We are looking for a cyber strategy professional to join our Strategy & Execution team as an Assistant Manager. The role combines practical cyber security, architecture and privacy expertise with transaction advisory experience. You will support private equity investors and corporate clients across Cyber Due Diligence, post-deal integration and separation, cybersecurity maturity assessments, and privacy assessments based on GDPR and other leading frameworks. Working with multidisciplinary teams, you will assess network security, identity and access management, security operations and other critical controls; translate technical findings into clear business and transaction implications; and help develop pragmatic recommendations, Day 1 priorities and implementation roadmaps. This is an opportunity to broaden your experience across the M&A lifecycle while building deeper capability in cyber strategy, transformation and execution.
Your key responsibilities
•Support global EY practice teams in planning, managing and delivering cybersecurity and privacy engagements across the M&A transaction lifecycle.
•Conduct buy-side, sell-side and red-flag Cyber Due Diligence to identify material risks, assess transaction implications and develop practical recommendations and remediation cost considerations.
•Support cyber workstreams for post-deal integration, carve-out and separation programmes, including Day 1 readiness, 100-day planning, transition-state requirements, TSA dependencies and execution tracking.
•Perform cybersecurity maturity assessments using recognised standards and frameworks; assess current and target states, identify gaps, benchmark capabilities and develop prioritised improvement roadmaps.
•Conduct privacy and data protection assessments against GDPR and other applicable regulations and leading frameworks, covering privacy governance, data lifecycle, third-party processing, cross-border transfers, data subject rights and breach management.
•Assess cybersecurity capabilities and controls across network security, identity and access management, privileged access management, security operations, vulnerability management, incident response, cloud security, endpoint security and data protection.
•Evaluate transaction-related dependencies and risks involving shared infrastructure, applications, identities, security tooling, data, third parties and transitional service arrangements.
•Support the design of target-state security architecture, operating models, governance structures, policies, processes and implementation roadmaps.
•Conduct proportionate outside-in research, including OSINT and dark web analysis, where relevant to the engagement scope.
•Translate complex cybersecurity and privacy observations into clear business risks, transaction implications and actionable recommendations for client stakeholders.
•Prepare high-quality deliverables, including diligence and assessment reports, gap analyses, risk registers, integration and separation plans, workstream trackers, executive presentations and implementation roadmaps.
•Manage assigned work packages, coordinate with client and EY stakeholders, monitor timelines and quality, and provide day-to-day guidance to junior team members.
•Build strong relationships with regional EY-Parthenon practice teams and contribute to proposals, client presentations, methodologies, knowledge assets and other practice-development initiatives.
Skills and attributes for success
•Experience delivering cybersecurity engagements across Cyber Due Diligence, post-deal integration or separation, cybersecurity maturity assessment, privacy assessment or cyber transformation.
•Ability to manage defined workstreams involving client stakeholders and multidisciplinary transaction and advisory teams.
•Strong understanding of security architecture and design principles, including Zero Trust, defence in depth and secure-by-design concepts.
•Ability to facilitate stakeholder discussions, gather and challenge information, present findings, and support decision-making under senior engagement oversight.
•Strong analytical and commercial judgement, with the ability to connect technical findings to business risk, deal value and implementation priorities.
•Clear written and verbal communication skills, with experience producing concise, executive-ready deliverables in PowerPoint, Word and Excel.
•An innovative and collaborative mindset, with the ability to develop practical solutions tailored to client and transaction needs.
•Ability to coach junior team members and contribute to recruitment, training and wider practice-development activities.
•Flexibility to support broader IT, cybersecurity and operational transaction work and to travel internationally when required.
To qualify for the role, you must have
•Four to six years of information and cybersecurity experience, including exposure to M&A, cyber or privacy assessments, security architecture, security operations or related consulting.
•A B.E., B.Tech. or equivalent degree in Computer Science or Information Technology from a reputed institution; an MBA or PGDM from a Tier 1 or Tier 2 institution is preferred.
•A leading cybersecurity qualification, such as CISSP, CISA, CCSP, CISM or ISO 27001 ISMS.
•Knowledge of cybersecurity and privacy requirements, including GDPR, NIS2, CCPA and other relevant regulations and frameworks.
•Experience with recognised cybersecurity frameworks, such as NIST CSF, ISO 27001, CIS Controls and PCI DSS.
•Strong understanding of network and cloud security, IAM and PAM, and security operations—including SIEM, threat monitoring, incident response and vulnerability management; knowledge of OT security is advantageous.
Ideally, you’ll also have
•Project management skills
•Strong communication and presentation skills with proven experience of producing high quality reports, papers, presentations and thought leadership
•Program and project management expertise with demonstrable experience in managing and being responsible for the delivery of successful cyber programs •