Description
This role is within the Security Consultancy sub-team who provide specialist technical security advice collaborating with technical and business teams throughout the entire or part of a digital solution’s life cycle. The team owns and develops Security Patterns, Security Specifications, and the Threat Modelling Framework, to support secure technology innovation in a changing threat landscape. The purpose of this role is to advise on the technical security aspects of digital solutions to be evaluated or developed and implemented by technology teams across KPMG Group for internal use, or as a service or product to KPMG clients.
Responsibilities
The Technical Security Consultant’s responsibilities will vary based on business alignment and will include:
• Lead as an internal consultant at Manager level to an assigned Platform/Product/Capability/Practice Management area as part of our Centre of Excellence function providing technical security direction, stakeholder management, and driving improvements to our ways of working.
• Collaborate with programmes and projects,
product and engineering teams to help deliver digital solutions that meet the business need, by supporting and contributing to design reviews. Ensuring that the proposed design, build and run are compliant with the KPMG and client security requirements – ensuring all applicable security controls and patterns are implemented.
• Work alongside internal Design Authorities and Change Management functions to ensure all change initiatives are reviewed, supported, and aligned with KPMG security requirements.
• Using threat modelling to provide risk and threat-based advice to programme stakeholders along with actionable recommendations where necessary in the design and implementation of digital solutions.
• Advise on secure-by-design adoption of AI/GenAI capabilities (e.g. Microsoft 365 Copilot/Copilot Studio and LLM integrations) including prompt and data protection, model/service selection considerat