Job description
Information Assurance (Supply Chain) Manager
Location: Birmingham, Manchester, Leeds, Watford, Reading or Bristol
Role Description:
The Information Assurance team is the 2nd Line of Defence, ensuring KPMG manages information security and data privacy risk and compliance in line with legislative, regulatory & client obligations, enabling the trust and growth agenda.
As an Information Assurance Manager, you will be responsible for the delivery of the supply chain risk and assurance compliance programme. You will collaborate with teams across the firm to navigate complexities of the supply chain and ensure suppliers are compliant with KPMG security and data protection and privacy requirements, helping to minimise risk to our employees, clients and audited entities.
The Information Assurance Manager will apply their supply chain risk and assurance skills to perform all relevant duties as part of the Information Assurance team.
Key Responsibilities:
1. Act as a trusted advisor to stakeholders, providing accurate, appropriate, timely assurance information regarding the KPMG supply chain across capabilities and firmwide.
2. Identify emerging trends and issues with the KPMG supply chain to shape and inform the KPMG risk posture.
3. Support the development and implementation of the annual service roadmap aligned to KPMG strategic goals and ambitions.
4. Develop the annualised audit schedule, applying a risk-based approach, proactively adapting the schedule to accommodate emerging risks or strategic requirements.
5. Be proactive in identification of continuous improvements to foster positive changewithin the Information Assurance team, seeking innovative solutions to enhance practices.
6. Deliver the 2nd LoD Supply Chain audit activity to monitor supply chain compliance against regulatory, client, global and local policy & standard requirements, including ISO27001.
7. Ensure that all supplier contracts include standardised Information Security and Data Privacy statements.
8. Define and report on Supply Chain Assurance metrics, providing insights into compliance and risk, highlighting areas for improvement.
9. Log all findings in the GRC tooling, track, review and monitor remediation results and associated evidence, signing off closure where appropriate.
10. Ensure all findings are linked to risks and the supply chain risk posture is documented and understood.
11. Proactively work with finding owners to ensure remediation actions plans are defined and delivered in a timely manner.
12. Provide analysis and thematic reviews and consolidation of findings and recommend risk treatment plans to reduce risk for the firm.
13. Ensure audit work is documented in accordance with business standard and fully supports conclusions and overall opinion through 1st / 2nd level reviews
14. Coach, performance manage and develop a team across multiple geographies
15. Monitor the activities of the audit team to ensure that all work is delivered to a high standard
16. Lead and conduct other Information Security & Privacy audit activity on behalf of KPMG ( SOC2)
Skills and experience required:
17. Excellent management capability at a manager level, with the ability to motivate teams in multiple locations to deliver an exceptional service
18. Outstanding stakeholder management skills, the ability to collaborate and develop relationships internally and externally
19. Strong experience advising on supply chain matters, with appropriate background in developing and implementing supply chain risk and assurance frameworks
20. Excellent audit management capability, with an ability to quality check auditors
21. Solid working knowledge of ISO27001, Cyber Essentials/ Cyber Essentials Plus, NIST Cybersecurity Framework, CIS, SOC2, Data Protection (UK GDPR, DPA, PECR) and experience of operational implementation
22. Good understanding of ancillary frameworks (EU AI Act, UK AI Frameworks)
23. Experience of maturing processes to deliver service improvements
24. Excellent analytical and reporting skills, using presentation tools to present complex information with exceptional attention to detail
25. Excellent communication skills, both written and verbal
26. Well organised and able to maintain a high workload efficiently at a consistently high standard and manage the workload of a multi geolocated team
27. Strong knowledge of information security controls
28. Experience of implementation and working with GRC tools (ServiceNow) and supplier management tools (Coupa, Bitsight).
29. Understanding of a 3 lines of defence model (risk & assurance)
30. Be highly motivated and able to work independently
Additional Requirements:
31. Significant experience in information security and supply chain risk and assurance.
32. Certifications in information security, such as CISM, CISMP, CISSP.
33. Auditor qualifications, CISA, ISO27001 Lead Auditor, GIAC or equivalent.
34. ITIL foundation certificate or above desirable