Regional Information Risk and Security Manager recruitment

KPMG is a global network of professional firms providing Audit, Tax and Advisory services. With 145,000 people operating in 150 countries around the world, we have outstanding professionals working together to provide value to local and global organisations. Committed to excellence, we are proud to be an often recognised Employer of Choice in Singapore.

KPMG ASPAC Regional Delivery Center delivers key global services such as integrated business systems, messaging and collaboration tools to KPMG member firms in the Asia Pacific. The Center also maintains the regional level of security in line with global KPMG policies and procedures and acts as the first point of contact for operational information risk and security related matters.

ASPAC Regional Delivery Centre – Regional Information Risk and Security Manager

Successful candidate will play a significant role in security operations process management, threat and incident management, change management and business relationship management. 

The successful candidate will be:

• collaborating with security stakeholders in the region to identify information risk and security solutions to any information risk and security requirements arising.

• acting as the security point-of-contact for operational groups across all KPMG member firms in the region.

• facilitating regional country member firms on security and information risk related topics and establishing knowledge sharing within the region to improve business efficiency.

• managing the resolution of operation security issues, co-coordinating incident management across the region and summarising critical security incidents and provide high-level recommendations to senior management.

• conducting security risk analysis and making risk decisions from monitoring information sources to identifying threats and vulnerabilities to KPMG.

• ensuring compliance with Service Level Agreements on change request approvals and providing metrics to senior management.

• assessing the risk of proposed changes in the Change Management process and working with change requestors, project and business stakeholders to ensure all changes meet the required security standards.

• managing security’s involvement in the Critical Incident Management, Change Management, and Patch Management Processes.

• identifying and designing improvements in the processes, and to communicate suggested changes to stakeholders.

• staying current with new technologies, platforms and methodologies relating to information risk and security matters

Candidate must also be willing to do occasional regional travel. 

The ideal candidate should:

• possess a recognised degree preferably in Management Information Systems, Computer Science, Business or related field with 4-7 years of relevant experience in a corporate environment operating information risk and security management processes.

• demonstrate current risk and security expertise and trend awareness with CISM or CISSP certification and constantly involved in similar programs from information security professional organisations.

• demonstrate good understanding of ITIL and ISO 27001 control objectives and risk and security understanding of the following systems:

  - SAP or other Customer Relationship Management (CRM)

  - Knowledge Management and Collaborative systems

  - Document Management Systems

  - SQL / Oracle databases

  - Microsoft operating systems and messaging tools

  - Network and telecommunication systems

• have experience in operating information risk and security programs in line with business needs while balancing risk mitigation, cost effectiveness and usability in a multi-divisional, multi-cultural and geographically diverse business.

• have good writing and verbal communication skills in English and preferably one other major regional language. 

• have good negotiation skills and relationship management with excellent business acumen and service mindset.

Interested candidates can apply via the link below, quoting the job reference SG/ASPAC/RDC-IRS/201204 and stating the position applied for.

All applications will be held in strict confidence.