At a Glance
- Tasks: Join a dynamic team to tackle cyber threats and enhance data security.
- Company: KPMG International, a global leader in professional services.
- Benefits: Flexible working, competitive salary, and opportunities for growth.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
- Qualifications: Experience in incident response and knowledge of data protection regulations.
- Other info: Inclusive culture with a focus on diversity and career development.
The predicted salary is between 43200 - 72000 £ per year.
Base Location: London or fully remote with occasional London travel.
About KPMG International
Together with more than 273,000 colleagues in 143 countries throughout our member firms, people at KPMG imagine big ideas and bring solutions to life for clients both big and small. A role with KPMG International will open a world of opportunity in your career. KPMG International helps set the strategy and protects the reputation of this global organization of independent professional services firms providing Audit, Tax and Advisory services. We deliver value to our member firms and drive positive change in the communities we serve. By joining us you will gain a unique understanding of how a global organization operates and work on projects that impact the whole organization.
About this Global Group
Global Technology & Knowledge provides crucial services to enable KPMG’s digital transformation, ensure security across the network and accelerate our Collective Strategy.
About this Team
GISG (Global Information Security Group) provides the information protection and technology infrastructure that secures KPMG’s technology environment and connects its network of member firms. GISG works with the other GT&K domains to ensure that appropriate security controls are in place for KPMG technology solutions.
Role summary
The Cyber Security Incident Response Manager plays a pivotal role in identifying, investigating, and managing cyber and data handling incidents within KPMG’s Global Information Security Services (ISS) function. ISS delivers and oversees critical cybersecurity capabilities—including Security Monitoring & Response (SMR), Vulnerability Assessment & Secure Development (VASD), and Cyber Threat Intelligence (CTI)—across Global, Global Functions, and the broader KPMG network of member firms.
This position offers an exciting opportunity to join a progressive and innovation-driven security team, contributing directly to the evolution of the Cyber Security Incident Response Team (CSIRT) on a global scale. The role reports directly to the Global Cyber Security Incident Response (CSIRT) Lead.
The ideal candidate will bring knowledge in Cyber incident response, data protection, and regulatory compliance, along with the ability to collaborate effectively across functions to reduce risk and strengthen KPMG’s global data security posture.
Key Accountabilities
- Incident Detection & Response: Triage alerts reported by GSOC, Global functions and KPMG's network of member firms, including clients, supply chain and from Security tooling like DLP, CASB, XDR and SIEM. Contribute to the investigation and response to cyber and data handling incidents, including misdirected emails, unauthorized data access, and policy violations. Support containment, eradication, and recovery efforts for Cyber and data-related incidents.
- Root Cause Analysis & Reporting: Contribute to root cause analysis to determine the origin and impact of incidents. Document incidents thoroughly and support preparation of detailed reports for internal stakeholders and regulatory bodies as required.
- Cross-Functional Integration & Alignment: Collaborate with teams across Legal, HR, Compliance, Global Enterprise Technology (GET), Global Functions, RSD and key Member Firms to ensure appropriate incident handling and communications aligned to best practices. Contribute to the delivery of guidance and support on secure data handling practices. Support changes in standards and policies.
- Process Improvement: Identify gaps in detection and response processes and recommend improvements. Support the development and refinement of playbooks and standard operating procedures (SOPs) for cyber and data-related incidents. Support the evolution of the service.
- Training & Awareness: Support security awareness initiatives related to data handling and incident management and reporting. Contribute to the delivery of training to first-line responders and KPMG member firm security teams on incident escalation procedures.
Experience / Knowledge / Qualification
- Leadership & Strategic Experience: Proven experience in incident response, preferably with a focus on data protection and privacy incidents within highly regulated industries such as professional services, finance, healthcare, or energy.
- Technical Expertise in Cybersecurity & Incident Response: Experience with email security, cloud platforms, and endpoint protection. Strong understanding of DLP, CASB, SIEM, XDR and other security monitoring tools. Proven ability to manage and/or support response to complex security incidents and data breaches. Strong troubleshooting and problem-solving skills, with the ability to remain calm and effective under pressure.
