frameworks and risk operating models, remain directly involved in critical strategic decisions, and guide teams from assessment through implementation alongside the practice's Data, Infrastructure, Identity, Security Operations and Application Security capabilities. You will also shape solutions during pursuits and help build repeatable delivery assets.
Recruiting for this role ends on 05/31/2027.
Work you'll do
As a Manager on the Cyber Strategy & Transformation team, you will be responsible for:
- Leading AI cybersecurity strategy assessments, governance workshops, and risk operating model design for clients adopting generative artificial intelligence and agentic systems.
- Translating business objectives, regulatory obligations, and risk appetite into AI governance frameworks, risk taxonomies, and control operating models.
- Advising clients on AI security strategy decisions while reviewing governance artifacts, policy documents, and risk assessments developed by engagement teams.
- Managing engagement scope, teams, milestones, quality, and client expectations across strategy-led AI security programs.
- Coordinating with Data, Infrastructure, Identity, Application Security, and Security Operations leaders to help translate strategic recommendations into implementable technical requirements, and technical considerations into strategic decisions.
- Shaping solutions during pursuits through workshops, executive briefings, proposals, estimates, and delivery plans, while developing reusable cyber strategy assets including security controls, governance frameworks, maturity models, risk taxonomies, and playbooks, and coaching practitioners on advisory quality.
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to mentor and provide clear guidance to others
Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.
Qualifications
Required:
- Bachelor's degree or equivalent demonstrated experience in Computer Science, Engineering, Information Technology, Cybersecurity, or Risk Management
- 8+ years of cybersecurity, risk management, or technology consulting experience, including experience advising on artificial intelligence, machine learning, or emerging technology risk
- Experience designing AI governance frameworks, risk operating models, or security strategy programs for enterprise clients
- Experience with AI and machine learning architectures, risks of generative artificial intelligence and agentic systems, and one or more of the following: National Institute of Standards and Technology Artificial Intelligence Risk Management Framework, International Organization for Standardization/International Electrotechnical Commission 42001, Open Worldwide Application Security Project Large Language Model Top 10, MITRE ATLAS, or the European Union Artificial Intelligence Act
- Experience leading client-facing advisory or risk engagements and coordinating cross-functional workstreams across identity, data, infrastructure, security operations, and application security
- Ability to travel 25%-50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
- Experience building AI cybersecurity controls, control guidance, governance operating models, risk committees, or intake and approval processes for enterprise AI programs
- Experience with governance, risk, and compliance platforms, AI governance tools, or model risk management systems
- Experience with AI threat modeling, red teaming, security evaluations, or secure AI development practices
- Experience building reusable strategy assets, delivery methods, or advisory frameworks used across multiple engagements
- Experience with machine learning lifecycle tools or frameworks such as PyTorch, TensorFlow, or MLflow
- One or more of the following certifications: Certified Information Systems Security Professional, Certified Information Security Manager, Certified Data Privacy Solutions Engineer, Artificial Intelligence Governance Professional, or International Organization for Standardization/International Electrotechnical Commission 42001 Lead Implementer or Lead Auditor
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.