Loading open roles
Loading open roles
Loading role

KPMG · posted 3 days ago
Role Summary"-
The Associate Director will lead the design, implementation,
governance, and continuous improvement of Information Security and
Data Privacy programs across the organization. The role is responsible
for ensuring compliance with global security standards, regulatory
requirements, and client contractual obligations while enabling
business growth through secure and resilient technology practices.
The individual will partner with senior leadership, technology teams,
business stakeholders, legal, risk, and global member firms to
strengthen the firm's security posture, manage cyber risks, and drive
strategic security initiatives.
Responsibilities
Key Responsibilities:
Information Security Governance----
Lead the implementation and continuous enhancement of the Information
Security Management System (ISMS).
Develop, review, and maintain enterprise information security
policies, standards, procedures, and guidelines.
Drive security governance aligned with ISO 27001, NIST CSF, CIS
Controls, and industry best practices.
Present security metrics, risk posture, and strategic updates to
executive leadership.
Data Privacy & Regulatory Compliance---
Ensure compliance with applicable privacy regulations including
GDPR, DPDP Act (India), UK GDPR, and other global privacy
requirements.
Collaborate with Legal, Compliance, and business teams on privacy
impact assessments and data protection initiatives.
Oversee data classification, retention, secure disposal, and data
handling practices.
Support client due diligence, privacy assessments, and regulatory
audits.
Security Risk Management--
Lead enterprise risk assessments and third-party security reviews.
Manage remediation of security findings and monitor risk treatment
plans.
Provide strategic guidance on emerging cyber threats and security
controls.
Evaluate security implications of new technologies and business
initiatives.
Security Operations & Incident Management---
Provide executive oversight of security incidents, investigations, and
root cause analysis.
Coordinate incident response activities with internal and external
stakeholders.
Ensure lessons learned are incorporated into security controls and
processes.
Monitor key security performance indicators and drive continual
improvement.
Security Architecture & Technology--
Review and approve security architecture for cloud, applications,
infrastructure, and digital transformation initiatives.
Promote Secure-by-Design and Privacy-by-Design principles across
projects.
Provide strategic oversight on identity and access management,
endpoint security, network security, encryption, DLP, and cloud
security.
Audit & Assurance...
Lead internal and external security audits.
Coordinate responses to client security questionnaires and assurance
requests.
Track audit observations and ensure timely remediation.
Support certifications and compliance initiatives.
Required Qualifications--
Bachelor's degree in Computer Science, Information Technology, Cyber
Security, or a related discipline.
Master's degree or MBA preferred.
14+ years of experience in
Information Security, Cyber Security, Risk Management, or Data
Privacy.
At least 5 years of leadership or people management experience.
Preferred Certifications
CISSP
CISM
ISO/IEC 27001 Lead Implementer or Lead Auditor
CCSP or equivalent cloud security certification
Privacy certifications such as CIPP/E or CIPP/A are desirable.
Information Security Governance
Cyber Risk Management
Data Privacy & Regulatory Compliance
Security Operations & Incident Response
Business Continuity & Disaster Recovery
Data Loss Prevention (DLP)
Strong communication and presentation skills