At a Glance
- Tasks: Lead incident response strategies and advise on global security standards.
- Company: Join KPMG, a leader in global information security.
- Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
- Other info: Dynamic role with a focus on collaboration and continuous learning.
- Why this job: Make a real impact in cybersecurity while working with diverse teams.
- Qualifications: Bachelor's degree in relevant field and experience in security programs required.
The predicted salary is between 70000 - 90000 € per year.
Location: Birmingham, Bristol, Glasgow, London, Manchester, Milton Keynes, Reading, Watford
Capability: International
Experience Level: Senior Manager
Type: Full Time
Business Area: KPMG International
Contract type: Permanent
About the Team
Global Information Security Group (GISG) is a domain within KPMG’s Global Digital group that provides information protection and technology infrastructure and services to secure KPMG’s technology environment and connect its network of member firms.
Role Summary
- Advise member firms on the implementation of KPMG information risk and security standards / requirements related to Incident Management.
- Recommend and support member firms to enforce defined security policies and global technology standard.
- Maintain an up-to-date knowledge base following global incident trends, security advisories and alerts, information on global standard and best practices.
- Vulnerability management and controls validation: evaluate and select vulnerability assessment and other security assessment capabilities, and deploy, operate and maintain these technologies and adjacent processes.
- Closely follow security trends and vulnerabilities, cyber security threats and provide feedback to Global security.
- Actively communicate and keep abreast of the latest trends in threat intelligence and incident response.
- Advise member firms how to best manage local incident response training to ensure readiness across regions.
- Advise and support member firms in improving the effectiveness of their event and incident management operation.
- Monitor and report a consolidated regional view of global technology standard adoption status and take action by following up on findings.
- Lead the assessment and provide recommendations on any exceptions to policies or standards.
- Lead and oversee regional incident triage activities and tracking of critical cybersecurity incidents from initial detection through final resolution.
- Lead and oversee incident escalation towards member firms and global teams.
- Work with Global security on red / blue teaming activities on regional level.
- Setting up and leading a community with the EMA region with respect to technical trends, vulnerabilities and incidents.
- Lead and oversee compliance with any applicable regulatory requirements for cyber incident.
Key Accountabilities
- Advise member firms on Global security standards for incident response and issues (adopting, monitoring).
- Deliver security reporting for incident response, escalations, and opportunities into Regional Information Security Officer (RISO).
- Facilitate meetings with Member Firms on implementation incident management processing and tools, including best practices.
- Capture specific Member Firm requirements for services and act as a conduit into RISO to recommend service updates.
- Provide support into Member Firms on incident management related matters.
- Support Security Incident Response processes across the Region.
Experience, Knowledge & Qualification
- Bachelor’s degree in Computer Science, Information Security, Information Systems, Computer Engineering, or a related field is required.
- Proven experience developing or managing an enterprise level of security programs (focus on Incident Management).
- At least one industry certification preferred (e.g. CISSP, CISA, CISM, CRISC, ISAAP).
- Background working on large-scale international services and the ability to manage multiple processes and service delivery at once while building constructive working relationships across the different teams, functions, cultures, genders and demonstrating KPMG behaviours and values.
- Security Operations / Incident Management / Managed Security Services experience preferred.
- Working knowledge of multiple security topics such as threat intelligence, vulnerability management products, firewall management or endpoint protection.
- Deep knowledge of cyber kill chain and understanding of threat intelligence lifecycle.
- Strong knowledge of computer networking concepts and protocols (including OSI and TCP/IP layer models) and network security methodologies.
- Strong knowledge of intrusion detection methodologies and techniques for detecting host and network-based intrusions.
- Experienced in deployment and maintenance of Microsoft products.
- Keeps abreast of security related technology, practices and regulations in the marketplace and validates tools for use to improve the Managed Security Services offerings.
- Experience in working in a matrix management environment.
- Working knowledge of common IT security-related regulations and or standards such as Sarbanes‑Oxley and ISO highly desired.
- Strong oral and written communication skills.
- Must have strong analytical and critical‑thinking skills.
- Expertise in conducting incident response activities and seeing incidents through to successful remediation across multiple geographies.
Accessibility and Reasonable Adjustments
KPMG International is proud to be an inclusive place to work and we are committed to ensuring that you are treated fairly throughout our recruitment process. If you require reasonable adjustments, please discuss them with your recruitment contact.
Commitment to Inclusion & Diversity
KPMG International recognises that inclusion and diversity are essential for success and strives to attract, retain, and develop diverse talent at all levels, creating a fully inclusive environment that empowers everyone.
Regional Information Security Manager - Incident Response in Birmingham employer: KPMG Careers
KPMG International is an exceptional employer, offering a dynamic work culture that prioritises inclusion and diversity while fostering professional growth. As a Regional Information Security Manager in various vibrant UK locations, you will benefit from a collaborative environment, access to cutting-edge technology, and opportunities to lead impactful security initiatives across member firms, ensuring your contributions are both meaningful and rewarding.
StudySmarter Expert Advice🤫
We think this is how you could land Regional Information Security Manager - Incident Response in Birmingham
✨Tip Number 1
Network like a pro! Reach out to folks in the industry on LinkedIn or at local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching common questions in the information security field. Practice your responses, but keep it natural. We want you to sound confident and knowledgeable!
✨Tip Number 3
Showcase your skills through real-world examples. When discussing your experience, highlight specific incidents you've managed or vulnerabilities you've addressed. This will make you stand out as a candidate.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Regional Information Security Manager - Incident Response in Birmingham
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in incident management and security standards. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!
Showcase Your Knowledge:Demonstrate your understanding of current security trends and incident response practices. Mention any certifications you have, like CISSP or CISM, as they can really set you apart from other candidates. We love seeing candidates who are up-to-date with the latest in cybersecurity!
Be Clear and Concise:When writing your application, keep it straightforward and to the point. Use clear language and avoid jargon unless necessary. We appreciate a well-structured application that’s easy to read and gets straight to the important bits.
Apply Through Our Website:Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it makes the whole process smoother for everyone involved.
How to prepare for a job interview at KPMG Careers
✨Know Your Incident Response Inside Out
Make sure you brush up on the latest trends in incident response and threat intelligence. Be prepared to discuss specific incidents you've managed and how you approached them. This shows your hands-on experience and understanding of the field.
✨Familiarise Yourself with KPMG's Standards
Research KPMG’s global security standards and policies related to incident management. Understanding their framework will help you align your answers with their expectations and demonstrate your commitment to their values.
✨Prepare for Scenario-Based Questions
Expect questions that ask you to solve hypothetical incident scenarios. Practice articulating your thought process clearly, focusing on how you would assess, respond, and communicate during an incident. This showcases your analytical skills and decision-making abilities.
✨Showcase Your Communication Skills
As a Regional Information Security Manager, you'll need to communicate effectively with various stakeholders. Prepare examples of how you've successfully facilitated meetings or communicated complex security concepts to non-technical teams. This will highlight your ability to build constructive relationships.