Description
- Minimum of 8 years of extensive experience in information protection and risk management and /or assurance, including minimum of 6 years of experience in information protection controls assessments, with demonstrated depth in ISO/IEC 27001 auditing and /or implementation and complex or judgment intensive reviews based on leading industry practices for internal audits and external / supplier audits.
- Advanced and well-rounded expertise in information security and privacy, with the ability to interpret requirements and risks in complex, global, and non-standard scenarios.
- Proven ability to function as a senior risk-based Quality Assessment (QA) reviewer of information controls audits, consistently exercising professional skepticism and independent judgment beyond procedural compliance, including the ability to:
- Differentiate between technical noncompliance, actual risk exposure, significant control weaknesses, and documentation or evidentiary quality gaps
- Identify and assess misalignment between local control interpretations and global SOQM expectations
- Detect nuanced quality concerns such as unsupported assumptions, circular reasoning, weak analytic logic, or evidence that does not substantiate conclusions
- Strong understanding of information security and data protection contractual requirements of third party suppliers and their translation into risk‑based assessment outcomes.
- Experience reviewing independent assurance reports for information security and privacy areas (e.g. ISO 27001, SOC 2), including scope considerations, exceptions and residual risks.
- Experience engaging with senior stakeholders and external third parties to communicate complex risk and assurance outcomes.
- Highly developed written and verbal communication skills in English, with demonstrated strength in executive level reporting; excellent command of M365 tools, including Word, PowerPoint, Excel, Teams, and Copilot.
- Ability to operate autonomously within a global delivery model, while effectively collaborating with diverse teams across geographies and time zones.
- Prior supplier audit and/or third-party risk assessment experience strongly preferred; professional certifications such as ISO 27001:2022 Lead Auditor and/or ISO 42001 / AI Lead Auditor are a plus.
- Prior experience with KPMG or another Big 4 organization preferred. Strong and practical familiarity with KPMG Global Information Security and Privacy Policies and frameworks, including Global Information Security Policies (GISP), Global Acceptable Use Policies (GAUP), and their application within a global System of Quality Management (SoQM) a plus.
- Strong personal accountability combined with a collaborative leadership approach and well-developed stakeholder management skills, including comfort engaging at senior levels.
Highly adaptive, capable of quickly assimilating new subject matter, with strong attention to detail and ability to maintain integrity and quality across multiple workstreams.
Responsibilities
- For the IPCR program:
- Oversee the KDN team of Information Protection Assessments – Managers” as requested by the Program leads, including review of deliverables and ensuring consistency in interpretation of KPMG Global policy requirements and results / conclusions across assessments.
- Provide oversight of complex risk and quality matters related to information protection, security, and privacy, bringing a solid enterprise perspective to the evaluation of control effectiveness and governance outcomes.
- Provide guidance in assessing evidence provided, in particular independent assurance evidence (e.g. ISO, SOC reports), including appropriateness of reliance and residual risk implications.
- Supporting the ongoing evolution of monitoring, Quality Assurance (QA) of reviews that took place as we relevant assurance methodologies.
- For GSIPRA program - Plan, execute and report on supplier security assessments / Global Supplier Information Protection Risk Assessments (GSIPRAs) based on risk indicator analysis and the information protection terms of the agreements of the suppliers,
including:
- Compile and maintain up-to-date Key Risk Indicators (KRIs) for suppliers / third parties based on contracts and other supplier profile information (including Bitsight).
- Scope information protection third party / supplier assessments leveraging independent attestation – such as SOC 2 – reports of suppliers and understanding of the information protection terms of agreements
- Perform testing following program workplan materials and ISO 27001 control framework, document results and maintain supporting workpapers and relevant materials up to date
- Report assessment results and potential risks to key stakeholders, including contacts responsible for supplier management and management.
- Contribute to maintenance and enhancement of program materials and procedures.
- Provide feedback for supplier remediation progress for findings identified during GSIPRAs,
monitor and report on remediation progress.
- For both IPCR and GSIPRA Programs:
- Report weekly status of KDN resource activities and contribute to management reporting.
- Develop executive‑ready reporting that communicates clear, defensible conclusions, often requiring pragmatic judgment, sensitivity to organizational context, and tailored messaging beyond standard templates
- Constructively question weak analysis or conclusions, articulating why issues matter from a quality and risk standpoint, and escalating concerns thoughtfully when required. In addition, the role plays a key mentoring function—coaching junior reviewers and managers, reinforcing risk‑based thinking, and elevating documentation quality through consistent, actionable, and educational feedback, while continuing to drive improvements in global monitoring and quality practices
- Work efficiently on multiple workstreams based on project plans. Operating autonomously within global teams.
- Deliver high‑quality written analysis for senior and global stakeholders, identify themes based on review results.
- Partner effectively across teams as a trusted Subject‑Matter Expert (SME)
Support ongoing enhancement of digital risk monitoring and quality practices.
Qualifications
B.E. / B. Tech
📌 Information Protection Assessments - Manager (Pune)
🏢 BSR
📍 Pune