Manager, Global Cyber Security Incident Response (Global CSIRT)

KPMG International Cooperative
London, UK
8 days ago
Apply on performancemanager5.successfactors.eu
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Cyber Security Computer Engineering Security Information and Event Management Information Technology

Job description

KPMG International sets strategy, supports collaboration and protects the reputation of a global network of independent professional services firms. Within Global Digital, the Global Information Security Group provides trusted security services that support KPMG’s digital transformation and help protect the network and its clients from cyber threats.

The Global Cyber Security Incident Response Team forms part of Information Security Services and works alongside the Global Security Operations Centre to detect, investigate and support the remediation of potential threats. In this senior operational role, you will support the strategic direction, effectiveness and continued maturity of the global incident response capability. You will provide calm, credible leadership during major incidents, strengthen collaboration across member firms and deliver improvements that enhance cyber resilience and operational excellence. The role includes participation in an on-call rota and out-of-hours support for critical incidents when required.

Roles and responsibilities

  • Lead major and crisis-level cyber security incident response, ensuring clear command, timely escalation, coordinated decision-making and effective service restoration.

  • Act as deputy to the Global Cyber Security Incident Response Team Lead when required, representing the function and supporting strategic priorities and executive decisions.

  • Coordinate technical, legal, privacy, risk, communications and operational stakeholders to deliver an effective global response to complex incidents.

  • Strengthen governance, reporting and service quality so stakeholders have clear oversight of incident response performance, risks and improvement priorities.

  • Drive capability improvements through automation, orchestration, artificial intelligence-enabled investigations, tooling enhancements and modern security operations practices.

  • Build trusted relationships across KPMG member firms to improve consistency, collaboration and alignment in incident response approaches.

  • Guide and influence incident response teams in the UK and US, promoting effective practices, operational excellence and continuous learning.

  • Coach and mentor team members, support talent development and help create an inclusive, collaborative and high-performing environment.

Requirements

  • Demonstrable leadership of complex cyber security incidents, including incident command, technical investigation oversight, cross-functional coordination, crisis communications and post-incident reviews.

  • Experience leading an incident response, security operations centre or cyber defence function, with evidence of developing people and improving team capability.

  • Experience advising and working with senior stakeholders across information security, technology, legal, privacy, risk, compliance and corporate communications during major incidents.

  • Strong knowledge of cyber defence operations and incident response, including the use of endpoint detection and response, security information and event management, incident response management and case management platforms.

  • Evidence of improving security operations through governance, service improvement, automation, orchestration, tooling or artificial intelligence-enabled investigation and response.

  • Strong analytical, decision-making and stakeholder management skills, with the ability to remain composed, communicate clearly and lead with empathy under pressure.

Qualifications required

A bachelor’s degree, master’s degree or doctorate in computer science, computer engineering, information technology, cyber security or a related field, or equivalent relevant industry experience. Professional information security certifications such as CISM, CISSP, GCIA, GCIH, GREM or GCFA are desirable.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on performancemanager5.successfactors.eu
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

2:14 min

Overcoming age and background to study engineering

Anna John · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:40 min

Macro global risks shaping the future of work

Nazim Unlu Nazim Unlu · World Congress 2025

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

Videos

See all

Related articles

See all