Proposed designation: Associate Director- Information Security & Data Privacy
- Role type: Supervisory-Managing the team consisting of 2 Managers, 1 Sr Executive and 2 CWKs.
- Reporting to: NITSO
- Geo to be supported: US/UK/ROW/Across geos
- Work timings: Flexible. Work from office atleast 2 days.
Roles & responsibilities
- Governance: Accountability for the management of information security within the KPMG member firm, with the mandate from senior leadership, including strategy and planning, monitoring and maintenance, investments, projects and communication.
- Information Security Risk Management: Oversight of information security risk management through risk assessment, including approval of key risks, involvement in information security related escalations, review of contractual terms, response to client questionnaires and RFP, accountability for review of suppliers and acquisitions.
- Compliance to Policies and Standards: Responsibility for supporting ongoing information security compliance initiatives, including policies and standards related to information security, technology, data governance and privacy
- Technology Approvals: Accountability for the review and approval of technology in relation to information security risks, including involvement and review of technology projects, approval of significant changes to technology environments, approval of cloud environments, and approval of Global Technology Standard exceptions.
- Security Operations: Accountability for security operations, working with technology teams to ensure that technical & information security compliance standards are met on an ongoing basis.
- Incident Management: Coordinates the local Member Firm incident response processes, including escalation to global (GSOC)
where necessary and conducting readiness rehearsals within the KPMG member firm.
Educational qualifications
- Minimum Bachelor's degree in Computer Science, Information Technology or MCA.
- Hold industry standard accreditation or certifications. (i.e., CISSP, CISM, ISO 27001)
- Be familiar with current data privacy regulations, including GDPR, DPDPA
Work experience
- Should have a minimum of 13 years’ experience within information security and risk management.
- Have understanding and experience with Secure SDLC and DevSecOps or security automation.
Strong background in Information Security, Risk Management, and Data Privacy
- Expertise in ISO 27001 , NIST, SOC2, GDPR, DPDPA , and related frameworks
- Experience with Cloud Security, DevSecOps, Security Automation, Identity & Access Management, and Security Governance
- Professional certifications such as CISSP, CISM, or ISO 27001 preferred
- Be capable of understanding and communicating the business and profit impact that infosec operations have on the organization
- Understand the requirements of relevant information security frameworks and attestations including for example ISO 27001, NIST, SOC2, SoQM
- The official language of KPMG International is English; therefore, appropriate written and verbal skills in English are needed.
- Knowledge of cloud security and governance tools, cloud access security brokers (CASBs), and server virtualization technologies.
- Strong experience with Directories, SSO, Federation, Delegated administration, API gateways
- Positive understanding of cloud computing architecture, technical design and implementations, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS) delivery models
📌 Information Security & Data Privacy Lead (Gurugram)
🏢 BIG4
📍 Gurugram