Manager, Security Governance Risk and Compliance
Remote work opportunity. Join KPMG’s Enterprise Security Services organization to lead security governance, risk, and compliance initiatives across a large professional services environment.
Responsibilities
- Apply a thorough knowledge of risk, compliance, and information security to develop and execute a multi-disciplined IT and Security Risk Management implementation plan, enabling leadership to make informed risk-based decisions across a broad range of risk categories.
- Build and maintain trust-based relationships with peers and leaders; evaluate risk reduction activities to drive continuous improvement in risk posture.
- Analyze key risks, define trade‑off criteria, and recommend actions to minimize overall risk posture; defend KPMG security capabilities to external entities as needed.
- Assess the changing operating landscape, determine its impacts on organizational risks and obligations, and recommend adaptation of risk approaches to align with current IT and security best practices.
- Collaborate with second- and third-line defense to ensure organizational risk measures and internal audit activities measure and evaluate appropriate risk areas.
- Lead small to medium‑sized projects, manage deadlines and expectations, and mentor junior staff, potentially serving as a formal performance manager.
- Act with integrity, professionalism, and personal responsibility to uphold KPMG’s respectful and courteous work environment.
Qualifications
Minimum five years of recent risk and compliance experience in a large professional services environment specializing in physical and cyber security.Bachelor’s degree preferred; relevant industry certifications (CISA, CISM, CISSP, ISO 27001 / 42001 Lead Auditor) preferred.Demonstrated understanding of disparate compliance frameworks and risk management principles, with experience making decisions to optimize overall operational risk.Ability to analyze and synthesize technical data and convey it to non‑technical audiences; understanding of key business objectives and balancing them against IT risks.Experience with ISO 27001 (Information Security and Privacy) and / or ISO 42001 (Artificial Intelligence) evaluation, mitigating controls, and remediation facilitation preferred.Strong verbal and written communication, problem‑solving, analytical and independent judgment skills; ability to positively influence, mentor, and serve as a credible source of knowledge to less experienced team members.Must be authorized to work in the U.S. without the need for employment‑based visa sponsorship now or in the future. KPMG will not sponsor applicants for U.S. work visa status for this opportunity.Equal Employment Opportunity and diversity statement : KPMG is an equal opportunity employer and complies with all applicable federal, state, and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state, and local laws.
#J-18808-Ljbffr