JobConnect

Information Security Manager

KPMG Global Services Hungary (KGSH) is supporting the KPMG Delivery Network (KDN). KPMG created KDN to provide large-scale, cross-functional capabilities and technology through a network of global delivery centers. KDN encourages global consistency and provides services and tools across Tax and Legal Services, Audit, and Advisory at a consistently high quality and at a competitive price point. It includes a multi-tiered global sales and delivery support network that transforms how KPMG firms and people work together. Our extensive network of dedicated KDN professionals has the depth and breadth of knowledge necessary to play a key role in the future of global productivity tools.

What we offer*:

  • 2 days home office opportunity and flexible working hours

  • Private health care coverage including dental services (Medicare)

  • Eyeglasses compensation

  • Collective life and accident insurance

  • Wide range of Cafeteria elements (such as SZÉP Card, MOL Bubi, MOL Limo)

  • Annual bonus may be awarded based on your and the Firm’s performance

  • Company car/car allowance

  • iPhone14 with subscription

  • Referral bonus

  • Internal coaching opportunity

  • Sports opportunities and All You Can Move sportpass availability

  • Compensation for long-distance commutes (for those who commute to work from outside the city limits)

  • Relocation support for foreign candidates

  • 3 paid days for volunteering and CSR activities

  • In-depth professional training from beginner to advanced level

  • Opportunity to participate in English and Hungarian language courses

Key Responsibilities

  • Support the KDN NISTO in information security matters and escalation and promote adherence to KPMG information protection policies and other relevant policies (for example those outlined in the Global Quality & Risk Management Manual).
  • Support and maintain relationships with information security teams from network firm locations from which KDN delivery centers are located.
  • Create, maintain and report on information security metrics.
  • Liaise with relevant stakeholders including Business Functions, Technology Groups, Legal, Privacy (Privacy Liaison (PL), Physical Security, Human Resources (HR).
  • Assist in evaluating the information security provisions for working with other member firms, to ensure compliance with the IFDTAs and other regulatory provisions.
  • Participate in and support the information security risk assessment process, tools and solutions used and facilitate risk treatment.
  • Provide input into information security related escalations.
  • Support the regular (at least annual) review of all security policies and standards, including their implementation.
  • Ensure that all relevant stakeholders are notified of the changes to global information security policies and standards, and that changes are appropriately reflected within documented policies, processes, and procedures.
  • Participate in and support the IPCR process and assist in monitoring that activities are carried out in the required timelines.
  • Contribute to the documentation and coordination of ISO 27001 processes (where applicable)
  • Work closely with the technology teams to ensure that relevant security controls are implemented consistently across all parts of the organization and reviews are carried out appropriately.
  • Support the Information Security Incident Management planning, preparation, implementation and communication.
  • Assist in monitoring that all KDN personnel receive information protection and data privacy training, as applicable.
  • Provide input and support in the SoQM related to IPCR and information security areas.

Requirements

  • 5+ years of experience within information security and risk management.
  • Industry standard accreditation or certifications. (i.e., CISSP, CISM, ISO 27001) preferred
  • Be familiar with current data privacy regulations, including GDPR.
  • Have understanding and experience with Secure SDLC and DevSecOps or security automation.
  • Be capable of understanding and communicating the business impact that infosec operations have on the organization.
  • Understand the requirements of relevant information security frameworks and attestations including for example ISO 27001, NIST, SOC2, SoQM.

*Elements should be in line with company guidelines and policies.

Skills

  • Information Security Management
  • Risk assessment
  • ISO 27001
  • Security Policy Development
  • Incident Response
  • Security Auditing
  • Stakeholder Management

Related jobs

KPMG Global Services HungaryApply for this job