
Consultant - Technology Risk Services
- Winnipeg, MB
- Permanent
- Temps-plein
What you will doWe are looking for a highly motivated Technology Risk Consulting professional at a Consultant level to join our team in Regina. As a member of KPMG Canada’s cross-functional Technology Risk Consulting team, you will be dedicated to enabling our clients' cyber transformation journey through service delivery leadership, advisory, and support.As a Consultant, you’ll work as part of a team of problem solvers with extensive consulting and industry experience, helping our clients solve their complex business issues from strategy to execution. Specific responsibilities include but are not limited to:
- Support key services including general/application control audits/assessments, compliance with SOC 1 / SOC 2 / SOC 3 audits of controls, Cybersecurity/Technology Risk, IT infrastructure security reviews, project governance reviews and ISO assessments
- Review new and existing systems in terms of adequacy of controls, security, operational considerations, conversion issues and project management assessment
- Provide advice and assistance on business process controls
- Participate in field engagement teams and contribute to coaching and mentoring junior staff
- Maintain sharing of knowledge through tool development, template enhancements and methodology enhancements
- Identify and implement improvements in existing processes and procedures
- Evaluate the risks and the adequacy of controls associated with IT applications, operating systems, databases, interfaces, business cycle controls
- Interact with various clients to understand their environments' needs
- Completion of one or a combination of the following designations is an asset: CPA, CISA, CISSP, CRISC, CISM
- A post-secondary degree is required
- 1–3 years of relevant experience in assessing information technology or business process risk, ideally within a large consulting practice
- Strong understanding and experience with business process controls, IT General controls (ITGCs), controls-based audits/assessment (e.g. CSAE 3416, CSAE 3000, SSAE 18) is required
- Experience testing of controls in different IT environments
- Experience with AWS, Azure, other leading cloud providers
- Good understanding of Industry standards and frameworks such as COBIT, ISO 27001, 27002, NIST, COSO
- Experience with developing client relationships, general project management, team collaboration