Information Protection Assessments - Assistant Manager (Pune)

Information Protection Assessments - Assistant Manager (Pune)

09 Aug
|
BSR
|
Pune

09 Aug

BSR

Pune

Description

- Minimum 6 years of information security and risk experience, including minimum 4 years of experience in information protection controls assessments and ISO 27001 information security controls auditing and /or implementing.

- Strong information security and privacy standards knowledge.

- Excellent information protection risk assessment planning, executing, managing and reporting skills for internal audits as well as third party supplier audits.

- Proven ability to operate as a risk-based Quality Assessment (QA) reviewer of audits performed, applying independent judgment based on leading industry practices. Demonstrated sound professional judgment to evaluate control effectiveness in context, separating isolated procedural issues from matters that present meaningful risk or systemic.

- Ability to assess contractual security obligations and map them to control testing and evidence.

- Experience reviewing and interpreting independent certification and attestation reports (e.g. ISO 27001, SOC 2).

- Understanding of risk‑based scoping approaches, including consideration of supplier risk indicators and service context.

- ISO 27001:2022 lead auditor or lead implementer certification. ISO 42001 / AI lead auditor or lead implementer a plus.

- Prior supplier security assessment experience preferred.

- Prior KPMG (or Big4) work experience a plus. Familiarity with KPMG policies (e.g. Global InfoSec & Privacy Policies, GISP, GAUP) or governance frameworks (e.g. IFDTA) a plus.

- Excellent written and verbal communication skills in English, including solid report writing and the ability to present clearly and confidently to senior stakeholders.

- Proficient in M365 tools (Word, PowerPoint, Excel, Teams, Copilot), with strong capability to produce clear, high‑quality reports and presentations.





- Strong ability to multitask and work independently within a global team. Proactive, can work with minimal supervision, and work on continuous improvements.

- Accountable and collaborative approach, and with excellent stakeholder management skills

- Adaptive, quick learner and attention to detail.

Experienced working in multicultural environments and sensitive to different business cultures.

Responsibilities

Key responsibilities of the “Information Protection Assessments – Manager” role (expected to work approximately 50% on each area):

- For IPCR program - Execute risk‑focused review activities related to information protection (security, and privacy) controls. Responsibilities include:
- Perform risk-based Quality Assessment (QA) reviews of audits/ IPCRs performed, applying independent judgment based on leading practices:

- Distinguish between technical non-compliance, risk, significant weaknesses, and documentation quality gaps.
- Identify misalignment between local (member firm) control interpretations and Global expectations (e.g. System of Quality Management / SoQM).
- Identify subtle issues such as unsupported assumptions, circular reasoning, or misaligned evidence.
- Critically assess the consistency of local testing practices with Global KPMG quality and governance requirements, identify underlying gaps such as weak rationale, unsupported conclusions, or misaligned evidence, as well as good practices.




- Evaluate compliance with Global KPMG information security and privacy policy requirements and governance frameworks (including GISP, GAUP, and IFDTA).

- For GSIPRA program - Plan, execute and report on supplier security assessments / Global Supplier Information Protection Risk Assessments (GSIPRAs) based on risk indicator analysis and the information protection terms of the agreements of the suppliers, including:

- Compile and maintain up-to-date Key Risk Indicators (KRIs) for suppliers / third parties based on contracts and other supplier profile information (including Bitsight).
- Scope information protection third party / supplier assessments leveraging independent attestation – such as SOC 2 – reports of suppliers and understanding of the information protection terms of agreements
- Perform testing following program workplan materials and ISO 27001 control framework, document results and maintain supporting workpapers and relevant materials up to date
- Report assessment results and potential risks to key stakeholders, including contacts responsible for supplier management and management.
- Contribute to maintenance and enhancement of program materials and procedures.
- Provide feedback for supplier remediation progress for findings identified during GSIPRAs,

monitor and report on remediation progress.

- For both IPCR and GSIPRA Programs:

- Work efficiently on multiple workstreams based on project plans. Operating autonomously within global teams.

- Deliver high‑quality written analysis for senior and global stakeholders, identify themes based on review results.

- Partner effectively across teams as a trusted Subject‑Matter Expert (SME)

- Support ongoing enhancement of digital risk monitoring and quality practices.

Qualifications

B.E. / B.Tech

📌 Information Protection Assessments - Assistant Manager (Pune)
🏢 BSR
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information protection assessments - assistant manager (pune) / pune

Subscribe to this job alert:

Get the latest job offers by email for: information protection assessments - assistant manager (pune) / pune