Security Production Assurance & Compliance Lead
Location: London
Capability: Technology & Engineering
Job details
Location: London
Capability: Technology & Engineering
Experience Level: Senior Manager
Type: Full Time
Service Line: EWT (excl. PE & Ops)
Contract type: Permanent
Job description
Security Production Assurance & Compliance Lead
Grade B
EWT
Role overview
The Security Production Assurance and Compliance Lead is a pivotal role within the Cyber Security Team. This position entails ensuring robust security control assurance and compliance with relevant regulations and standards. The ideal candidate will have extensive experience in 1st Line of Defence (1LoD) information security, a deep understanding of production environments, and a keen eye for regulatory compliance.
Key Responsibilities
- Security Operations Support: Provide 1LoD support to ensure the protection of information assets across the digital ecosystem
- Budget and Service Optimisation: Support embedding new initiative and maturing current investments made from transformations programmes.
- Product Assurance: Track Security hygiene remediation on an enduring basis
- Compliance Assurance: Ensure adherence to industry standards, regulatory requirements, and internal policies related to information security.
- Risk Management: Conduct regular risk assessments and develop strategies to mitigate identified risks.
- Policy Development: Enforce information security policies, procedures, and guidelines.
- Audit Coordination: Coordinate internal and external audits related to 1LoD.
- Collaboration: Work closely with other departments to integrate security measures into production processes and systems.
- Continuous Improvements: Advise and oversee operational improvements to reach 100% compliance, making significant difference to the security posture of KPMG
- Create and sponsor programmes to enhance the operational effectiveness for security compliance, act as key stakeholder and consultant on these programmes
Qualifications
- Bachelor’s degree, or equivalent qualification/experience, in Information Security, Computer Science, or a related field.
- Significantf experience in information security and compliance.
- Certifications such as CISSP, CISA, or CISM are highly desirable.
- Detailed working experience of Cyber Essentials and Cyber Essentials Plus
- Extensive knowledge of infrastructure of a large organisation; including data centre, endpoint and cloud technologies and their assets
- Proven experience of working with large programmes and dependent outcomes, with security compliance being the beneficiary
- Strong knowledge of regulatory requirements (e.g., GDPR, HIPAA) and industry standards (e.g., ISO 27001, Cyber Essentials Plus, NIST).
- Excellent communication and leadership skills.
Key Competencies
- Analytical Thinking: Strong ability to analyse complex security issues and develop effective solutions.
- Attention to Detail: Keen eye for detail in identifying potential security risks and compliance issues.
- Leadership: Demonstrated ability to lead and motivate a team of security professionals.
- Stakeholder management: Strong ability to manage an extensive range of stakeholders including C- Suite, Partners and Directors across each business capability
- Collaboration: Effective collaboration skills to work seamlessly with other departments and stakeholders.
#LI-AR1
#LI-AR1
Apply for roleWhy Technology & Engineering at KPMG?
Technology is at the heart of what we do and part of the very DNA of our business. That’s why we’ve invested in a single powerful team of connected technologists. 1,500 specialists, creating a step change in the way we work. Broader, deeper expertise, which is delivered to our clients faster than ever. Our connected solutions stretch across a range of specialisms too. From technology transformation, cyber and risk management through to security operations, data and analytics, automation, powered apps and Cloud. This is an opportunity to join a team that combines the entrepreneurial spirit and imagination of a start-up with the resources only a global network can provide. We’re committed to simplified structures and are investing in workplace tools that enable us to collaborate and innovate whether you’re working at home, in our office or at client sites.
Read about Technology & EngineeringAbout KPMG
With offices across the UK, we are part of a global network of firms providing Audit, Tax & Law, Consulting, Deal Advisory and Technology Services to diverse clients.
About KPMGOur Values
They provide us with a strong sense of identity, ensuring we can grow stronger. They bind us together, across our different backgrounds and cultures, and are common to each of us. Explore more about why Our Values matter.
Read moreAgile working
From role sharing and flexible start and finish times to home working, we'll try and support the flexible work patterns that best suit you.
Read moreCommitted to inclusion
We want you to bring your full self to work - to make this a place where people from every background thrive.
Read moreSupporting work returners
We welcome applications from people who have taken a career break.
Read moreNeed support? Let us know
We're a member of the Business Disability Forum so please get in touch if you'd like to discuss any adjustments that you might need in the application process - and if you are successful beyond this.
Need Support? Let us knowOur agency policy
We don't accept speculative CVs from agencies - you can see our policy on agencies here:
Read more