KPMG Nederland logo

Information Security Advisor (Governance Risk and Compliance)

KPMG Nederland

Amstelveen
Full-time
2-5 years experience
Hybrid

€3,700 - €4,400 per month

Key Skills

Information security
Risk assessment
Governance
Compliance
ISO 27001
NIST
Stakeholder management
Cloud security
Third-party risk management
Audit coordination
Security controls
Data privacy
Cyber security
Policy development
Vulnerability management

Job Description

Company Description

Ready to help safeguard KPMG's digital services in a rapidly evolving technology landscape? As an information security advisor in Amstelveen, you'll work with cloud technologies, AI-enabled solutions, and external suppliers to strengthen security, manage risk, and help maintain the trust our clients place in KPMG.

Job Description

  • Lead information security risk assessments for applications, infrastructure and third-party suppliers.
  • Advise product owners and stakeholders on security controls, risk mitigation and compliance requirements.
  • Review and improve information security policies, standards and control frameworks.
  • Coordinate internal and external audit activities and support the timely resolution of findings.
  • Evaluate security exceptions and monitor the effectiveness of implemented controls.

 

As an Information Security Advisor, you will be part of KPMG's IT Security Governance, Risk & Compliance (GRC) team. Together with colleagues across Technology, Risk, Privacy and Procurement, you help ensure that security is embedded in everything we do.

You will advise on security risks related to both internally managed systems and externally sourced technology services. This includes conducting risk assessments, reviewing security controls, and helping teams implement improvements that align with KPMG's security standards and industry frameworks such as ISO 27001 and NIST.

A significant part of the role involves partnering with application owners, project teams and suppliers. You challenge where necessary, identify potential vulnerabilities, and help stakeholders make informed decisions that balance security, business objectives and regulatory requirements.

You will also contribute to audit preparation and remediation activities, evaluate security exception requests, and support continuous improvement initiatives across the organisation. This gives you a broad view of KPMG's technology landscape and the opportunity to influence how security is integrated into modern cloud, AI and digital services.

In this role, you will combine technical understanding with strong stakeholder management skills, helping colleagues across the business navigate increasingly complex security and risk challenges

 

Qualifications

  • Bachelor's or master's degree in Information Security, Cyber Security, IT, Risk Management or a related field.
  • Experience with information security frameworks such as ISO 27001, NIST or SOC 2.
  • Experience conducting information security or IT risk assessments.
  • Experience engaging with business stakeholders and translating security requirements into practical solutions.
  • Strong command of English and Dutch, as you will work with local and international internal stakeholders, documentation and suppliers.

Nice to have

  • CISSP, CISM or CISA certification.
  • Experience with supplier security assessments and third-party risk management.
  • Knowledge of data privacy and cloud security.

Additional Information

  • Gross salary between €3,700  and €4,400  per month depending on your work experience, variable performance based reward, a fixed expense allowance and a  fixed working from home allowance per working day.
  • Pension accrual without a compulsory personal contribution.
  • 30 vacation days (on a full-time basis) and the option to buy more days or sell your vacation days.
  • At KPMG we work hybrid, so you can work from home, from the client or at the office.
  • A completely furnished home office.
  • Reimbursement of your travel expenses with a NS business card or travel allowance.
  • A laptop and iPhones.
  • Choice to pick from different courses which contribute to your own personal and professional development.
  • Diversity networks in the areas of pride, gender, ability, cultural diversity, and generations that regularly organize various activities to celebrate differences!
  • Focus on well-being! There is a gym at the Amstelveen office or you can get a discount for a gym near your house and you get access to different health and/or vitality programs.
  • ‘Together’ is one of our core values. So you can count on different social activities, like team events, drinks with colleagues and events with all your KPMG colleagues.
  • Compensation: EUR 3770 - EUR 4400 - monthly
  • Core Responsibilities

    Lead information security risk assessments for infrastructure, applications, and third-party suppliers while advising stakeholders on risk mitigation and compliance. Coordinate internal and external audit activities and ensure security standards are integrated into modern cloud and AI-enabled services.

    Requirements

    Requires a bachelor's or master's degree in Information Security, IT, or a related field along with experience in security frameworks like ISO 27001 or NIST. Candidates must possess strong stakeholder management skills and proficiency in both English and Dutch.

    Benefits

    • Variable performance based reward
    • Fixed expense allowance
    • Fixed working from home allowance
    • Pension accrual
    • 30 vacation days
    • Hybrid work model
    • Furnished home office
    • Travel expense reimbursement
    • Laptop
    • iPhone
    • Professional development courses
    • Diversity networks
    • Gym access
    • Health and vitality programs
    • Team events

    About KPMG Nederland

    Industry: Financial Services

    Company size: 1,001-5,000 employees

    KPMG Nederland levert hoogwaardige dienstverlening op het gebied van audit, tax en advisory. We werken voor een brede groep opdrachtgevers: grote (inter)nationale ondernemingen, middelgrote bedrijven, non-profitorganisaties en overheden. De ingewikkelde problematiek van onze cliënten vraagt om een multidisciplinaire aanpak die helpt orde te scheppen in de complexiteit. Onze professionals blinken uit in hun eigen specialisme, maar werken tegelijkertijd nauw samen om zo de toegevoegde waarde te bieden die onze cliënten helpt om te excelleren. Daarbij putten we uit een rijke bron van kennis en ervaring, opgedaan in uiteenlopende organisaties en markten.

    Added Today