Logo
KPMG US

Manager, Technology Risk

KPMG US, San Francisco, California, United States, 94199

Save Job

Overview

Join to apply for the

Manager, Technology Risk

role at

KPMG US . KPMG Advisory practice is currently our fastest growing practice. We are seeing tremendous client demand, and we anticipate this trend to continue. In this market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. We offer learning and career development opportunities, world-class training, and leading market tools to help you grow professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility to explore new areas of inspiration, consider a career in Advisory. KPMG is currently seeking a Technology Risk Manager to join our Advisory Services practice. Responsibilities

Design, coordinate, and oversee day-to-day activities related to client engagements in one or more areas such as IT strategy and transformation programs, agile software development/DevOps, business continuity and disaster recovery, cybersecurity, cloud providers and other third parties; data management/governance, emerging technology such as AI, automation (robotics, cognitive, and more), and projects, General IT controls (GITCs) and application controls testing, and regulatory/compliance requirements such as Sarbanes Oxley (SOX), FedRAMP and Payment Card Industry (PCI) Review clients' IT traditional and agile processes as well as tools for security, resiliency and DevOps controls against leading practices, industry standards, or client frameworks; assess capability maturity, identify gaps in design and execution of the controls, and communicate issues and recommendations to senior management Work with client senior management to design and implement new IT risk and control frameworks, sustainable solutions (including applying knowledge of governance, risk and security tools), operating processes and people models to address key and evolving risks as necessary. Plan and lead (or delegate) kickoff, status, and closing meetings with the engagement team and clients Supervise and provide performance management for staff resources working on assigned engagements Complete comprehensive executive summaries, final reports and deliver to client senior management; document and review engagement workpapers in accordance with KPMG requirements and common industry practice for internal audit and risk consulting client engagements; contribute to related KPMG knowledge bases and internal practice development initiatives, including research, thought leadership, marketing collateral and share forums/peer exchange materials Qualifications

Minimum five years of recent experience working within IT risk (first line or second line of defense), cybersecurity, internal audit or IT compliance function as an internal employee; similar role as part of a professional services firm Bachelor's degree from an accredited college/university in an appropriate field; CISA, CISM, CISSP, CRISC or similar certifications preferred; Master's degree from an accredited college/university preferred; one or more enterprise technology vendor certifications from IBM, Oracle, Microsoft, Google, AWS, ServiceNow, GitHub, Artifactory, Atlassian, or GitLab preferred Prior knowledge leading and executing IT risk consulting, IT process re-engineering, IT audit, and IT internal controls engagements, leveraging IT governance and control frameworks such as COBIT, NIST Cybersecurity framework (CSF), NIST 800-53, IIA GTAG, Cloud Security Alliance, Capability Maturity Model Integration (CMMI), and Information Technology Infrastructure Library (ITIL) and proficiency in core requirements and methodologies for Sarbanes-Oxley (SOX) internal control programs Experience with IT risk management operating models, three lines-of-defense frameworks, integrated risk management practices, and/or risk intelligence capabilities Understanding of commonly used enterprise technology infrastructure, Continuous Integration and Continuous Delivery (CI-CD) pipelines and DevOps management products/solutions from IBM, Oracle, Microsoft, Google, AWS, ServiceNow, Jenkins, GitHub, Artifactory, Atlassian, or GitLab preferred Strong leadership and executive communication skills, technical knowledge; ability to write at publication quality level in order to communicate findings and recommendations to the clients and senior management team; proficiency in executing projects in accordance with leading practice project management principles Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity Ability to travel as necessary Seniority level

Mid-Senior level Employment type

Full-time Job function

General Business Equal Employment Opportunity

KPMG is an equal opportunity employer. All qualified applicants will be considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or any other status protected by applicable law.

#J-18808-Ljbffr