Skip to content
← Back to job listings

Beijing/Chengdu, Assistant Manager, Information Protection Group

kpmg · Minhang, Shanghai, China

External listingfull-timeabout 2 months ago

About The Role

Job description KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients’ needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment and community. At KPMG, you’ll translate insights into action and reveal opportunities for all—our teams, our clients and our world. Service Line Overview KPMG’s Information Protection Group (IPG), an internal service team under Quality & Risk Management (Q&RM), focuses on information security, privacy, and data rights and movement management. The team ensures expectations from our clients and regulatory bodies are met, so we stay competitive in our business. This position will be based in Chengdu / Beijing and will primarily focus on audit and compliance management, strategic execution, and stakeholder communications, including with senior management. Key Responsibilities Reporting to the Chief Information Security Officer (CISO) on information security matters, and under their direction, the position will: Manage internal/external application security reviews, remediation plan tracking, and firmwide solution lifecycle re-testing. Support and coordinate internal and external information security audits and compliance reviews, including ISO 27001, ISO 27017, and ISO 27701. Maintain and improve compliance with firm policies and standards based on risk assessment results, including tracking remediation actions to closure. Ensure compliance with applicable information security laws and regulations across the Chinese Mainland, Hong Kong, and Macao, and support related evidence collection and reporting. Support and coordinate information protection queries from business units and authorities/regulators, including follow-up actions. Support execution of the firm’s information security agenda through policy implementation, governance routines, and stakeholder communications. Provide risk-based security recommendations that balance information security, operational needs, and business requirements. Partner with first-line IT, the technology group, and business teams to safeguard company information while enabling business development and strategy. Lead by example to foster collaboration and growth within the team. Experience & Background Minimum 3 years of relevant experience in the information security industry. University degree in information Technology, Computer Science, or a related discipline. Hands-on experience in application security review, code auditing, penetration testing, architecture evaluation, etc. Hands-on experience supporting ISO 27001, ISO 27017 and ISO 27701, and related security frameworks. Professional certifications such as CISM, CISA, CISSP and CISP are highly preferred. Hands-on risk assessment experience that addresses both technical controls and actual business risk exposure. Experience with China’s MLPS 2.0 is preferred. Prior experience in a Big 4 environment is a plus. Excellent written and spoken communication skills in English and Chinese. Good time management and analytical skills; able to work independently and provide accurate, timely reporting and management. About KPMG At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance for any form of discrimination against any persons. It is important for us to create an inclusive, diverse and agile workplace for our people to develop and thrive at both a personal and professional level. We strive to make ESG (environmental, social and governance) a watermark running through our organisation; from empowering our people to become agents of positive change, to providing better solutions and services to our clients. To lead by example, we launched Our Impact Plan (OIP) which includes our ESG commitments and progress across four key pillars – Planet, People, Prosperity and Governance. We encourage you to come as you are, and we welcome all qualified candidates to apply, and hope you unlock opportunities with us. Visit KPMG China website for more company information. Please note that all information in this form has been voluntarily supplied and will be used by KPMG for selection purposes only.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing