Apply Edge Start your job search

Senior Consultant - Cyber Security Governance

KPMG Sri Lanka · Colombo, Western Province, Sri Lanka

Apply & track with Apply Edge

We are looking for a Cyber Security Governance - Senior Consultant to support organizations in strengthening their information security, compliance, risk management, and resilience capabilities. The ideal candidate will have strong hands-on experience implementing internationally recognized security and governance frameworks, leading certification initiatives, and supporting compliance audits.Key ResponsibilitiesLead and support Information Security Management System (ISMS) implementations and continuous improvement initiatives.Drive ISO 27001 certification and surveillance activities from planning through successful certification.Conduct governance, risk, and compliance assessments and develop remediation roadmaps.Support SOC 2 readiness assessments, audits, and control improvement initiatives.Develop and review information security policies, standards, procedures, and governance frameworks.Facilitate enterprise risk assessments and security control evaluations.Advise clients on cyber security governance, regulatory compliance, and best practices.Deliver security awareness and governance workshops for stakeholders.Engage with senior management and provide executive-level reporting on cyber security risks and compliance posture.Mentor junior consultants and contribute to the growth of the cyber security practice.Essential RequirementsBachelor's Degree in Information Technology, Cyber Security, Computer Science, or a related field.Minimum 3 years of experience in Cyber Security Governance, Risk, and Compliance (GRC).Proven experience in implementing ISO/IEC 27001, including participation in at least two complete implementation and certification cycles.Experience supporting or leading SOC 2 audits and readiness assessments.Hands-on experience with ISO 22301 (Business Continuity Management) and ISO 27701 (Privacy Information Management) implementation and compliance programs.ISO/IEC 27001 Lead Auditor certification (mandatory).Strong understanding of NIST Cybersecurity Framework (NIST CSF) and COBIT governance principles.Experience conducting risk assessments, control reviews, and compliance gap assessments.Excellent communication, stakeholder management, and report-writing skills.Preferred QualificationsISO 22301 Lead Implementer/Auditor certification.ISO 27701 implementation experience.CISA Certification Experience within a consulting or professional services environment.Exposure to regulatory and data privacy compliance frameworks.Please use the LinkedIn Apply option if you satisfy the requirements given above.All applications will be treated with the strictest confidentiality in accordance with the guidelines of the Sri Lankan PDPA. We will correspond only with applicants shortlisted for interviews.By submitting your Curriculum Vitae (CV), you grant KPMG consent to process your personal data for recruitment purposes. This includes, but is not limited to, assessment of your suitability for the role and communication pertaining to your application. Should your application not be successful, your CV will be securely retained for a period of three months for consideration against future vacancies, after which it will be permanently deleted. You retain the right to request the deletion of your data at any time. For comprehensive information regarding data processing practices and your rights, please consult our Privacy Notice, available at: https://kpmg.com/lk/en/home/misc/privacy1.html.