Senior Consultant Technology Assurance Cyber Security
Technology and cybersecurity are increasingly important for the continuity, resilience, and reliability of organizations. At KPMG, you help clients understand and manage cyber risks. You also assess whether their governance, processes, and controls form a reliable basis for decision-making, compliance with laws and regulations, and external assurance. Within Technology Assurance, you develop specialist expertise at the intersection of cybersecurity, risk management, audit, and assurance. You contribute to engagements in the fields of financial statement audits, cyber advisory, and independent assurance, in collaboration with colleagues from IT Audit, Financial Audit, and Cyber Security. You can count on structured coaching, funded professional qualifications, and opportunities to develop both your technical expertise and your leadership skills towards clients. Together, we help organizations translate complex cyber risks into practical improvements and greater trust in technology.
As a Senior Consultant Technology Assurance with a focus on Cyber Security, you help clients improve the reliability and security of their technological environments. You assess how organizations manage cyber risks within, among other things, cloud platforms and AI solutions. You combine a solid foundation in IT audit and cyber risk management with an interest in emerging technologies. In this way, you offer practical insights that enable clients to strengthen their controls, comply with legal requirements, and make better-informed decisions. You share your findings through presentations, workshops, and clear, actionable recommendations. You contribute to the growth ambition of our team. By working with international organizations and medium-sized clients, you will encounter diverse challenges and develop your expertise. You will have the opportunity to: Assess cyber governance, risk management, and control environments based on recognized frameworks, such as the NIST Cybersecurity Framework and ISO/IEC 27001. Evaluate clients' cyber risk assessments, detection and response capabilities, operational resilience, third-party dependencies, and security governance. Support Financial Audit teams in assessing the potential relevance of cyber risks and cyber incidents to business continuity, financial reporting, and the risk of material misstatement. Perform cyber maturity analyses and assess the design and implementation of cybersecurity measures. Assess the extent to which organizations are prepared for cyber-related laws and regulations, including NIS2, DORA, and the Cyber Resilience Act. Translate technical and regulatory findings into clear, proportionate, and actionable recommendations for management, audit committees, and other senior stakeholders. Contribute to cyber assurance engagements that provide independent conclusions on controls, compliance with laws and regulations, resilience, third-party risks, and management assertions. Work closely with specialists from Cyber Security, IT Audit, and Financial Audit to provide clients with the right combination of audit, assurance, and technical expertise. Coach junior colleagues and review their work, so they can further develop their skills in the field of cybersecurity and assurance. Contribute to the development of cyber propositions, methodologies, templates, training materials, and thought leadership. Support market development by identifying client needs, contributing to proposals, and building long-term client relationships. “Cyber is increasingly touching the core of an organization. In this role, you help clients translate complex cyber risks into what they concretely mean for their operational resilience, governance, and risk management. It is precisely the combination of cyber knowledge, audit skills, and a broad view of the organization that makes the work within ITA challenging and relevant.”
Dirk Jan, Senior Manager Technology Assurance
A bachelor's or master's degree in Information Security, Cyber Security, Information Management, IT Audit, Computer Science, Business Administration, or a similar field. At least 3 years of relevant experience in cybersecurity, IT or cyber risk, IT audit or internal audit, technology risk, or assurance. Experience with cybersecurity frameworks and standards, preferably the NIST Cybersecurity Framework and ISO/IEC 27001, and familiarity with relevant regulations such as NIS2, DORA, or the Cyber Resilience Act. Practical knowledge of cyber domains, such as governance and risk management, security controls, incident management, operational resilience, cloud security, IAM, data security/privacy, and third-party risks. Experience in performing risk or maturity analyses, control reviews, or assurance engagements, including assessing underlying documentation and evidence. The ability to translate technical cybersecurity topics into business risks, legal requirements, audit objectives, and practical recommendations. Strong skills in reporting, presenting, and stakeholder management, with the ability to engage both business and technological stakeholders. Excellent oral and written command of English. Good communicative skills in Dutch are a plus due to contact with Dutch-speaking clients. A proactive and collaborative working attitude, with the ability to take responsibility and coach less experienced colleagues. Preferably a relevant professional certification, or the willingness to work towards one, such as CISA, RE, CISM, CISSP, ISO/IEC 27001 Lead Auditor/Implementer, or ISC2. Equivalent practical experience in cybersecurity will also be considered.
Gross monthly salary between € 3,965 and € 4,500 depending on your work experience, variable performance bonus, a fixed expense allowance, and a fixed home office allowance per worked day. A flexible pension without mandatory personal contribution. 30 vacation days (on a full-time basis) and the possibility to buy more days or sell your vacation days. At KPMG, we work hybrid, so a combination of working from home, at the client, and at the office. A fully equipped home office workspace. A lease car with an NS business card or a mobility scheme. A laptop and iPhone. An extensive range of training and education that contributes to your professional and personal development. Diversity networks regarding pride, gender, ability, cultural diversity, and generations that regularly organize various activities to celebrate difference! Attention to vitality! Exercise at the office in Amstelveen or a discount at a gym near you, as well as access to coaching, health, and vitality programs. ‘Together’ is one of our core values. Therefore, you can count on various social activities such as team outings, drinks, and events together with your colleagues. </body>