Talent.com
KPMG
Business Information Security Officer, AdvisoryKPMG • Toronto, Ontario, Canada
Business Information Security Officer, Advisory

Business Information Security Officer, Advisory

KPMG • Toronto, Ontario, Canada
30+ days ago
Job type
  • Full-time
Job description
Overview
At KPMG in Canada, our people bring their unique perspectives to Canada's most important challenges. Here, you can build momentum that reaches beyond our business, develop skills for the future, and take ownership of your career with support at every stage. Join a firm where your career can make a difference.

KPMG Canada is seeking an experienced professional to fulfill the role of Business Information Security Officer (BISO) - Advisory. This role reports to the Firm's Chief Information Security Officer and operates within the Advisory Business Unit, serving as the primary liaison between the central security function and the business.

This is an exciting opportunity for an individual with deep, cutting-edge experience in assessing security risks related to modern AI-enabled technology solutions and designing security guardrails to enable their safe and effective use.

Advisory at KPMG is a fast-paced environment, offering Risk and Management Consulting, Cyber Security, and Deal Advisory services to drive value and success. KPMG Canada's Digital Security Group is responsible for governing and overseeing the Firm's data and information security programme.

The BISO will collaborate with Business, Risk, Privacy, and Technology teams to assess and analyze cybersecurity risks. The individual will provide security recommendations based on identified threats and risks, while considering compliance and regulatory requirements relevant to the Business Unit. Additionally, the individual will document and track identified risks and recommendations and obtain necessary risk and security approvals where required.

The ideal candidate will demonstrate strong knowledge of modern application lifecycle practices, security architecture, cloud platforms, Generative AI tools, frontier models, API security, and application security standards such as OWASP, along with familiarity with frameworks such as ISO 42001.

What you will do
  • Serve as the primary information security liaison between the Business Unit and the Digital Security Group
  • Translate Firm security policies, procedures, and standards into practical, risk-based controls for the Business Unit technology ecosystem
  • Proactively unblock and manage security, risk, and compliance issues by bringing together Advisory, ITS, Risk, Security stakeholders, driving decisions, tracking actions, and ensuring issues are worked through to a clear and timely end state
  • Monitor compliance with KPMG security policies, standards, and control requirements; identify non-compliance, initiate remediation actions, and track exceptions through formal risk acceptance processes with appropriate compensating controls
  • Act as the BU key point of contact to understand security risks related to evolving business requirements for technology and solutions, and apply security-by-design principles to provide proactive, business-focused, guidance aligned with Firm's security policies and standards
  • In coordination with Platform Security team, assess and review business-requested software, tools, and AI capabilities (including SaaS and Generative AI solutions) for security, privacy, and compliance risks; lead intake, risk evaluation, and provide delegated approval or whitelisting where necessary
  • Collaborate with Project, Technology, Business, and Risk teams to gather requirements and support the Security Assessment Review (SAR) process, led by Platform Security
  • Develop and maintain a business unit Risk Register to track security risks
  • Coordinate with stakeholders to ensure security requirements are documented and tracked throughout the project lifecycle
Governance
  • Maintain a strong understanding of KPMG security policies (e.g., GISP, AUP, ATO), requirements, and guidance from the CISO, Risk Management Partner, and Office of the General Counsel
  • Maintain and validate a comprehensive inventory of business applications, tools, and technology assets (on-premises and cloud), ensuring alignment with Firm security standards
  • Coordinate implementation and onboarding of new security programs and capabilities as directed by the CISO
  • Contribute to annual business planning processes and recommend initiatives to enhance security posture and operational efficiency
  • Represent the business unit and provide key metrics in monthly security governance forums
Vulnerability Management and Incident Response
  • Own BU-level vulnerability management, including identification, prioritization, and remediation tracking across applications, endpoints, and cloud environments (including CSPM)
  • Partner with Technology teams to drive timely remediation of identified vulnerabilities
  • Manage responses to security incidents following KPMG's incident management processes
  • Represent the business unit in SEV1 incident response bridges
Monitoring
  • Monitor adherence to KPMG security policies and standards
  • Review compliance reports generated by security tools and address identified issues
  • Perform regular reviews of installed applications to identify prohibited software and initiate remediation actions
  • Maintain an accurate and up-to-date inventory of business applications (on-premises and cloud environments including Azure, AWS, and GCP)
  • Monitor control effectiveness across all technology assets within the business unit
What you bring to the role
  • Bachelor's or Master's degree in Information Technology, Computer Science, Cyber Security or a related field, or equivalent experience•
  • 10+ years of experience in application, technology, or solution design, architecture, development, and implementation
  • 5+ years of experience in secure design/architecture and project risk assessments across modern cloud and on-premises environments, including SaaS solutions
  • 5+ years of experience as a security practitioner in a leadership role
  • Deep understanding of modern application development ecosystems, open systems, Generative AI, and emerging technologies
  • Strong knowledge of information security standards and frameworks (e.g., CSA CCM, ISO 27001/27017/27018/42001, PCI DSS, NIST CSF, NIST 800-53) and data protection principles
  • Experience working with modern AI tools and capabilities
  • Proven experience in a consulting or advisory role, collaborating with Technology, Project, and Business stakeholders
  • Holding any of the following certifications would be considered an asset but not required: CISSP, CISA, CRISC, CISM
Providing you with the support you need to be at your best
Our Values, The KPMG Way
Integrity, we do what is right | Excellence, we never stop learning and improving | Courage, we think and act boldly | Together, we respect each other and draw strength from our differences | For Better, we do what matters

KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice.

Adjustments and accommodations throughout the recruitment process
At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. Adjustments (informal requests), such as extra preparation time or the option for micro breaks during interviews, and accommodations (formal requests), such as accessible communication supports or technology aids, are tailored to individual needs and role requirements. You will have an opportunity to request an adjustment or accommodation at any point throughout the recruitment process. If you require support, please contact KPMG's Employee Relations Service team by calling 1-888-466-4778.

AI Usage
Weembrace the use of artificial intelligence (AI) to enhance the candidate experience and streamline our recruitment processes. AI tools may help with organizing applications or surfacing relevant qualifications. However, no hiring decisions are made using AI. Every hiring decision is made by our hiring managers and recruitment professionals, who are equipped with training that empowers them to use these tools responsibly. AI technologies used in our recruitment process undergo detailed risk assessments, including security and privacy requirements, that align with KPMG's Trusted AI framework.

We believe technology should empower human judgment, not replace it. It's one of the many ways we're delivering on our vision of being a technology-first, people-driven firm.
Create a job alert for this search

Business Information Security Officer, Advisory • Toronto, Ontario, Canada

Similar jobs

Senior Information Security Officer

SOCANToronto, ON, CA
Permanent

Senior Information Security Officer (SISO).English required; French is an asset.Security Governance: develop, maintain, and socialize security policies, standards, procedures, and architecture guar... Show more

 • Promoted

Senior Associate, Information Security

Publicis Groupe Holdings B.VToronto
Full-time

The Senior Associate, Information Security is part of a global team and is responsible for incident response of cyber security incidents that are associated with our businesses, clients, and vendor... Show more

 • Promoted

Information Security Analyst (1-Year Contract) - C$85,000 - C$90,000 A Year

NumerisToronto County, Canada
Full-time

Information Security Analyst responsible for promoting security awareness, protecting assets from cyber threats, monitoring systems, responding to incidents, managing vulnerabilities, and conductin... Show more

 • Promoted

Director, Information Security

Teranettoronto, on, Canada
Full-time

Teranet is Canada’s leader in the delivery and transformation of statutory registry services with extensive expertise in land and commercial registries.Teranet seeks a visionary Director of Informa... Show more

 • Promoted

Information Security Governance Analyst

Ontario Medical AssociationToronto, ON, CA
Full-time

Advance the cybersecurity landscape as an Information Security Governance Analyst.Focus on compliance oversight, risk management strategies, and security improvements in a flexible hybrid environme... Show more

 • Promoted

Strategic Information Security Architect

ColliersToronto, ON, CA
Full-time

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Show more

 • Promoted

AWS Security Architect

Venterra Realtyrichmond hill, york region, Canada
Full-time

Hybrid / Corporate Office in Richmond Hill, Ontario.Salary: $130,000 - $170,000; up to 10% discretionary incentive target*.This position is designed for a senior‑level subject matter expert (SME) w... Show more

 • Promoted

Information Security Specialist

Raise - find a more meaningful working experienceToronto
Full-time

Information Security Specialist.We at Raise are hiring an Information Security Specialist for one of our top clients.After establishing themselves as an industry leader, they’re now expanding their... Show more

 • Promoted

Information Security Consultant

CONFLUX SYSTEMSMarkham, Ontario, Canada
Full-time

This request is to on-board resource for Application security team focusing on threat modelling, security architecture.Work with application teams and complete threat model.Develop and deliver secu... Show more

 • Promoted

Enterprise Security Specialist

Cprvisionwhitchurch stouffville, on, Canada
Full-time

Enterprise Security Specialist.Location: Stouffville, ON • Department: R&D • Reports to: Chief Technology Officer (CTO) • Salary: $120,000 - $135,000 • Openings: 1.Lead the development, implementat... Show more

 • Promoted

Manager, IT Governance, Risk and Compliance

Pet Valumarkham, on, Canada
Full-time +1

Manager, IT Governance, Risk and ComplianceApplyremote type: Hybridlocations: 0001 – Markham Officetime type: Full timeposted on: Posted Todayjob requisition id: R25751Hybrid: Markham, On... Show more

 • Promoted

Information Security Officer Business Operations · Vancouver · - C$110,000 - C$130,000 A Year

Klohn Crippen BergerToronto County, Canada
Full-time

Seeking an experienced Information Security Officer to lead KCB's enterprise cybersecurity program, focusing on strategy, risk management, policy, operations, and incident response across globa... Show more

 • Promoted

Information Security Officer - $110,000 - $130,000 A Year

KcbNorth York, Canada
Full-time

Lead the development and execution of cybersecurity strategy, risk management, incident response, and policy compliance for an organization.Requires strong knowledge of security frameworks and tech... Show more

 • Promoted

Information Security Consultant

ReleadyToronto, ON, CA
Full-time

Contract Duration: June 29th - December 12th 2026.We are seeking an experienced Information Security Consultant to provide expert advisory and delivery support across business units.This role invol... Show more

 • Promoted

Senior Information Security Officer - $101,360 - $121,360 A Year - Remote

SocanNorth York, Canada
Remote
Full-time

Seeking a Senior Information Security Officer to manage security governance, risk, and operations.Responsibilities include threat hunting, incident response, and vulnerability management across clo... Show more

 • Promoted

Information Security Analyst

BDO CanadaToronto, ON, CA
Full-time

BDO is a firm built on a foundation of positive relationships with our people and clients.Reporting to the Manager, Information Security, the Information Security Analyst supports security operatio... Show more

 • Promoted

Chief Information Security Officer

CohereToronto, Canada
Full-time

Canada)Type: US Applicants – Full-Time; Canadian Applicants – Independent ContractorAbout Human AgencyWe\ 're scaling rapidly and havea growing pipeline of opportunities that demand exception... Show more

 • Promoted

Information Security Analyst — Toronto Opportunity

Canada fruit produce companyToronto
Full-time

Information Security Analyst vacancy in Toronto Canada.Information Security Analyst Jobs in Toronto:.The most in-demand professions in Toronto:.Users also frequently search in these cities::.More p... Show more

 • Promoted

Information Security Operations Leader - $110,000 - $130,000 A Year

Global Engineering Consulting FirmNorth York, Canada
Full-time

Experienced Information Security Officer to lead cybersecurity initiatives, manage governance, risk, and policy implementation for a global engineering consulting firm. Show more

 • Promoted

Information Security Manager

Insight GlobalToronto, ON, CA
Full-time

Demonstrated history of technical leadership and strategic thinking in security roles.Extensive experience leading and managing complex security investigations and threat hunting engagements.Bachel... Show more