Information Protection Assessments - Assistant Manager
Kpmg India Services LlpJob Description
Information Protection Assessments - Assistant Manager
Minimum 6 years of information security and risk experience, including minimum 4 years of experience in information protection controls assessments and ISO 27001 information security controls auditing and /or implementing.
Strong information security and privacy standards knowledge.
Excellent information protection risk assessment planning, executing, managing and reporting skills for internal audits as well as third party supplier audits.
Proven ability to operate as a risk-based Quality Assessment (QA) reviewer of audits performed, applying independent judgment based on leading industry practices. Demonstrated sound professional judgment to evaluate control effectiveness in context, separating isolated procedural issues from matters that present meaningful risk or systemic.
Ability to assess contractual security obligations and map them to control testing and evidence.
Experience reviewing and interpreting independent certification and attestation reports (e.g. ISO 27001, SOC 2).
Understanding of risk‑based scoping approaches, including consideration of supplier risk indicators and service context.
ISO 27001:2022 lead auditor or lead implementer certification. ISO 42001 / AI lead auditor or lead implementer a plus.
Prior supplier security assessment experience preferred.
Prior KPMG (or Big4) work experience a plus. Familiarity with KPMG policies (e.g. Global InfoSec & Privacy Policies, GISP, GAUP) or governance frameworks (e.g. IFDTA) a plus.
Excellent written and verbal communication skills in English, including strong report writing and the ability to present clearly and confidently to senior stakeholders.
Proficient in M365 tools (Word, PowerPoint, Excel, Teams, Copilot), with strong capability to produce clear, high‑quality reports and presentations.
Strong ability to multitask and work independently within a global team. Proactive, can work with minimal supervision, and work on continuous improvements.
Accountable and collaborative approach, and with excellent stakeholder management skills
Adaptive, quick learner and attention to detail.
Experienced working in multicultural environments and sensitive to different business cultures.
Key responsibilities of the “Information Protection Assessments – Manager” role (expected to work approximately 50% on each area):
- For IPCR program - Execute risk‑focused review activities related to information protection (security, and privacy) controls. Responsibilities include:
Perform risk-based Quality Assessment (QA) reviews of audits/ IPCRs performed, applying independent judgment based on leading practices:
- Distinguish between technical non-compliance, risk, significant weaknesses, and documentation quality gaps.
- Identify misalignment between local (member firm) control interpretations and Global expectations (e.g. System of Quality Management / SoQM).
- Identify subtle issues such as unsupported assumptions, circular reasoning, or misaligned evidence.
- Critically assess the consistency of local testing practices with Global KPMG quality and governance requirements, identify underlying gaps such as weak rationale, unsupported conclusions, or misaligned evidence, as well as good practices.
Evaluate compliance with Global KPMG information security and privacy policy requirements and governance frameworks (including GISP, GAUP, and IFDTA).
For GSIPRA program - Plan, execute and report on supplier security assessments / Global Supplier Information Protection Risk Assessments (GSIPRAs) based on risk indicator analysis and the information protection terms of the agreements of the suppliers, including:
- Compile and maintain up-to-date Key Risk Indicators (KRIs) for suppliers / third parties based on contracts and other supplier profile information (including Bitsight).
- Scope information protection third party / supplier assessments leveraging independent attestation – such as SOC 2 – reports of suppliers and understanding of the information protection terms of agreements
- Perform testing following program workplan materials and ISO 27001 control framework, document results and maintain supporting workpapers and relevant materials up to date
- Report assessment results and potential risks to key stakeholders, including contacts responsible for supplier management and management.
- Contribute to maintenance and enhancement of program materials and procedures.
- Provide feedback for supplier remediation progress for findings identified during GSIPRAs,
monitor and report on remediation progress.
For both IPCR and GSIPRA Programs:
Work efficiently on multiple workstreams based on project plans. Operating autonomously within global teams.
Deliver high‑quality written analysis for senior and global stakeholders, identify themes based on review results.
Partner effectively across teams as a trusted Subject‑Matter Expert (SME)
Support ongoing enhancement of digital risk monitoring and quality practices.
B.E. / B.Tech
Experience Level
Mid LevelJob role
Job requirements
About company
Similar jobs you can apply for
Hardware & Network Engineer
Hardware & Network Engineer
Sonali Enterprises
Hardware & Network Engineer
Techtrix Solutions Pvt Ltd
Printer Engineer
IT WorldMaintenance Engineer
Vision Industrial ServicesInstallation Engineer
Teamlease Services LimitedComputer Hardware Technician
Ezee Power solutionYou can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.
The candidate should have completed the required education and people who have 6 to 31 years are eligible to apply for this job. You can apply for more jobs in Pune to get hired quickly.
The candidate should have sound communication skills and sound communication skills for this job.
Both Male and Female candidates can apply for this job.
No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Pune at apna.
No work-related deposit needs to be made during your employment with the company.
Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.
The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Pune . Through apna, you can find jobs in 64 cities across India. Join NOW!