Manager, Security Governance, Risk and Compliance
KPMG US · Virginia Beach, VA · 2 days ago
Hybrid$127k/yrFull-time
Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today’s most important industries. Our growth is driven by delivering real results for our clients and is enabled by a culture that encourages individual development, embraces an inclusive environment, rewards innovative excellence, and supports our communities. KPMG is currently seeking a Manager, Security Governance, Risk and Compliance to join our Enterprise Security Services organization.
Responsibilities
- Lead technology, data, operations, artificial intelligence (AI), and cyber risk assessments; translate complex findings into actionable insights to enable leadership to make informed, risk‑based decisions.
- Demonstrate deep proficiency in data risk management within the lines of defense (LoD) with a focus on data modeling, strategy, governance and management controls.
- Evaluate and recommend controls to mitigate risk and drive a risk‑aware culture; ensure all recommendations align with firm policies and control standards to maintain risk within an acceptable appetite.
- Analyze the impact of key risks and the evolving operating landscape; define criteria for risk trade‑offs and provide recommendations to leadership to optimize the organization’s risk posture.
- Develop and maintain comprehensive risk and control matrices (RCMs) and risk registers; manage the end‑to‑end risk lifecycle, including identification, evaluation, and treatment planning.
- Build trust‑based relationships with peers and senior leadership, collaborate with LoD partners to ensure internal audits and risk measures are accurately targeted toward high‑impact areas.
- Act with integrity, professionalism, and personal responsibility to uphold KPMG’s respectful and courteous work environment.
Qualifications
- Minimum five years of recent risk and compliance experience within a large professional services environment specializing in physical and cyber security.
- Bachelor’s degree from an accredited college or university is preferred; minimum of a high school diploma or GED required; relevant industry certifications (e.g., CIA, CISA, CISM, CRISC, or CISSP) are preferred.
- Demonstrated understanding of disparate compliance frameworks and risk management principles, with experience making decisions to optimize overall operational risk.
- Ability to analyze and synthesize technical data and convey it to non‑technical audiences.
- Understanding of key business objectives and how to balance business objectives against IT risks.
- Strong verbal and written communication, problem‑solving, analytical, and independent judgment skills; ability to positively influence, mentor, and be a credible source of knowledge to less experienced team members.
- Applicants must be authorized to work in the U.S. without the need for employment‑based visa sponsorship now or in the future; KPMG will not sponsor visas for this opportunity.
Benefits
- Comprehensive, competitive benefits package including medical, dental, vision, disability, and life insurance.
- 401(k) retirement plans.
- Personal well‑being benefits supporting mental health.
- Personal Time Off (PTO) based on job classification, standard work hours, and years of service.
- Company‑observed holiday calendar with two additional paid breaks each year (year‑end and around July 4th).
- Additional details available on the KPMG US Careers site.
Pay
California Salary Range: $127,200 – $246,900