About this role
This is an assistant manager role in the Information Risk Assessment team, helping to provide information risk assessments by supporting how the firm identifies and analyses information security threats and risks to KPMG and client information in projects, initiatives, applications and IT resources, to advise on the controls necessary to keep these risks within agreed limits. The role holder will provide support for the day-to-day service, to support the Information Risk Assessments Manager ensuring risks are identified and are entered into the Information Risk Assessment tool.
Key Activities include:
- Conduct Information Security Risk assessments of the technologies used.
- Supplier information risk assessments are completed in line with the inherent risk rating.
- Appropriate information security contractual clauses are used in any formal agreement.
- Provide support to the Information Risk Assessments Manager. Working within agreed timescales, and keeping the Information Risk Assessments on track within agreed SLA’s with business stakeholders.
Technical knowledge and qualifications
- A minimum of 3 years’ experience of technical information security risk assessments required.
- Good working knowledge of industry best practice around information security controls covering: cloud security, network security, application security, encryption, information security testing, vulnerability management, access governance, and SaaS assurance.
- Familiarity with information security standards (e.g. Cyber Essentials, ISO 27001, NIST Cybersecurity Framework, CIS Top 20 Controls).
- Understanding of personal data and privacy.
- Security certifications desirable.
- Excellent English-language communication skills essential – both spoken and written.
- Diligent and focused, with the ability to prioritise multiple tasks and manage multiple risk assessments concurrently by themselves.
- Ability to deal with a broad range of stakeholders at all levels, both internal and external, in a confident and assured manner. Happy to engage, manage, chase and communicate with stakeholders.
- Good team player who is enthusiastic about engaging with the wider Information Risk Assessment team, and with the ability to act independently and exercise sound judgment.
- Assertive, by being able to articulate technical concerns with stakeholders.
- Strong analytical and problem-solving skills, with excellent attention to detail.
- Proven ability to identify and articulate information security requirements, risks and issues, and formulate clear decisions and recommendations.
- Ability to understand business drivers and risk appetite, in order to make informed risk assessment decisions.
- Covering at least 75% of UK working hours.
- Willing and able to obtain BPSS clearance for the UK.
Personal qualities and leadership skills
- Excellent English-language communication skills essential – both spoken and written.
- Diligent and focused, with the ability to prioritise multiple tasks and manage multiple risk assessments concurrently by themselves.
- Ability to deal with a broad range of stakeholders at all levels, both internal and external, in a confident and assured manner. Happy to engage, manage, chase and communicate with stakeholders.
- Good team player who is enthusiastic about engaging with the wider Information Risk Assessment team, and with the ability to act independently and exercise sound judgment.
- Assertive, by being able to articulate technical concerns with stakeholders.
Analytical skills
- Strong analytical and problem-solving skills, with excellent attention to detail.
- Proven ability to identify and articulate information security requirements, risks and issues, and formulate clear decisions and recommendations.
- Ability to understand business drivers and risk appetite, in order to make informed risk assessment decisions.
Other requirements
- Covering at least 75% of UK working hours.
- Willing and able to obtain BPSS clearance for the UK.