About the role
AI summarisedThis is a cybersecurity consulting role at KPMG, focusing on Operational Technology (OT) and Industrial Internet of Things (IIoT) security for clients in critical infrastructure sectors. The associate will perform risk assessments, threat modelling, and security reviews for industrial control systems, working closely with clients and subject matter experts.
BusinessFull-timeGeneral
Key Responsibilities
- Performing risk assessment or threat modelling for variety of industry control system, on-prem IT and cloud systems.
- Digesting sizable amounts of information about complex systems by using your technical grounding in IT, OT/IIoT, engineering or cloud computing (e.g network architecture, firewall rules and etc) to assemble an accurate understanding of the system.
- Analysing and identifying the cybersecurity risks associated to them e.g. how an attack might get into a network and cause disruption to operations or cause a dangerous situation in which safety might be compromised.
- Work closely with our clients in gathering information, providing clarification, and managing expectations on the task we are required to perform.
- Providing security recommendations and improvement to the client in the current practices while considering impact to their operations and concerns.
- Performing other assessment/review for clients including system/network architecture reviews and reviewing actual practices in OT/IT systems against regulatory requirements e.g. the Cybersecurity Code of Practice (CCOP) for critical information infrastructure.
- Working in a project team and closely guided by the experience team member.
- Working closely with subject matter experts in a wide range of cyber security services to delivered to our clients (e.g. managing projects involving penetration testing or red teaming exercises to an owner/operator of a critical infrastructure).
Requirements
- Bachelor's degree in Cybersecurity/ Information Security/ Engineering/ Computer Science OR Information Technology equivalent.
- Experienced or keen interest in OT/IIoT;
- Certifications in cybersecurity e.g. OSCP, CISA, CRISC, CISSP, CISM etc might be advantageous.
- Certifications in OT cybersecurity e.g. GICSP, GRID, IEC62443 might be advantageous.
- Committed to continuously learn and develop oneself in a fast-expanding field.
- Aptitude of consulting including managing oneself, projects and clients.
- Able to think logically and communicate clearly.
- Effective interpersonal skills and able to work well in a team.
- Good presentation skills might be advantageous.