Manager, Security Governance, Risk and Compliance
KPMG US · McLean, VA · 2 days ago
Hybrid$127k/yrFull-time
About the role
KPMG is currently seeking a Manager, Security Governance, Risk and Compliance to join our Enterprise Security Services organization.
Responsibilities
- Lead technology, data, operations, artificial intelligence (AI), and cyber risk assessments; translate complex findings into actionable insights to enable leadership to make informed, risk-based decisions
- Demonstrate deep proficiency in data risk management within the lines of defense (LoD) with a focus on data modeling, strategy, governance and management controls
- Evaluate and recommend controls to mitigate risk and drive a risk-aware culture; ensure all recommendations align with firm policies and control standards to maintain risk within an acceptable appetite
- Analyze the impact of key risks and the evolving operating landscape; define criteria for risk tradeoffs and provide recommendations to leadership to optimize the organization's risk posture
- Develop and maintain comprehensive risk and control matrices (RCMs) and risk registers; manage the end-to-end risk lifecycle, including identification, evaluation, and treatment planning
- Build trust-based relationships with peers and senior leadership, collaborate with LoD partners to ensure internal audits and risk measures are accurately targeted toward high-impact areas
- Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications
- Minimum five years of recent risk and compliance experience within a large professional services environment specializing in physical and cyber security
- Bachelor's degree from an accredited college or university is preferred; minimum of a high school diploma or GED required; relevant industry certifications, for example CIA, CISA, CISM, CRISC, or CISSP are preferred
- Demonstrated understanding of disparate compliance frameworks and risk management principles, as well as experience making decisions to optimize overall operational risk
- Ability to analyze and synthesize technical data and convey it to non-technical audiences
- Understanding of key business objectives and how to balance business objectives against IT risks
- Strong verbal/written communication, problem solving, analytical and independent judgment skills to support an environment driven by customer service and teamwork, ability to positively influence, mentor and be a credible source of knowledge to less