
Minimum 6 years of experience, including minimum 4 years of experience in information security and risk management as well as ISO 27001 and ISO 27017 certification auditing and /or implementing.
ISO 27001:2022 lead auditor or lead implementor certification. ISO 42001 / AI lead auditor or lead implementor a plus.
Excellent communication skills and strong reporting skills in English. Excellent command of M365 tools, e.g. MS Word, PowerPoint, Excel, Teams, and Copilot.
Works independently with a diverse global team. Proactive, can work with minimal supervision, and work in continuous improvements.
Adaptive, quick learner and attention to detail. Accountable and collaborative approach, and with excellent stakeholder management skills.
Experienced working in multicultural environments and sensitive to different business cultures.
Prior KPMG (or Big4) work experience a plus.
Key responsibilities of the role:
Support for ISMS facilitation of group meetings and management reporting, preparation of relevant materials including presentations and minutes of meetings. and maintenance of documentation based on ISO 27001:2022 and ISO 27017:2015 requirements.
Support for the preparatory materials of audits, including those for the ISO re-certification and /or surveillance audits. Produce content, participate, provide input for actions and follow-up on status as needed.
Support for the implementation of potential corrective actions from prior audits and contribute to the continuous improvement cycles by advising on justified potential Opportunities for Improvement (OFIs).
Support for the review of the ISMS framework documentation (Clauses 4-10) and select operational documentation (Annex-A) providing comments, feedback and suggestions for improvements.
Support for the review and updates as needed of the ISMS risk assessment templates and mapping tables (including providing comments, feedback and suggestions for improvements in aligning threat, vulnerabilities, risks and mitigating controls).
Support for the preparation of the ISMS asset review and risk assessment working files based on templates provided by the ISMS Manager (e.g. for assets, entity level, member firms).
Support for the ISMS asset review and risk assessment workshops guiding discussions, offering clarity on requirements and documenting points discussed and actions (i.e. Minutes of Meetings / MoM).
Support for the review of the results of the ISMS asset review and risk assessment to help ensure consistency of threat-vulnerabilities and control effectiveness assessment levels across the registers.
Support for monitoring status of activities and actions noted above and follow up with risk assessors and asset owners as needed.
Support for confirming completeness and thoroughness of the risk assessment process, alignment with the Statement of Applicability (SoA) as per ISO 27001:2022 requirements.
Support for drafting content for ISMS and ISO related contribution to information security awareness materials.
Collaborate across KPMG groups and teams: working closely with extended teams in other global locations, member firms in the KPMG network, and other teams to help support efficient execution of ISMS processes. Anticipate potential challenges, address issues proactively, and inform the ISMS Manager timely for necessary actions or escalations.
Weekly status reporting of ISMS SME Support activities.
B.E. / B.Tech

KPMG – це міжнародна мережа фірм, що надають аудиторські, податкові та консультаційні послуги. В офісах KPMG у 143 країнах світу працюють понад 273,000 співробітників (FY23). Кожна фірма KPMG є незалежною юридичною особою і представляє себе як таку.
KPMG працює в Україні з 1992 року. KPMG в Україні надає аудиторські, податкові, бухгалтерські та консультаційні послуги для місцевих і міжнародних компаній. Нашою метою завжди було використання глобального інтелектуального потенціалу фірми в поєднанні з практичним досвідом наших українських професіоналів, щоб допомогти провідним компаніям досягти своїх цілей.
Офіси компанії знаходяться у Києві та Львові.
______________
KPMG is a global network of professional services firms providing audit, tax and advisory services. We operate in 143 countries and territories, and in FY23, collectively employed more than 273,000 people working in member firms around the world.
KPMG in Ukraine provides audit, tax, accounting and advisory services to local and international businesses. KPMG has been working in Ukraine since 1992, and our goal has always been to use the firm's global intellectual potential, combined with the practical experience of our Ukrainian professionals, to help leading companies to achieve their goals.
In Ukraine KPMG has its offices in Kyiv and Lviv.