Cybersecurity Strategy, Governance & Risk
Cybersecurity Strategy, Governance & RiskAt KPMG, your long-term future is every bit as important to us as it is to you. That's why our aim is to give you experiences that will stay with you for a lifetime. Whether it's great training and development, working across functional sectors, mobility opportunities or corporate responsibility volunteering activities - you'll gain a wealth of experiences on which to build a rewarding career. We're proud of our culture - it's one that recognises hard work, encourages new ways of thinking and embraces diversity and inclusion. We have an innovative spirit which inspires what we do and how we do it - striving to be better lies at the heart of who we are.
Technology underpins many of the most influential organisations in the world and presents opportunities for businesses that want to seek out new markets and are prepared to invest in transformational change. The last ten years have seen a rapid emergence of new technology, greater connectivity for organisations and individuals, and a 24/7 approach to global commerce. However, this has left many organisations behind the curve and struggling to achieve their business aspirations without feeling exposed to cyber security risk.
To join a growing team to assist clients with managing one or more of the following areas:
- Ethical Hacking - this discipline covers vulnerability assessment, application and network penetration testing, wireless security, mobile security, and system security testing.
- Cybersecurity Risk & Governance - this discipline covers designing and implementing Cybersecurity frameworks; Cyber maturity assessments; organisational design for Cyber Security; Cloud security; design and rollout of cyber security processes such as Incident Management, Intrusion Detection, and Security Monitoring.
- Technology Risk and 3rd Party Cyber Risk - this discipline covers IT-Business related consulting over how an organisation manages technology risk and governs its outsourcing. This involves review, re-design and implementation controls over the 3rd party organisation's IT environment. Topics include system development, project management, business or IT outsourcing, business continuity management, information security, incident management, user access management.
- Cyber Business Continuity, Disaster Recovery & Crisis Management - this discipline covers building business and technology resilience against cyber-attacks. Creating and testing Cyber Incident Response Plans around typical cyber-attack scenarios. Taking regulatory requirements around BCM and Crisis management and international standards based consulting.
Cyber team members regularly interact with C-Suite clients, such as Chief Executive Officer (CEO), Chief Information Security Officer (CISO), Chief Information Officer (CIO), Chief Operating Officer (COO), Chief Risk Officer (CRO) and their direct reports. Hence, a client centric mind-set, understanding of IT within a Business context, and well-developed communication skills are desirable.
Cybersecurity Strategy, Governance & Risk specialist:
The role involves delivering Cybersecurity Maturity Assessments and Cybersecurity Control Gap Remediation (covering the design and implementation of controls to address the people, process and technology risks) projects across the region, and working closely with our team of Cybersecurity Readiness professionals.
Your responsibilities will include the following:
• Perform Cybersecurity Maturity Assessments to ensure appropriate design and implementation of controls for Protection, Detection, Response, Integration, and Threat Intelligence against cyber-attacks.
• Perform Cybersecurity Maturity Assessments by assessing cyber risk factors across 6 functional domains - Leadership & Governance, Human Factors, Information Risk Management, Business Continuity, Technology & Operations, Legal & Compliance.
• Assess the IT architecture - application, database, operating system, hardware platforms (including web and mobile) and network infrastructure - for vulnerabilities to cyber-attacks.
• Review and analyse security vulnerabilities to identify false positives.
• Prepare a report on identified security risks, threats, vulnerabilities and recommendations to remediate.
• Design a Cybersecurity Roadmap or Cybersecurity Strategy to address ongoing cyber readiness at an organisational level which holistically addresses the people, process and technology dimensions.
• Design and implement processes for Identity & Access Controls, Cyber Incident Management, Intrusion Detection, Threat Intelligence, Cyber Data Analytics, Security Monitoring, etc
• Assist in continuously enhancing the existing cyber readiness methodologies.
• Remain up-to-date on the latest cybersecurity threats and vulnerabilities.
You will demonstrate the following capabilities:
• Identify and resolve complex issues and develop innovative solutions for high profile clients on a variety of local and international engagements
• Client-centric with good communication skills
• Driven to learn new things and share knowledge with your clients and colleagues
• Able to work as part of a team, and at the same time being an independent self-starter
• Flexible working style to work in a dynamic environment
• Actively identify and support business development opportunities which includes supporting the team with sales activities such as proposal writing and client presentations
• Coach and develop team members as part of the firm's overall Performance Management process or on specific engagements
The ideal candidate should:
• Any degree in technology, engineering, or business studies with information systems major/minor along with deep interest in technology risk, security and IT governance will be considered
• Have a good working knowledge of information security principles, techniques and standards
• Have strong analytical, problem solving and inter-personal skills
• Excellent written and oral communication skills with the ability to present ideas and results to technical and non-technical audiences
• Be willing to travel on regional and international assignments (occasionally)
• Have prior consulting experience in IT risk assessment or IT security
• For Cybersecurity Risk & Governance, preferably possess professional certifications such as CISSP, CRISC, CISA, CISM, PMP or other relevant qualifications
• For Ethical Hacking, preferably possess professional certifications such as OSCP/CREST and/or GIAC (GXPN, GPEN, GWAPT, etc.)
• Fresh graduates to 2 years of relevant experience for Associate
• Minimum 3 years of relevant experience for Senior Associate
• Minimum 4 years of relevant experience for Assistant Manager
• At least 5-6 years of relevant experience for Manager
• More than 8 years of relevant experience for Associate Director