KPMG Ukraine

Associate Director- GTS Security Architect

KPMG Ukraine  •  Hyderabad, IN (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Roles & responsibilities

  1. Security Architecture & Design

Own, govern, and continuously evolve security architecture standards, patterns, reference architectures, and implementation guidance.

Ensure security requirements are integrated throughout the Secure/System Development lifecycle (S/SDLC).

Review and approve solution architectures and act as the final design authority for enterprise security standards.

Define security requirements for cloud-native, hybrid-cloud, SaaS, and on-premises solutions.

Design security architectures that support confidentiality, integrity, availability, and regulatory compliance requirements.

Set the technology direction by evaluating emerging technologies and recommending security controls and architectures to mitigate risks.

  1. Cloud Security & DevSecOps

Act as the principal Subject Matter Expert (SME) for cloud security across Azure, AWS, and GCP.

Provide guidance on secure cloud architecture, workload protection, identity security, data protection, and network security.

Partner with engineering teams to integrate security controls into CI/CD pipelines and DevSecOps processes.

Promote Infrastructure-as-Code (IaC) security practices and automated security validation.

  1. Risk & Compliance

Lead security architecture reviews and identify design-level risks across the portfolio.

Develop remediation recommendations and risk treatment strategies.

Support industry standard compliance e.g. SOC 1 / SOC 2, ISO, COBIT, NIST, CIS, GDPR.

Define and implement compensating controls where required.

Partner with risk management and audit leadership to address security findings and drive remediation to closure.

  1. Application Security

Review application designs for secure coding and architectural vulnerabilities.

Partner with development teams to implement secure development lifecycle practices.

Evaluate authentication, authorization, encryption, API security, and secrets management strategies.

Support threat modeling exercises and security design reviews.

Assess application architectures against OWASP Top 10 and industry best practices.

  1. Security Governance

Own and mature the security architecture governance process across the organization.

Chair or lead architecture review boards and change advisory activities.

Ensure alignment between business objectives and cybersecurity requirements.

Support development and maintenance of security policies, standards, and technical guidelines.

  1. Stakeholder Engagement

Engage senior business leaders, application owners, infrastructure teams, audit teams, and cybersecurity functions.

Communicate security risks and recommendations to both technical and non-technical stakeholders.

Act as a trusted advisor to senior leadership on security architecture and strategic technology investments.

Lead, mentor, and develop architects and engineering teams on security best practices.

Roles & responsibilities

  1. Security Architecture & Design

Own, govern, and continuously evolve security architecture standards, patterns, reference architectures, and implementation guidance.

Ensure security requirements are integrated throughout the Secure/System Development lifecycle (S/SDLC).

Review and approve solution architectures and act as the final design authority for enterprise security standards.

Define security requirements for cloud-native, hybrid-cloud, SaaS, and on-premises solutions.

Design security architectures that support confidentiality, integrity, availability, and regulatory compliance requirements.

Set the technology direction by evaluating emerging technologies and recommending security controls and architectures to mitigate risks.

  1. Cloud Security & DevSecOps

Act as the principal Subject Matter Expert (SME) for cloud security across Azure, AWS, and GCP.

Provide guidance on secure cloud architecture, workload protection, identity security, data protection, and network security.

Partner with engineering teams to integrate security controls into CI/CD pipelines and DevSecOps processes.

Promote Infrastructure-as-Code (IaC) security practices and automated security validation.

  1. Risk & Compliance

Lead security architecture reviews and identify design-level risks across the portfolio.

Develop remediation recommendations and risk treatment strategies.

Support industry standard compliance e.g. SOC 1 / SOC 2, ISO, COBIT, NIST, CIS, GDPR.

Define and implement compensating controls where required.

Partner with risk management and audit leadership to address security findings and drive remediation to closure.

  1. Application Security

Review application designs for secure coding and architectural vulnerabilities.

Partner with development teams to implement secure development lifecycle practices.

Evaluate authentication, authorization, encryption, API security, and secrets management strategies.

Support threat modeling exercises and security design reviews.

Assess application architectures against OWASP Top 10 and industry best practices.

  1. Security Governance

Own and mature the security architecture governance process across the organization.

Chair or lead architecture review boards and change advisory activities.

Ensure alignment between business objectives and cybersecurity requirements.

Support development and maintenance of security policies, standards, and technical guidelines.

  1. Stakeholder Engagement

Engage senior business leaders, application owners, infrastructure teams, audit teams, and cybersecurity functions.

Communicate security risks and recommendations to both technical and non-technical stakeholders.

Act as a trusted advisor to senior leadership on security architecture and strategic technology investments.

Lead, mentor, and develop architects and engineering teams on security best practices.

Mandatory technical & functional skills

Strong expertise in security architecture across enterprise, solution, and cloud environments.

Deep hands-on experience with Microsoft Azure, AWS, and Google Cloud Platform (GCP).

Strong knowledge of:

NIST CSF, NIST SP 800-53, NIST SSDF, ISO 27001/27002, SABSA, TOGAF

Zero Trust Architecture and secure-by-design principles

Cloud, network, application, and data security

Identity, privileged access, and key management

Solid understanding of security monitoring and detection, vulnerability management, and cryptography.

Proficiency in security architecture documentation, patterns, and reference architectures.

This role is for you if you have the below

Educational qualifications

Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, Engineering, or a related field (Master’s preferred).

Work experience

14+ years of overall IT experience, including 8+ years in security architecture.

Proven experience leading enterprise-scale security architecture programs across cloud and on-premises platforms.

Experience leading architecture review boards, risk assessments, and embedding security into Agile and DevSecOps delivery.

KPMG Ukraine

About KPMG Ukraine

KPMG – це міжнародна мережа фірм, що надають аудиторські, податкові та консультаційні послуги. В офісах KPMG у 143 країнах світу працюють понад 273,000 співробітників (FY23). Кожна фірма KPMG є незалежною юридичною особою і представляє себе як таку.

KPMG працює в Україні з 1992 року. KPMG в Україні надає аудиторські, податкові, бухгалтерські та консультаційні послуги для місцевих і міжнародних компаній. Нашою метою завжди було використання глобального інтелектуального потенціалу фірми в поєднанні з практичним досвідом наших українських професіоналів, щоб допомогти провідним компаніям досягти своїх цілей.

Офіси компанії знаходяться у Києві та Львові.

______________

KPMG is a global network of professional services firms providing audit, tax and advisory services. We operate in 143 countries and territories, and in FY23, collectively employed more than 273,000 people working in member firms around the world.

KPMG in Ukraine provides audit, tax, accounting and advisory services to local and international businesses. KPMG has been working in Ukraine since 1992, and our goal has always been to use the firm's global intellectual potential, combined with the practical experience of our Ukrainian professionals, to help leading companies to achieve their goals.

In Ukraine KPMG has its offices in Kyiv and Lviv.

Industry
Consulting & Advisory
Company Size
201-500 employees
Headquarters
Kyiv, UA
Year Founded
1992
Website
kpmg.com
Social Media