IT Risk and Compliance Manager
Kingston, St. Andrew Parish, Jamaica (Hybrid) · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- hace 2 horas
- Work mode
- Hybrid
- Education
- Bachelor's degree in Computer Science, Risk Management, Cybersecurity, or a related field
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
The IT Risk and Compliance Manager will lead multifaceted risk management efforts at KPMG Jamaica's JESS delivery center in Kingston, supporting KPMG United States. This role emphasizes data risk expertise, control design, and collaboration with leadership and Line of Defense (LoD) partners to enhance technology, data, operations, and cyber risk practices. The manager will oversee risk lifecycle management and recommend improvements to safeguard the organization.
Key Responsibilities
- Conduct comprehensive risk assessments across technology, data, operations, and cybersecurity sectors, converting complex insights into executive recommendations.
- Apply advanced knowledge in Second and Third LoD data risk management, including data modeling, strategies, and governance controls.
- Design and advocate for management controls that mitigate risks, support a risk-conscious culture, and align with firm policies and risk appetite.
- Assess critical risk impacts and industry changes to offer strategic risk management recommendations to senior leaders.
- Create and maintain detailed risk and control matrices and registers overseeing the entire risk lifecycle from identification through remediation.
- Develop collaborative relationships with peers, senior management, and LoD teams to focus internal audits and risk initiatives on key areas.
Qualifications and Experience
- Bachelor's degree in Computer Science, Risk Management, Cybersecurity, or related discipline.
- At least five years of experience in risk and compliance roles within professional services, particularly involving physical and cyber security.
- Possession of industry certifications such as CIA, CISA, CISM, CRISC, or CISSP.
- Proven knowledge of multiple compliance frameworks and risk management methodologies with a capacity for optimizing operational risks.
- Strong ability to interpret technical data and communicate effectively to non-technical stakeholders.
- Understanding of balancing business goals with IT risk management.
- Excellent verbal and written communication, analytical thinking, problem solving, and decision-making capabilities.
- Skilled in independent work and teamwork, time management, organization, and adherence to deadlines.
- Proficiency in Microsoft Office applications including Word, Excel, PowerPoint, and Outlook.
Special Working Conditions
- The position supports a hybrid work approach, requiring office presence at least five days per month with flexibility for additional days based on operational demands.
- Use of KPMG-approved generative AI tools is expected to support daily tasks.
- The role involves working mainly in a paperless environment, utilizing information systems throughout the workday.
- Occasional extended hours and work on public holidays may be necessary.