- Risk, Governance & Regulatory Knowledge: Strong understanding of cyber and data risk factors impacting information security. Familiarity with data protection regulations (e.g., GDPR, HIPAA, CCPA). In-depth knowledge of cybersecurity regulations, standards, and best practices. High level of integrity and professionalism, with a commitment to ethical conduct and confidentiality. Ability to obtain and maintain security clearance where required.
- Communication & Stakeholder Engagement: Exceptional communication and interpersonal skills, with the ability to collaborate effectively across diverse global stakeholders. Strong analytical skills with the ability to assess and mitigate risks and influence decision-making at senior levels.
- Education & Certifications: Bachelor’s, Master’s, or PhD in Computing, Information Security, or a related field (or equivalent professional experience). Relevant certifications such as CISSP, CISM, GIAC (GCIH, GCFA), or CIPP are highly desirable.
Agile/Flexible Working
At KPMG International, we are supportive of helping you to achieve a balance between your home and work demands. We are happy to discuss individual requirements and our range of flexible working arrangements could be of interest.
KPMG International's commitment to inclusion & diversity
At KPMG International, we recognise that we need inclusion and diversity to be successful. We want to attract, retain and develop diverse talent at all levels.
Global CSIRT Senior Analyst employer: KPMG UK
Contact Detail:
KPMG UK Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Global CSIRT Senior Analyst
✨Tip Number 1
Network like a pro! Reach out to current or former KPMG employees on LinkedIn. Ask them about their experiences and any tips they might have for landing the Global CSIRT Senior Analyst role. Personal connections can give you insights that job descriptions just can't.
✨Tip Number 2
Prepare for the interview by brushing up on your incident response knowledge. Be ready to discuss specific scenarios where you've handled cyber incidents. We want to see how you think on your feet, so practice articulating your thought process clearly.
✨Tip Number 3
Show off your passion for cybersecurity! During interviews, share your thoughts on current trends in data protection and how they relate to KPMG's mission. This will demonstrate your commitment and understanding of the field.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you're serious about joining the KPMG team. Make sure to follow up after applying to express your enthusiasm!
We think you need these skills to ace Global CSIRT Senior Analyst
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter for the Global CSIRT Senior Analyst role. Highlight your experience in incident response and data protection, and show us how your skills align with what we're looking for.
Showcase Your Technical Skills: We want to see your expertise in cybersecurity tools like DLP, CASB, and SIEM. Be specific about your technical skills and any relevant certifications you hold, as this will help us understand your fit for the role.
Be Clear and Concise: When writing your application, keep it straightforward. Use clear language and avoid jargon where possible. We appreciate a well-structured application that gets straight to the point!
Apply Through Our Website: Don’t forget to submit your application through our official website! It’s the best way for us to receive your details and ensures you’re considered for the role. We can’t wait to hear from you!
How to prepare for a job interview at KPMG UK
✨Know Your Cybersecurity Stuff
Make sure you brush up on your knowledge of incident response, data protection, and regulatory compliance. Be ready to discuss specific tools like DLP, CASB, and SIEM, as well as your experience with them. This will show that you’re not just familiar with the theory but have practical expertise.
✨Prepare for Scenario Questions
Expect to be asked about how you would handle specific cyber incidents. Think through some scenarios in advance, such as dealing with a data breach or a phishing attack. Having a structured approach to these situations will demonstrate your problem-solving skills and calmness under pressure.
✨Show Your Collaborative Spirit
This role requires working across various teams, so be prepared to talk about your experience collaborating with different departments. Highlight any past experiences where you successfully integrated with legal, HR, or compliance teams to manage incidents effectively.
✨Communicate Clearly and Confidently
Strong communication skills are key in this role. Practice articulating your thoughts clearly and confidently. You might be asked to explain complex cybersecurity concepts to non-technical stakeholders, so being able to simplify your language will be a big plus.