Service Delivery Security Manager
Location: Aberdeen, Birmingham & Other locations
Capability: Technology & Engineering
Job details
Location: Aberdeen, Birmingham, Bristol, Cambridge, Cardiff, Edinburgh, Gatwick, Gibraltar, Glasgow, Leeds, Liverpool, London, Manchester, Milton Keynes, Newcastle upon Tyne, Norwich, Nottingham, Plymouth, Reading, South Coast - Southampton, Watford
Capability: Technology & Engineering
Experience Level: Manager
Type: Full Time
Service Line: EWT (excl. PE & Ops)
Contract type: Permanent
Job description
Service Delivery Security Manager
Team
The Service Delivery Security Manager role is in the KPMG UK Information Security function and reports directly to the Security Production Assurance & Compliance Lead. This role is critical in the provision and delivery of secure, innovative, technology-enabled services and solutions for KPMG and our clients. The role is vital to KPMG’s ability to demonstrate that we are delivering ‘secure by design’ services and solutions such that our business stakeholders, our clients and our regulators trust KPMG.
Role
The primary purpose of the role is to enable harmonious delivery of Security Services, by ensuring strong collaboration with the external Service Providers and entire range of KPMG business functions. There are 3 main areas of focus:
- Manage the security services relationship to protect the delivery of the end to service services that involve all KPMG UK Technology services, or third-party suppliers.
- Provide governance for infrastructure security services
- Provide an overview of the complete set of services provided by all KPMG UK Technology services, or third-party suppliers and troubleshoot any issues and escalate as appropriate.
Key responsibilities are:
- Work closely with the Service Owners who are accountable for the end-to-end services, understand their roadmap for the service and the day-to-day operational requirements
- Maintain and lead the process to manage the Governance of these services
- Ensure firm standards and guidelines are followed, and contractual or operational commitments are delivered
- Review and govern the Service Provider Quality, Improvement Plans, Issues and Operational Risks, engaging the Security Production Assurance & Compliance Lead as required
- Raise and build consensus around issues or escalations and enable timely resolution.
- Govern Service Provider Knowledge Management, Knowledge Transfer, Reporting, Documentation and other engagement practices to ensure ongoing operational excellence
- Review Service Provider capacity plan to ensure it has enough capacity to meet the required demand and is in line with the Service Owner’s roadmaps
- Consolidate and provide reports on the delivery of Security services and initiatives across the relevant KPMG capabilities
- Ensure any planned changes across Technology or Service Provider are co-ordinated to ensure there is minimum disruption to Information Security services.
- Communicate major changes or enhancements in Information Security to Service Provider/ Business function and vice-versa
- Act as a single point of contact for general queries or issues flowing to and from the Security Function to the delivery teams
- Work closely with the Service Delivery Managers and Service Owners to ensure everyone has a clear view of the remediations and expectations
- Work closely with the Security Production Assurance & Compliance Lead to implement the operational security activities, processes and standards as determined by them.
- Build long-term stakeholder relationships including negotiating service levels, and defining project scope.
- Monitor, review and drive compliance to security policies, guideline and standards (as defined by KPMG) using compliance reports supplied by the Supplier and internal teams. You will escalate issues to the Security Production Assurance & Compliance Lead where necessary
- Use your experience to propose changes to existing policies and procedures based on feedback from Internal and Supplier Service Operations teams to Security Production Assurance & Compliance Lead to drive operating efficiency and compliance
- You will support incident and problem management teams in prioritisation of security issues and serve as an active participant in the security governance processes
- Manage and develop the compliance for relevant technical security domains using automation, digitisation, security by design and a customer focussed approach as appropriate, and formulate a service strategy and roadmap for these
Knowledge/Skills
- Ability to create and maintain insightful dashboards (ideally via PowerBI), by unifying reports and metrics from various sources (e.g. spreadsheets and SaaS platforms.)
- Excellent and relevant experience in a similar infrastructure or technology management leadership role
- Proven understanding of change management processes in a fully change managed environment (ITIL)
- Excellent interpersonal skills, ability to negotiate and influence wide range of stakeholders at all levels of the firm; UK and Global
- Experience in managing delivery teams and the delivery of Managed IT services
- Experience in managing relationships with key stakeholders and 3rd party suppliers
- Able to deliver transformation plans to support operational objectives
- Literate and numerate, with Good financial and commercial skills
- Must have excellent presentation skills
- Sets challenging objectives that reflect key strategic medium and longer-term priorities
- Works on CPD to maintain professional status/accreditation.
- Strong understanding of tooling associated with infrastructure services management such as Endpoint Protection, IT Service Management (ITSM) platforms, and a range of security tools.
- Experience and knowledge of managing applications and infrastructure within the Cloud.
- Be able to demonstrate the ability to adapt communication style to explain technical concepts to different people within an organisation whether advising stakeholders, directing teams or sharing experience;
- Experience of successfully working in a fast paced, customer service environment, delivering high quality information security services.
Desirable certifications:
- CISM
- CISSP
- Cloud-related Certifications
Why Technology & Engineering at KPMG?
Technology is at the heart of what we do and part of the very DNA of our business. That’s why we’ve invested in a single powerful team of connected technologists. 1,500 specialists, creating a step change in the way we work. Broader, deeper expertise, which is delivered to our clients faster than ever. Our connected solutions stretch across a range of specialisms too. From technology transformation, cyber and risk management through to security operations, data and analytics, automation, powered apps and Cloud. This is an opportunity to join a team that combines the entrepreneurial spirit and imagination of a start-up with the resources only a global network can provide. We’re committed to simplified structures and are investing in workplace tools that enable us to collaborate and innovate whether you’re working at home, in our office or at client sites.
Read about Technology & EngineeringAbout KPMG
With offices across the UK, we are part of a global network of firms providing Audit, Tax & Law, Consulting, Deal Advisory and Technology Services to diverse clients.
About KPMGOur Values
They provide us with a strong sense of identity, ensuring we can grow stronger. They bind us together, across our different backgrounds and cultures, and are common to each of us. Explore more about why Our Values matter.
Read moreAgile working
From role sharing and flexible start and finish times to home working, we'll try and support the flexible work patterns that best suit you.
Read moreCommitted to inclusion
We want you to bring your full self to work - to make this a place where people from every background thrive.
Read moreSupporting work returners
We welcome applications from people who have taken a career break.
Read moreNeed support? Let us know
We're a member of the Business Disability Forum so please get in touch if you'd like to discuss any adjustments that you might need in the application process - and if you are successful beyond this.
Need Support? Let us knowOur agency policy
We don't accept speculative CVs from agencies - you can see our policy on agencies here:
Read more