Senior Associate, IT Internal Audit
About the role
KPMG Advisory is at the forefront of transformation, offering excellent opportunities for career advancement and expertise development. Our professionals thrive in a collaborative, team-driven culture and benefit from a wealth of learning and career development opportunities, world-class training, and leading market tools. We prioritize our people, fostering both personal and professional growth in an environment where you can be your whole self, make an impact, and expand your capabilities.
Responsibilities
- Design, coordinate, and oversee day-to-day activities related to client engagements in areas such as IT strategy and transformation, agile software development/DevOps, business continuity and disaster recovery, cybersecurity, cloud providers, data management/governance, emerging technology (AI, automation), and projects.
- Focus on General IT controls (GITCs), application controls testing, and regulatory/compliance requirements (e.g., Sarbanes-Oxley (SOX), FedRAMP, Payment Card Industry (PCI)).
- Review clients' IT processes and tools for security, resiliency, and DevOps controls against leading practice frameworks; assess capability maturity, identify gaps, and communicate issues and recommendations to senior management across industries like Financial Services, Consumer and Retail, Manufacturing, Energy, and Technology.
- Work with client senior management to design and implement new IT risk and control frameworks, sustainable solutions, and operating processes to address evolving risks.
- Complete comprehensive executive summaries and final reports for client senior management; document and review engagement workpapers in accordance with KPMG requirements and industry practices.
- Lead efforts in developing and contributing content to KPMG knowledge bases and internal practice development initiatives, including research, thought leadership, marketing collateral, and peer exchange materials.
Qualifications
- Minimum three years of recent experience in IT risk (first or second line of defense), cybersecurity, internal audit, or IT compliance, either as an internal employee or in a professional services firm.
- Bachelor’s degree from an accredited college/university in a relevant field; CISA, CISM, CISSP, CRISC, or similar certifications preferred.
- Master’s degree and enterprise technology vendor certifications (e.g., IBM, Oracle, Microsoft, Google, AWS, ServiceNow, GitHub, Atlassian, GitLab) preferred.
- Experience in IT risk consulting, IT process re-engineering, IT audit, and IT internal controls engagements using frameworks such as COBIT, NIST CSF, NIST 800-53, IIA GTAG, Cloud Security Alliance, CMMI, and ITIL.
- Proficiency in core requirements and methodologies for Sarbanes-Oxley (SOX) internal control programs.
- Experience with IT risk management operating models, three lines-of-defense frameworks, integrated risk management practices, and/or risk intelligence capabilities.
- Understanding of enterprise technology infrastructure, CI-CD pipelines, and DevOps management products/solutions (e.g., IBM, Oracle, Microsoft, AWS, ServiceNow, Jenkins, GitHub, Atlassian, GitLab).
- Strong communication skills, technical knowledge, and the ability to write at a publication-quality level to convey findings and recommendations to clients and senior management.
- Must be authorized to work in the U.S. without employment-based visa sponsorship now or in the future; ability to travel as necessary.
Pay
California Salary Range: $95,095 – $161,000. Salary ranges for other locations can be found here. Any offered salary is determined based on relevant factors such as skills, job responsibilities, prior experience, degrees, certifications, and market considerations.
Benefits
- Comprehensive medical, dental, and vision coverage.
- Disability and life insurance.
- 401(k) plans.
- Robust suite of personal well-being benefits to support mental health.
- Personal Time Off per fiscal year, based on job classification, standard work hours, and years of service.
- Two annual breaks where employees are not required to use Personal Time Off: one at year-end and another around the July 4th holiday.
Additional details about benefits can be found on the KPMG US Careers site.