> Markdown version of [/jobs/ext/169866-director-kdn-national-it-security-officer-nitso](https://www.wearedevelopers.com/jobs/ext/169866-director-kdn-national-it-security-officer-nitso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director - KDN National IT Security Officer (NITSO) - **Company:** Kpmg LLP - **Location:** San Diego, CA, United States - **Experience:** Expert - **Salary:** $171,000.0 - $311,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management, Virtual Private Networks (VPN), Systems Development Life Cycle, Remote Access Technology, Software Engineering, Utility Software, Operational Systems, Devsecops, Security Orchestration, Automation & Response - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=032f0c45f5766231 ## About the Role Do you have experience in Risk management?, Do you have a Bachelor's degree?, * Minimum ten years of recent experience in information security and risk management, with industry-standard accreditations or certifications (e.g. CISSP, CISM, ISO 27001), and solid understanding of relevant information security frameworks and attestations (e.g. ISO 27001, NIST, SOC 2, SoQM) * Bachelor's degree from an accredited college or university preferred or ten years relevant work experience in a professional services/risk environment * Strong knowledge of current data privacy regulations, including GDPR, and demonstrated understanding and experience with secure software development practices, including Secure SDLC, DevSecOps, and/or security automation. * Proven ability to understand and clearly communicate the business impact of information security operations on the organization, balancing security requirements with business needs and operational constraints, and providing pragmatic, risk-based recommendations * Strong strategic thinking and decision-making skills, with advanced problem-solving and analytical capabilities, including the ability to assess complex security issues, interpret risk, and propose effective mitigation strategies * Demonstrated project and program management capabilities, including planning, prioritizing, and delivering multiple security initiatives in parallel, coordinating across stakeholders and functions, and monitoring progress against objectives * High level of resilience and ability to perform under pressure, particularly when managing security incidents or time-critical issues, with strong communication and stakeholder management skills to ensure effective coordination and escalation when required * Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa) ## Description * Lead the Information Security Organization and oversee the direction, evolution, and budgeting of the information security program, ensuring alignment with Global information security priorities and strategy; act as the primary point of contact for the Global Information Security Group (GISG), GQRM - Global Digital Risk (GDR), and participate in regular Global meetings, forums, and NITSO induction sessions as required * Provide leadership insight and escalation on information security matters, promoting adherence to KPMG information protection policies and other relevant policies (e.g. the Global Quality & Risk Management Manual); ensure appropriate Information Security Incident Management planning, preparation, implementation, and communication across KDN * Establish and maintain strong relationships with NITSOs from KPMG network firm locations from which KDN delivery centers operate, and liaise with key stakeholders including Business Functions, Technology Groups, Legal, Privacy (Privacy Liaison), Physical Security, Human Resources, and the global insurance team to support the annual cyber insurance program and other global requirements * Oversee the information security risk assessment process, including tools and solutions used, and facilitate risk treatment; assess third-party risks (initial and ongoing) for suppliers and acquisitions, evaluate information security provisions for working with other member firms (e.g. IFDTAs and other regulatory provisions), and provide input into all information security-related escalations * Ensure the creation, maintenance, and reporting of information security metrics, and drive the regular (at least annual) review of all security policies and standards, including their implementation; ensure that changes to global information security policies and standards are communicated to relevant stakeholders and appropriately reflected in documented policies, processes, and procedures; ensure a senior sponsor is established for IPCR, that IPCR is carried out in a timely manner, and remediation activities are completed within agreed timelines * Advise the business on security requirements for new systems and technologies, including review of technology projects and approval of significant changes to technology environments (e.g. communication tools, VDI, remote access including VPN, external-facing solutions, installation of software on operational systems, and privileged utility programs); work closely with technology teams to ensure consistent implementation and review of security controls across the organization, contribute to the documentation and coordination of ISO 27001 processes (where applicable), and ensure that all KDN personnel receive information protection and data privacy training, as applicable * Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [RPA crash course for .Net developers – intro into the world of RPA from the perspective of a .Net developer](https://www.wearedevelopers.com/videos/271-rpa-crash-course-for-net-developers-intro-into-the-world-of-rpa-from-the-perspective-of-a-net-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)