Minimum of 8 years of extensive experience in information protection and risk management and /or assurance, including minimum of 6 years of experience in information protection controls assessments, with demonstrated depth in ISO/IEC 27001 auditing and /or implementation and complex or judgment intensive reviews based on leading industry practices for internal audits and external / supplier audits.
Advanced and well-rounded expertise in information security and privacy, with the ability to interpret requirements and risks in complex, global, and non-standard scenarios.
Proven ability to function as a senior risk-based Quality Assessment (QA) reviewer of information controls audits, consistently exercising professional skepticism and independent judgment beyond procedural compliance, including the ability to:
Differentiate between technical noncompliance, actual risk exposure, significant control weaknesses, and documentation or evidentiary quality gaps
Identify and assess misalignment between local control interpretations and global SOQM expectations
Detect nuanced quality concerns such as unsupported assumptions, circular reasoning, weak analytic logic, or evidence that does not substantiate conclusions
Strong understanding of information security and data protection contractual requirements of third party suppliers and their translation into risk‑based assessment outcomes.
Experience reviewing independent assurance reports for information security and privacy areas (e.g. ISO 27001, SOC 2), including scope considerations, exceptions and residual risks.
Experience engaging with senior stakeholders and external third parties to communicate complex risk and assurance outcomes.
Highly developed written and verbal communication skills in English, with demonstrated strength in executive level reporting; excellent command of M365 tools, including Word, PowerPoint, Excel, Teams, and Copilot.
Ability to operate autonomously within a global delivery model, while effectively collaborating with diverse teams across geographies and time zones.
Prior supplier audit and/or third-party risk assessment experience strongly preferred; professional certifications such as ISO 27001:2022 Lead Auditor and/or ISO 42001 / AI Lead Auditor are a plus.
Prior experience with KPMG or another Big 4 organization preferred. Strong and practical familiarity with KPMG Global Information Security and Privacy Policies and frameworks, including Global Information Security Policies (GISP), Global Acceptable Use Policies (GAUP), and their application within a global System of Quality Management (SoQM) a plus.
Strong personal accountability combined with a collaborative leadership approach and well-developed stakeholder management skills, including comfort engaging at senior levels.
Highly adaptive, capable of quickly assimilating new subject matter, with strong attention to detail and ability to maintain integrity and quality across multiple workstreams.
Provide guidance in assessing evidence provided, in particular independent assurance evidence (e.g. ISO, SOC reports), including appropriateness of reliance and residual risk implications.
Supporting the ongoing evolution of monitoring, Quality Assurance (QA) of reviews that took place as we relevant assurance methodologies.
For GSIPRA program - Plan, execute and report on supplier security assessments / Global Supplier Information Protection Risk Assessments (GSIPRAs) based on risk indicator analysis and the information protection terms of the agreements of the suppliers, including:
monitor and report on remediation progress.
For both IPCR and GSIPRA Programs
Develop executive‑ready reporting that communicates clear, defensible conclusions, often requiring pragmatic judgment, sensitivity to organizational context, and tailored messaging beyond standard templates
Constructively question weak analysis or conclusions, articulating why issues matter from a quality and risk standpoint, and escalating concerns thoughtfully when required. In addition, the role plays a key mentoring function—coaching junior reviewers and managers, reinforcing risk‑based thinking, and elevating documentation quality through consistent, actionable, and educational feedback, while continuing to drive improvements in global monitoring and quality practices
Work efficiently on multiple workstreams based on project plans. Operating autonomously within global teams.
Deliver high‑quality written analysis for senior and global stakeholders, identify themes based on review results.
Partner effectively across teams as a trusted Subject‑Matter Expert (SME)
Support ongoing enhancement of digital risk monitoring and quality practices.
B.E. / B. Tech

KPMG – це міжнародна мережа фірм, що надають аудиторські, податкові та консультаційні послуги. В офісах KPMG у 143 країнах світу працюють понад 273,000 співробітників (FY23). Кожна фірма KPMG є незалежною юридичною особою і представляє себе як таку.
KPMG працює в Україні з 1992 року. KPMG в Україні надає аудиторські, податкові, бухгалтерські та консультаційні послуги для місцевих і міжнародних компаній. Нашою метою завжди було використання глобального інтелектуального потенціалу фірми в поєднанні з практичним досвідом наших українських професіоналів, щоб допомогти провідним компаніям досягти своїх цілей.
Офіси компанії знаходяться у Києві та Львові.
______________
KPMG is a global network of professional services firms providing audit, tax and advisory services. We operate in 143 countries and territories, and in FY23, collectively employed more than 273,000 people working in member firms around the world.
KPMG in Ukraine provides audit, tax, accounting and advisory services to local and international businesses. KPMG has been working in Ukraine since 1992, and our goal has always been to use the firm's global intellectual potential, combined with the practical experience of our Ukrainian professionals, to help leading companies to achieve their goals.
In Ukraine KPMG has its offices in Kyiv and Lviv.