- Company Name
- KPMG Canada
- Job Title
- Senior Manager - IT Risk Services
- Job Description
-
**Job Title**
Senior Manager – IT Risk Services
**Role Summary**
Lead IT risk assessment, advisory, and internal audit engagements across diverse technology domains. Manage multiple client engagements, ensuring quality, profitability, and compliance with industry standards while driving business development and client relationship growth.
**Expectations**
- Deliver high‑quality IT risk reviews, control testing, and advisory services.
- Manage engagement lifecycle, including planning, execution, monitoring, and reporting.
- Develop and maintain risk‑control matrices and control frameworks.
- Provide consulting on IT governance, data governance, third‑party risk, asset management, and cyber security maturity.
- Support business development and proposal creation to expand market presence.
**Key Responsibilities**
1. Conduct IT risk and control assessments for audits (internal/external), advisory projects, and IT internal audit support.
2. Perform reviews of:
- Data governance, IT projects, system implementations, project assurance, IT governance, third‑party risk, asset management.
- General IT controls, security controls, cyber maturity, ISO audits, incident management.
3. Monitor technology risk standards (SOC 1, ISO 27001, NIST, etc.) and maintain relevant knowledge.
4. Develop risk and control matrices, review procedures, and provide process improvement advice.
5. Manage engagement risk, quality assurance, file reviews, planning, monitoring, and profitability.
6. Deliver client reports, technical testing results, and interview findings.
7. Engage in business development: network, build proposals, identify opportunities, and increase practice penetration.
8. Travel within Canada and internationally as required.
**Required Skills**
- Strong knowledge of IT General Controls, security controls, and audit methodologies.
- Experience designing, testing, and assessing controls in varied IT environments.
- Excellent written and oral communication; ability to present complex insights clearly.
- Self‑driven, organized, detail‑oriented, analytical.
- Ability to work independently and collaboratively within a team.
- Proficiency in managing multiple engagements of varying size and complexity.
**Required Education & Certifications**
- Bachelor’s or Master’s degree in Computer Science, Information Systems, or related field.
- Minimum 8 + years of experience in IT risk assessment or business process risk within a consulting environment.
- Relevant certifications: CISA, CRISC, CGEIT, ISO 27001 (or equivalent).