岗位描述
KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients' needs and their industries. At KPMG, you'll translate insights into action and reveal opportunities for all—our teams, our clients and our world.
Service Line Overview
KPMG's Information Protection Group (IPG), an internal service team under Quality & Risk Management (QRM), focuses on driving matters covering information security, privacy, data rights and movement management. The team is to ensure expectations from our clients and regulatory bodies are addressed to stay competitive in our business.
We are looking for a motivated information security professional to join our Information Protection Group as an Assistant Manager. Reporting to the Chief Information Security Officer (CISO), you will help manage the firm's information security governance, risk, compliance, assurance, and stakeholder engagement activities. You will work with technology, risk, compliance, business, and external stakeholders to protect the firm and client information while supporting business priorities.
Key Responsibilities
Coordinate vulnerability assessments, track remediation plans, escalate overdue actions, and monitor high-risk, actively exploited, and zero-day vulnerabilities.
Coordinate internal and external information security audits, certifications, and compliance reviews, including assessments against ISO 27001, ISO 27017, ISO 27701, and applicable regulatory and client requirements.
Review risk assessment results and track corrective actions to help ensure compliance with firm policies, standards, and control requirements.
Support the coordination of compliance evidence collection, report preparation, and remediation follow-up within the applicable jurisdiction, helping the firm comply with information security, personal information protection, data security, and cybersecurity laws and regulations in the Chinese Mainland, Hong Kong SAR, and Macao SAR, in accordance with established firm policies and procedures.
Coordinate responses to information security enquiries, client due diligence requests, and security assessments from business teams, clients, authorities, and regulators.
Support the firm's information security programme through policy implementation, governance activities, risk reporting, awareness initiatives, and stakeholder communications.
Provide practical, risk-based advice that balances information security requirements with operational needs, regulatory expectations, and business objectives.
Work with technology, risk, compliance, and business teams to protect firm and client information and support business initiatives.
Promote a security-conscious culture by supporting awareness initiatives, sharing good practices, and advising stakeholders on information security requirements.
Experience & Background
Bachelor's degree in information technology, cybersecurity, computer science, or a related discipline.
Typically three to five years of relevant experience in cybersecurity, information security governance, technology risk management, compliance, or a related field. You should be comfortable coordinating workstreams and working independently with stakeholders.
Sound knowledge of technology risk management and cybersecurity practices, with familiarity with ISO 27001, the NIST Cybersecurity Framework, the Chinese Mainland Multi-Level Protection Scheme (MLPS), data privacy requirements, and other relevant industry standards.
Relevant professional certifications—such as CISA, CISM, CDPSE, CRISC, CISSP, Certified Information Security Professional (CISP), or an equivalent qualification—are desirable.
Strong communication, interpersonal, coordination, and stakeholder management skills, together with a collaborative approach.
Strong analytical and problem-solving skills, attention to detail, and the ability to manage several priorities at the same time.
Proficiency in written and spoken English and Chinese.
About KPMG
At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance for any form of discrimination against any persons. It is important for us to create an inclusive, diverse and agile workplace for our people to develop and thrive at both a personal and professional level.
We strive to make ESG (environmental, social and governance) a watermark running through our organisation; from empowering our people to become agents of positive change, to providing better solutions and services to our clients. To lead by example, we launched Our Impact Plan (OIP) which includes our ESG commitments and progress across four key pillars – Planet, People, Prosperity and Governance.
We encourage you to come as you are, and we welcome all qualified candidates to apply, and hope you unlock opportunities with us. Visit KPMG China website for more company information.
You acknowledge and agree that all personal information hereby provided regarding yourself will be used by KPMG China for its candidate selection purposed only. KPMG China collects, uses, processes, and retains your personal information in accordance with KPMG China's Online Privacy Statement and/or KPMG China Privacy Statement (collectively "Privacy Statement"). During the recruitment process, KPMG China may need to store personal information of candidates in a designated third-party application tracking platform.
If you have any questions regarding the information you provided in the form or your job application in general, please contact KPMG China's HR personnel in the location where your application is submitted [see here].