KPMG Ukraine

Information Risk Assessment - Assistant Manager - MFT - KGS CH

KPMG Ukraine  •  Bengaluru, IN (Onsite)  •  6 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

This is an assistant manager role in the Information Risk Assessment team, helping to provide information risk assessments by supporting how the firm identifies and analyses information security threats and risks to KPMG and client information in projects, initiatives, applications and IT resources, to advise on the controls necessary to keep these risks within agreed limits. The role holder will provide support for the day-to-day service, to support the Information Risk Assessments Manager ensuring risks are identified and are entered into the Information Risk Assessment tool.

Key Activities include:

  • Conduct Information Security Risk assessments of the technologies used.
  • Supplier information risk assessments are completed in line with the inherent risk rating.
  • Appropriate information security contractual clauses are used in any formal agreement.
  • Provide support to the Information Risk Assessments Manager. Working within agreed timescales, and keeping the Information Risk Assessments on track within agreed SLA’s with business stakeholders.

Technical Information Risk Assessment

  • Along with other Risk Assessors, responsible for performing risk assessments upon projects, suppliers and hybrid (technology projects with a supplier), KPMG managed technology solutions, managing demand and prioritising assessment appropriately.
  • Provide guidance towards completing risk assessments
  • Provide consulting advice to CTO’s, Technology Engineering and Operations, business service owners and 3rd parties on how best to implement the firm’s information security policies
  • Support the firm’s mission to build client trust and confidence with regard to information security generally and information risk assessment specifically
  • Stay abreast of industry best practice in relation to information risk assessments
  • Support the delivery of a high-quality and timely information risk assessment service to the firm.
  • Promote good information security practices and standards across the firm.

Information Risk Management

  • Proactively foster an environment that drives appropriate information risk control behaviour, including early anticipation, identification and mitigation of information risk, as well as escalation of issues in line with the Information Risk Management Framework.
  • Support the ongoing development and maintenance of the firm’s Information Risk Management Framework, including its supporting methodologies, processes and artefacts.

Co-ordination

  • Working with Project Team and requestors to ensure the accuracy of Risk Assessment forms, managing expectations, clarifying timelines and obtaining artefacts for the Risk Assessment Process.
  • Ensure teams understand the Information Risk Assessment process and manage the process for specific assessments.
  • Support the Information Risk Assessment team with other ad hoc work as required.

Awareness and collaboration

  • Establish strong relationships with business, functional teams and other relevant stakeholders.
  • Build on and preserve the firm’s reputation with third-party suppliers around information security.

Technical knowledge and qualifications

  • A minimum of 3 years’ experience of technical information security risk assessments required.
  • Good working knowledge of industry best practice around information security controls covering: cloud security, network security, application security, encryption, information security testing, vulnerability management, access governance, and SaaS assurance.
  • Familiarity with information security standards (e.g. Cyber Essentials, ISO 27001, NIST Cybersecurity Framework, CIS Top 20 Controls).
  • Understanding of personal data and privacy.
  • Security certifications desirable.
  • Excellent English-language communication skills essential – both spoken and written.
  • Diligent and focused, with the ability to prioritise multiple tasks and manage multiple risk assessments concurrently by themselves.
  • Ability to deal with a broad range of stakeholders at all levels, both internal and external, in a confident and assured manner. Happy to engage, manage, chase and communicate with stakeholders.
  • Good team player who is enthusiastic about engaging with the wider Information Risk Assessment team, and with the ability to act independently and exercise sound judgment.
  • Assertive, by being able to articulate technical concerns with stakeholders.
  • Strong analytical and problem-solving skills, with excellent attention to detail.
  • Proven ability to identify and articulate information security requirements, risks and issues, and formulate clear decisions and recommendations.
  • Ability to understand business drivers and risk appetite, in order to make informed risk assessment decisions.
  • Covering at least 75% of UK working hours.
  • Willing and able to obtain BPSS clearance for the UK.

Personal qualities and leadership skills

  • Excellent English-language communication skills essential – both spoken and written.
  • Diligent and focused, with the ability to prioritise multiple tasks and manage multiple risk assessments concurrently by themselves.
  • Ability to deal with a broad range of stakeholders at all levels, both internal and external, in a confident and assured manner. Happy to engage, manage, chase and communicate with stakeholders.
  • Good team player who is enthusiastic about engaging with the wider Information Risk Assessment team, and with the ability to act independently and exercise sound judgment.
  • Assertive, by being able to articulate technical concerns with stakeholders.

Analytical skills

  • Strong analytical and problem-solving skills, with excellent attention to detail.
  • Proven ability to identify and articulate information security requirements, risks and issues, and formulate clear decisions and recommendations.
  • Ability to understand business drivers and risk appetite, in order to make informed risk assessment decisions.

Other requirements

  • Covering at least 75% of UK working hours.
  • Willing and able to obtain BPSS clearance for the UK.
KPMG Ukraine

About KPMG Ukraine

KPMG – це міжнародна мережа фірм, що надають аудиторські, податкові та консультаційні послуги. В офісах KPMG у 143 країнах світу працюють понад 273,000 співробітників (FY23). Кожна фірма KPMG є незалежною юридичною особою і представляє себе як таку.

KPMG працює в Україні з 1992 року. KPMG в Україні надає аудиторські, податкові, бухгалтерські та консультаційні послуги для місцевих і міжнародних компаній. Нашою метою завжди було використання глобального інтелектуального потенціалу фірми в поєднанні з практичним досвідом наших українських професіоналів, щоб допомогти провідним компаніям досягти своїх цілей.

Офіси компанії знаходяться у Києві та Львові.

______________

KPMG is a global network of professional services firms providing audit, tax and advisory services. We operate in 143 countries and territories, and in FY23, collectively employed more than 273,000 people working in member firms around the world.

KPMG in Ukraine provides audit, tax, accounting and advisory services to local and international businesses. KPMG has been working in Ukraine since 1992, and our goal has always been to use the firm's global intellectual potential, combined with the practical experience of our Ukrainian professionals, to help leading companies to achieve their goals.

In Ukraine KPMG has its offices in Kyiv and Lviv.

Industry
Consulting & Advisory
Company Size
201-500 employees
Headquarters
Kyiv, UA
Year Founded
1992
Website
kpmg.com
Social Media