•
Proposed designation: Associate Director- Information Security
& Data Privacy
•
Role type:
Supervisory-Managing the team consisting of 2 Managers, 1 Sr Executive and
2 CWKs.
•
Reporting to: NITSO
•
Geo to be supported:
US/UK/ROW/Across geos
•
Work timings: Flexible. Work from office atleast 2 days.
Roles & responsibilities
•
Governance: Accountability for the management of information security
within the KPMG member firm, with the mandate from senior leadership,
including strategy and planning, monitoring and maintenance, investments,
projects and communication.
•
Information Security Risk Management: Oversight of information security
risk management through risk assessment, including approval of key risks,
involvement in information security related escalations, review of
contractual terms, response to client questionnaires and RFP,
accountability for review of suppliers and acquisitions.
•
Compliance to Policies and Standards: Responsibility for supporting
ongoing information security compliance initiatives, including policies
and standards related to information security, technology, data governance
and privacy
•
Technology Approvals: Accountability for the review and approval of
technology in relation to information security risks, including
involvement and review of technology projects, approval of significant
changes to technology environments, approval of cloud environments, and
approval of Global Technology Standard exceptions.
•
Security Operations: Accountability for security operations, working with
technology teams to ensure that technical & information security
compliance standards are met on an ongoing basis.
•
Incident Management: Coordinates the local Member Firm incident response
processes, including escalation to global (GSOC) where necessary and
conducting readiness rehearsals within the KPMG member firm.
Awareness: Accountability for security awareness training program within
the KPMG member firm, including the coordination of phishing campaigns.
Also, accountability for awareness of external threats through the
management of Threat Intelligence relate to the KPMG member firm or
cluster of member firms
This role is for you if you have
the below
Educational qualifications
•
Minimum Bachelor's degree in Computer Science, Information Technology or
MCA.
•
Hold industry standard accreditation or certifications. (i.e., CISSP,
CISM, ISO 27001)
•
Be familiar with current data privacy regulations, including GDPR, DPDPA
Work experience
•
Should have a minimum of 13 years’ experience within information security
and risk management.
•
Have understanding and experience with Secure SDLC and DevSecOps or
security automation.
Strong background in Information Security, Risk Management, and Data
Privacy
• Expertise in
ISO 27001
, NIST, SOC2,
GDPR, DPDPA
, and related frameworks
• Experience with Cloud Security, DevSecOps, Security Automation, Identity
& Access Management, and Security Governance
• Professional certifications such as CISSP, CISM, or ISO 27001 preferred
•
Be capable of understanding and communicating the business and profit
impact that infosec operations have on the organization
•
Understand the requirements of relevant information security frameworks
and attestations including for example ISO 27001, NIST, SOC2, SoQM
•
The official language of KPMG International is English; therefore,
appropriate written and verbal skills in English are needed.
•
Knowledge of cloud security and governance tools, cloud access security
brokers (CASBs), and server virtualization technologies.
•
Strong experience with Directories, SSO, Federation, Delegated
administration, API gateways
•
Good understanding of cloud computing architecture, technical design and
implementations, including Infrastructure as a Service (IaaS), Platform as
a Service (PaaS) and Software as a Service (SaaS) delivery models