Share this Job

Technical Security Consultant - Information Risk Assessments (Manager)

Date: Jan 19, 2021

Location: London, United Kingdom

Company: KPMG UK

Location: UK Wide

The Role

The role holder will be a manager in the Information Risk Assessment team, leading on information risk assessments. This is to support how the firm identifies and analyses information security threats and risks to KPMG and client information in projects, initiatives, applications, IT resources, and Third Parties. The outcome of this is to advise on the controls necessary to keep these risks within agreed limits.

The role holder will provide support for the day-to-day service, providing consultancy advice to stakeholders and ensuring risks identified are entered into the Information Risk Register. The role holder will be expected to deputise for the Information Risk Assessment Manager (Lead) when required, and provide mentoring and support to the Assistant Information Risk Assessment Managers in the team.

Key Stakeholders

Chief Information Security Officer, Head of Information Assurance, and Head of Security Operations
Business and functional managers across the firm including Project Managers, BISOs (Business Information Security Officers), Procurement, and Supplier Managers
Chief Information Officer, and the IT Service Provider community in the firm
Senior Managers, Directors, and Partners from across the UK firm, KPMG Global, and other KPMG member firms who act as Information/Application/Product Owners

Key Responsibilities

Information Risk Assessment

- Lead on the delivery of information risk assessments
- Support the delivery of a highly quality and timely information risk assessment (including Business Impact Assessment) service to the firm
- Support the requirements of the firm’s information risk management framework, to ensure a consistent and structured approach to information risk management is taken across the firm
- Provide consulting advice to project managers and other stakeholders on how best to implement the firm’s information security policies
- Support the firm’s mission to build client trust and confidence with regard to information security generally and information risk assessment specifically
- Stay abreast of industry best practice in relation to information risk assessment
Policy

- Support the development of the UK firm’s information security policies
- Promote good information security practice and standards across the firm
- Risk management
- Proactively foster an environment that drives appropriate information risk control behaviour, including early anticipation, identification and mitigation of information risk, escalating issues in line with the Information Risk Management Framework.
- Support the on-going development and maintenance of the firm’s Information Risk Management Framework, including its supporting methodologies, processes and artefacts.
Awareness and collaboration

- Establish strong relationships with business and functional teams
- Establish effective relationships with IT service providers and other relevant stakeholders
- Build on and preserve the firm’s reputation with clients, with regard to information security
Knowledge, Experience and Skills

Technical knowledge and qualifications

- Proven experience of information security with at least 1 year in a specific information risk assessment capacity
- Strong knowledge of information security standards (e.g. Cyber Essentials, ISF Standard of Good Practice for Information Security, ISO 27001, NIST Cybersecurity Framework, CIS Top 20 Controls)
- Strong understanding of privacy requirements (including GDPR)
- Strong working knowledge of the IT security aspects of IT infrastructure (network and servers) and services, including Cloud computing
- Security certifications essential (CISSP, CRISC or equivalents)
Leadership skills

- Experience of providing guidance, mentoring and planning
- Strong influencing skills
- Ability to deal with a broad range of stakeholders at all levels, both internal and external, in a confident and assured manner
- Ability to prioritise and manage a complex workload, including multiple tasks for themselves.
Analytical skills

- Strong analytical and problem solving skills
- Proven ability to identify and articulate information security requirements, risks and issues, and to make clear decisions and recommendations
- Ability to understand business drivers and risk appetite and to align threat intelligence accordingly
Personal qualities

- A good team player, with the ability to act independently and exercise sound judgment
- Excellent communication skills, both written and verbal
- Multi-cultural awareness and sensitivity
- Strong integrity, independence and resilience
- Excellent attention to detail combined with strategic vision


Job Segment: Risk Management, Information Technology, IT Manager, Consulting, Finance, Technology, Security