Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Business Information Security Officer, Advisory

Full-time
Overview
At KPMG in Canada, our people bring their unique perspectives to Canada's most important challenges. Here, you can build momentum that reaches beyond our business, develop skills for the future, and take ownership of your career with support at every stage. Join a firm where your career can make a difference.

KPMG Canada is seeking an experienced professional to fulfill the role of Business Information Security Officer (BISO) - Advisory. This role reports to the Firm's Chief Information Security Officer and operates within the Advisory Business Unit, serving as the primary liaison between the central security function and the business.

This is an exciting opportunity for an individual with deep, cutting-edge experience in assessing security risks related to modern AI-enabled technology solutions and designing security guardrails to enable their safe and effective use.

Advisory at KPMG is a fast-paced environment, offering Risk and Management Consulting, Cyber Security, and Deal Advisory services to drive value and success. KPMG Canada's Digital Security Group is responsible for governing and overseeing the Firm's data and information security programme.

The BISO will collaborate with Business, Risk, Privacy, and Technology teams to assess and analyze cybersecurity risks. The individual will provide security recommendations based on identified threats and risks, while considering compliance and regulatory requirements relevant to the Business Unit. Additionally, the individual will document and track identified risks and recommendations and obtain necessary risk and security approvals where required.

The ideal candidate will demonstrate strong knowledge of modern application lifecycle practices, security architecture, cloud platforms, Generative AI tools, frontier models, API security, and application security standards such as OWASP, along with familiarity with frameworks such as ISO 42001.

What you will do
  • Serve as the primary information security liaison between the Business Unit and the Digital Security Group
  • Translate Firm security policies, procedures, and standards into practical, risk-based controls for the Business Unit technology ecosystem
  • Proactively unblock and manage security, risk, and compliance issues by bringing together Advisory, ITS, Risk, Security stakeholders, driving decisions, tracking actions, and ensuring issues are worked through to a clear and timely end state
  • Monitor compliance with KPMG security policies, standards, and control requirements; identify non-compliance, initiate remediation actions, and track exceptions through formal risk acceptance processes with appropriate compensating controls
  • Act as the BU key point of contact to understand security risks related to evolving business requirements for technology and solutions, and apply security-by-design principles to provide proactive, business-focused, guidance aligned with Firm's security policies and standards
  • In coordination with Platform Security team, assess and review business-requested software, tools, and AI capabilities (including SaaS and Generative AI solutions) for security, privacy, and compliance risks; lead intake, risk evaluation, and provide delegated approval or whitelisting where necessary
  • Collaborate with Project, Technology, Business, and Risk teams to gather requirements and support the Security Assessment Review (SAR) process, led by Platform Security
  • Develop and maintain a business unit Risk Register to track security risks
  • Coordinate with stakeholders to ensure security requirements are documented and tracked throughout the project lifecycle
Governance
  • Maintain a strong understanding of KPMG security policies (e.g., GISP, AUP, ATO), requirements, and guidance from the CISO, Risk Management Partner, and Office of the General Counsel
  • Maintain and validate a comprehensive inventory of business applications, tools, and technology assets (on-premises and cloud), ensuring alignment with Firm security standards
  • Coordinate implementation and onboarding of new security programs and capabilities as directed by the CISO
  • Contribute to annual business planning processes and recommend initiatives to enhance security posture and operational efficiency
  • Represent the business unit and provide key metrics in monthly security governance forums
Vulnerability Management and Incident Response
  • Own BU-level vulnerability management, including identification, prioritization, and remediation tracking across applications, endpoints, and cloud environments (including CSPM)
  • Partner with Technology teams to drive timely remediation of identified vulnerabilities
  • Manage responses to security incidents following KPMG's incident management processes
  • Represent the business unit in SEV1 incident response bridges
Monitoring
  • Monitor adherence to KPMG security policies and standards
  • Review compliance reports generated by security tools and address identified issues
  • Perform regular reviews of installed applications to identify prohibited software and initiate remediation actions
  • Maintain an accurate and up-to-date inventory of business applications (on-premises and cloud environments including Azure, AWS, and GCP)
  • Monitor control effectiveness across all technology assets within the business unit
What you bring to the role
  • Bachelor's or Master's degree in Information Technology, Computer Science, Cyber Security or a related field, or equivalent experience•
  • 10+ years of experience in application, technology, or solution design, architecture, development, and implementation
  • 5+ years of experience in secure design/architecture and project risk assessments across modern cloud and on-premises environments, including SaaS solutions
  • 5+ years of experience as a security practitioner in a leadership role
  • Deep understanding of modern application development ecosystems, open systems, Generative AI, and emerging technologies
  • Strong knowledge of information security standards and frameworks (e.g., CSA CCM, ISO 27001/27017/27018/42001, PCI DSS, NIST CSF, NIST 800-53) and data protection principles
  • Experience working with modern AI tools and capabilities
  • Proven experience in a consulting or advisory role, collaborating with Technology, Project, and Business stakeholders
  • Holding any of the following certifications would be considered an asset but not required: CISSP, CISA, CRISC, CISM
Providing you with the support you need to be at your best
Our Values, The KPMG Way
Integrity , we do what is right | Excellence , we never stop learning and improving | Courage , we think and act boldly | Together , we respect each other and draw strength from our differences | For Better , we do what matters

KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice.

