Job Directory Policies and Standards Leader

Policies and Standards Leader
Chicago, IL

Companies like
are looking for tech talent like you.

On Hired, employers apply to you with up-front salaries.
Sign up to start matching for free.


Job Description

Deloitte leads with purpose, solving complex issues for our clients and communities. Across disciplines and across borders, Deloitte Touche Tohmatsu Limited (DTTL) Global supports our network of national member firms by developing and driving global strategy, programs, and platforms, and creating new solutions and transformational experiences. Our people share a passion for igniting change and a strong service orientation that shapes our organization and those it supports.

Work you'll do:

The Policies and Standards Leader reports to the Cybersecurity Strategy & Governance Leader. The role focuses on defining and maintaining cybersecurity policies and standards that all member firms are required to follow and managing the exceptions process when member firms cannot or will not comply.

As part of the Global Cybersecurity team, this professional:


* Identifies key cybersecurity controls required for Deloitte based on an understanding of the firms cybersecurity risks and business objectives, and considering key threats, client requirements, regulatory requirements and technology trends


* Creates and maintains cybersecurity policies and standards that all member firms are required to follow (excluding Member Firm Standards)
* Helps to resolve cybersecurity policy and standard deployment challenges and risks
* Understands and interacts with related disciplines through committees to ensure the consistent application of cybersecurity policies and standards across all technology projects, systems and services, including privacy, risk management, compliance and business continuity management
* Defines and manages the exception process for cybersecurity policies and standards when member firms cannot or will not comply
* Track and report on member firm exceptions to cybersecurity policies and standards

Relationship Management

* Works closely with the other direct reports of the Cybersecurity Strategy & Governance Leader to ensure collaboration and alignment
* Works closely with CAP & Strategic Programs Leader to ensure set up of needed programs to drive implementation of policies and standards across the Deloitte network
* Works closely with the Architecture Leader and Engineering Leader to ensure that architectures and solution designs embed the controls defined within cybersecurity policies and standards
* Works closely with member firms to understand their needs and challenges in relation to cybersecurity policies and standards
* Works with Cybersecurity Risk Management Leader

What you'll be part of-our Deloitte Global culture:

At Deloitte, we expect results. Incredible-tangible-results. And Deloitte Global professionals play a unique role in delivering those results. We reach across disciplines and borders to serve our global organization. We are the engine of Deloitte. We develop and lead global strategies and provide programs and services that unite our network.

In Deloitte Global, everyone has an opportunity to lead. We see the importance of your perspective and your ability to create value. We want you to fit in-with an inclusive culture, focus on work-life fit and well-being, and a supportive, connected environment; but we also want you to stand out-with opportunities to have a strategic impact, innovate, and take the risks necessary to make your mark.

Deloitte Global supports our talented professionals in answering the question: What impact will you make?

Expectations from the Professional

Our purpose is to make an impact that matters and our aspiration is to be the undisputed leader in professional services. At the root of these goals are our Shared Values, which describe the distinctive Deloitte culture. Our Values are timeless, all-encompassing and embrace the cultures in which Deloitte member firms operate. We expect all professionals to live our purpose and shared values and be the brand ambassadors holding Deloitte Global and member firms together.


At Deloitte, everything we do starts with integrity. In our marketplace, nothing is more important than our reputation and, accordingly, we commit to conducting business with honesty, distinctive quality, and high levels of professional behavior.

Outstanding value to markets and clients

We play a critical role in helping both the capital markets and our member firm clients operate more effectively. We consider this role a privilege, and we know it requires constant vigilance and unrelenting commitment.

Commitment to each other

We are proud of our culture of borderless collegiality and work hard to support our people. We strive to create an inclusive environment that reflects our strong, clear expectations about diversity, respect, and fair treatment.

Strength from cultural diversity

Our member firm clients' business challenges are complex and benefit from the innovation and varied perspectives that our practitioners bring. We understand that working with people of different backgrounds, cultures, and thinking styles helps our people grow into better professionals and leaders.

Who you'll work with:

The Deloitte Global Cybersecurity function is responsible for the firm's overall objectives of enhancing data protection, standardizing and securing critical infrastructure and gaining cyber visibility through security operations centers. The Cybersecurity organization delivers a comprehensive set of cybersecurity services to Deloitte member firms through regional delivery hubs and a Global Fusion Center. We are seeking a Policies and Standards Leader to join this team.

How you'll grow:

Deloitte Global inspires leaders at every level. We believe in investing in you, helping you embrace leadership opportunities at every step of your career, and helping you identify and hone your unique strengths. We encourage you to grow by providing formal and informal development programs, coaching and mentoring, and on-the-job challenges. We want you to ask questions, take chances, and explore the possible.

Benefits you'll receive:

Deloitte's Total Rewards program reflects our continued commitment to lead from the front in everything we do - that's why we take pride in offering a comprehensive variety of programs and resources to support your health and well-being needs. We provide the benefits, competitive compensation, and recognition to help sustain your efforts in making an impact that matters.



* Bachelor's degree: degree in business administration, a technology-related field, or equivalent education-related experience
* Master's degree preferred

Work experience

* Minimum of 12 years of combined experience in the Information Security / Cybersecurity domain with a focus on policies and standard setting
* At least five years holding a management and leadership role
* Proven track record and experience of the following in a highly complex and global organization:
* developing and driving the adoption of information security policies and standards and related exemptions processes
* connecting closely with operational leadership to make policies and standards relevant for day-to-day operations


* Professional security management certification strongly desirable, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials
* Member of IISP or have the qualification, skills and experience to become a member


* Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate strategic information security topics, policies and standards as well as risk-related concepts to technical and nontechnical audiences at various hierarchical levels
* Sound knowledge of business management and an expert knowledge of information / cybersecurity policies and standards
* Strong knowledge and understanding of information security legal and regulatory requirements, such as Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA) and Payment Card Industry/Data Security Standard
* Knowledge of common information security management frameworks, such as ISO/IEC 27001, COBIT, and NIST, including 800-53 and the Cybersecurity Framework
* Experience interacting, presenting and working with C-level executives (CEO, CIO, etc.).
* Ability to manage a global team in a matrix environment
* Ability to travel as needed up to 40%

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Disclaimer: Nothing in this job description/posting shall constitute an offer or promise of employment. If you are not reviewing this job posting on our Careers' site ( or one of our approved job boards we cannot guarantee the validity of this posting. For a list of our current postings, please visit us at

Requisition code: DE19USAGTS007LS1842


Let your dream job find you.

Sign up to start matching with top companies. It’s fast and free.