Job description
Service Delivery Security Manager
Team
The Service Delivery Security Manager role is in the KPMG UK Information Security function and reports directly to the Security Production Assurance & Compliance Lead. This role is critical in the provision and delivery of secure, innovative, technology-enabled services and solutions for KPMG and our clients. The role is vital to KPMG’s ability to demonstrate that we are delivering ‘secure by design’ services and solutions such that our business stakeholders, our clients and our regulators trust KPMG.
Role
The primary purpose of the role is to enable harmonious delivery of Security Services, by ensuring strong collaboration with the external Service Providers and entire range of KPMG business functions. There are 3 main areas of focus:
1. Manage the security services relationship to protect the delivery of the end to service services that involve all KPMG UK Technology services, or third-party suppliers.
2. Provide governance for infrastructure security services
3. Provide an overview of the complete set of services provided by all KPMG UK Technology services, or third-party suppliers and troubleshoot any issues and escalate as appropriate.
Key responsibilities are:
4. Work closely with the Service Owners who are accountable for the end-to-end services, understand their roadmap for the service and the day-to-day operational requirements
5. Maintain and lead the process to manage the Governance of these services
6. Ensure firm standards and guidelines are followed, and contractual or operational commitments are delivered
7. Review and govern the Service Provider Quality, Improvement Plans, Issues and Operational Risks, engaging the Security Production Assurance & Compliance Lead as required
8. Raise and build consensus around issues or escalations and enable timely resolution.
9. Govern Service Provider Knowledge Management, Knowledge Transfer, Reporting, Documentation and other engagement practices to ensure ongoing operational excellence
10. Review Service Provider capacity plan to ensure it has enough capacity to meet the required demand and is in line with the Service Owner’s roadmaps
11. Consolidate and provide reports on the delivery of Security services and initiatives across the relevant KPMG capabilities
12. Ensure any planned changes across Technology or Service Provider are co-ordinated to ensure there is minimum disruption to Information Security services.
13. Communicate major changes or enhancements in Information Security to Service Provider/ Business function and vice-versa
14. Act as a single point of contact for general queries or issues flowing to and from the Security Function to the delivery teams
15. Work closely with the Service Delivery Managers and Service Owners to ensure everyone has a clear view of the remediations and expectations
16. Work closely with the Security Production Assurance & Compliance Lead to implement the operational security activities, processes and standards as determined by them.
17. Build long-term stakeholder relationships including negotiating service levels, and defining project scope.
18. Monitor, review and drive compliance to security policies, guideline and standards (as defined by KPMG) using compliance reports supplied by the Supplier and internal teams. You will escalate issues to the Security Production Assurance & Compliance Lead where necessary
19. Use your experience to propose changes to existing policies and procedures based on feedback from Internal and Supplier Service Operations teams to Security Production Assurance & Compliance Lead to drive operating efficiency and compliance
20. You will support incident and problem management teams in prioritisation of security issues and serve as an active participant in the security governance processes
21. Manage and develop the compliance for relevant technical security domains using automation, digitisation, security by design and a customer focussed approach as appropriate, and formulate a service strategy and roadmap for these
Knowledge/Skills
22. Ability to create and maintain insightful dashboards (ideally via PowerBI), by unifying reports and metrics from various sources (e.g. spreadsheets and SaaS platforms.)
23. Excellent and relevant experience in a similar infrastructure or technology management leadership role
24. Proven understanding of change management processes in a fully change managed environment (ITIL)
25. Excellent interpersonal skills, ability to negotiate and influence wide range of stakeholders at all levels of the firm; UK and Global
26. Experience in managing delivery teams and the delivery of Managed IT services
27. Experience in managing relationships with key stakeholders and 3rd party suppliers
28. Able to deliver transformation plans to support operational objectives
29. Literate and numerate, with Good financial and commercial skills
30. Must have excellent presentation skills
31. Sets challenging objectives that reflect key strategic medium and longer-term priorities
32. Works on CPD to maintain professional status/accreditation.
33. Strong understanding of tooling associated with infrastructure services management such as Endpoint Protection, IT Service Management (ITSM) platforms, and a range of security tools.
34. Experience and knowledge of managing applications and infrastructure within the Cloud.
35. Be able to demonstrate the ability to adapt communication style to explain technical concepts to different people within an organisation whether advising stakeholders, directing teams or sharing experience;
36. Experience of successfully working in a fast paced, customer service environment, delivering high quality information security services.
Desirable certifications:
37. CISM
38. CISSP
39. Cloud-related Certifications