- Company Name
- KPMG Canada
- Job Title
- Manager - Cyber Security Strategy & Governance
- Job Description
-
**Job Title**
Manager – Cyber Security Strategy & Governance
**Role Summary**
Lead and manage multiple cyber‑security consulting projects, develop and implement tailored security strategies and governance frameworks for clients—especially in private equity and pensions—while coaching team members and fostering internal innovation.
**Expectations**
- Deliver project outcomes on time and within scope.
- Advise clients on cyber‑risk, regulatory compliance, and defense‑in‑depth controls.
- Build and maintain strong client relationships.
- Mentor junior staff and drive continuous improvement of KPMG’s cyber practice.
**Key Responsibilities**
- Oversee several client engagements simultaneously, ensuring quality and profitability.
- Conduct cyber‑risk assessments, due‑diligence on third parties, and threat analyses.
- Design, update and implement cyber‑security strategies, roadmaps, and operating models.
- Align security controls with standards such as NIST, ISO, COBIT, ISF and sector‑specific regulations.
- Provide governance advice, framework selection, and operating model design.
- Integrate cyber‑security with broader risk management, resilience, and IT transformation services.
- Coach and develop team members; manage performance and professional growth.
- Contribute to internal practice development and KPMG brand building.
**Required Skills**
- Deep knowledge of cyber‑risk assessment, reporting, and mitigation in a business context.
- Experience designing and applying multi‑layer security controls (defense‑in‑depth).
- Proficiency interpreting NIST, ISO, COBIT, ISF, and related regulatory requirements.
- Strong understanding of risk management principles and business resilience planning.
- Ability to translate technical security concepts into clear client guidance.
- Excellent communication, stakeholder management, and leadership abilities.
- Consulting experience preferred; sector expertise in private equity or pensions essential.
**Required Education & Certifications**
- Bachelor’s or Master’s degree in Information Security, Computer Science, Engineering, Business, or related field (or equivalent experience).
- Professional certifications such as CISSP, CISA, CRISC, CISM, CEH, CGEIT, ITIL, PCI QSA, CIPP/C, TOGAF, or SABSA (one or more preferred).