Adjustments and accommodations throughout the recruitment process
At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. Adjustments (informal requests), such as extra preparation time or the option for micro breaks during interviews, and accommodations (formal requests), such as accessible communication supports or technology aids, are tailored to individual needs and role requirements. You will have an opportunity to request an adjustment or accommodation at any point throughout the recruitment process. If you require support, please contact KPMG's Employee Relations Service team by calling View phone number on onjobcentre.ca.

AI Usage
Weembrace the use of artificial intelligence (AI) to enhance the candidate experience and streamline our recruitment processes. AI tools may help with organizing applications or surfacing relevant qualifications. However, no hiring decisions are made using AI. Every hiring decision is made by our hiring managers and recruitment professionals, who are equipped with training that empowers them to use these tools responsibly. AI technologies used in our recruitment process undergo detailed risk assessments, including security and privacy requirements, that align with KPMG's Trusted AI framework.

We believe technology should empower human judgment, not replace it. It's one of the many ways we're delivering on our vision of being a technology-first, people-driven firm.
Vacancy posted 9 hours ago
Similar jobs that could be interesting for youBased on the Business Information Security Officer, Advisory in Toronto, ON vacancy
  •  ...Position: Business Security Consultant/ Project Security Consultant (Application Security) Client: Enterprise Canadian Banking Client Type: 6 m contract + extensions Location: 2 days a week on site downtown Toronto Rate: 55-60/hr incorporated (60 is MAX rate)... 
    Suggested
    Contract work
    2 days per week

    Insight Global

    Toronto, ON
    5 days ago
  • $102.64k - $153.96k per year

     ...Bennett Jones is one of Canada’s premier business law firms and home to 500 lawyers and...  ...transactions and litigation matters, and offices in Calgary, Edmonton, Montréal, Toronto...  ...complex legal matters. GRC Analyst, Information security The Role The information security... 
    Suggested

    Bennett Jones

    Toronto, ON
    3 days ago
  •  ...end onsite deskside support for our Toronto office and serves as a service desk escalation...  ...managed service desk partners to support business and laboratory computing environments....  ...software, and local network issues, and maintain secure system configurations as needed. Manage... 
    Suggested
    Work at office
    Local area

    Vinebrook Technology

    Toronto, ON
    12 days ago
  •  ...specialist financial and software businesses. While our roots are in...  ...in one of our international offices (such as Sydney or Toronto),...  ...Analysts to join our growing cyber security function. This role will be...  ...Go and/or Java. ~ A Cyber/Information Security related degree and/... 
    Suggested
    Worldwide
    Visa sponsorship
    Work visa
    Flexible hours

    Starling

    Toronto, ON
    12 days ago
  •  ...outputs related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios...  ...For details about the interview process and platform information, please check: For any help or support, reach out to: support... 
    Suggested
    Remote job
    Hourly pay
    Contract work
    Summer work

    Mercor

    Toronto, ON
    8 days ago
  •  ...willingness to make a difference and help protect business areas and data Nice to have Industry related certification – eg. Security+, CC certified with ISC2 Knowledge of...  ...associated applications and processes Information Technology standards, methodologies, and audit... 
    Full time
    Flexible hours

    RBC

    Toronto, ON
    8 days ago
  • $70k - $95k per year

     ...solutions across the GO Transit network. What You'll Do The Information Management Specialist will support the delivery of a portfolio...  ...specific governance frameworks. Ensure compliance with data security, confidentiality, and data retention policies across all... 
    For subcontractor

    ONxpress

    Toronto, ON
    20 days ago
  •  ...The Enforcement Officer is a frontline role responsible for ensuring safety, security, and regulatory compliance across airport,...  ...appropriately handle sensitive information and confidential materials....  ...format, creating and delivering business presentations. • Highly organized... 
    Work at office

    Toronto Port Authority

    Toronto, ON
    12 days ago
  • $100 - $105 per hour

     .... Job ID: 26-18139 Job Title: Business Architect - Senior Location: Toronto...  ...deliverables, ensuring alignment between business, information, and solution architectures, and...  ...and technical recruitment and staffing advisory organization. We are comprised of... 
    Hourly pay

    Russell Tobin

    Toronto, ON
    4 days ago
  • $66.72k - $85.32k per year

     ...day to day operations of the office including key and fob requests...  ...related to the front desk/business office. The incumbent will be...  ...and others including Campus Security. Your responsibilities will...  ...Experience using a financial information system. Experience processing... 
    Full time
    Work at office

    University of Toronto

    Toronto, ON
    3 days ago
  •  ...Toronto. The ideal candidate will have at least four years' experience working on a variety of matters including corporate tax planning, business succession, restructuring, M&A, sales/commodity tax, etc. Interested candidates should contact Travis Usher with a CV at tusher@... 

    ZSA Canada

    Toronto, ON
    8 days ago
  • $144.2k - $320.3k per year

     ...value of their data by leveraging SAP’s Business Data Cloud, Clean Core principles, and cloud...  ...Consultant, Business Data Strategy & Advisory, you’ll lead customer engagements to bring...  ..., and maintain trusted feedback loops to inform the evolution of SAP products and concepts... 
    Permanent employment
    Full time
    Local area
    Worldwide
    Flexible hours

    SAP

    Toronto, ON
    2 hours ago
  •  ...Certified SUMMARY About the Role - Security Officer As a Security Officer at Park Hyatt...  ...play a key role in maintaining a safe, secure, and welcoming environment for our guests...  ...contacted for a job opportunity, please inform the Human Resources department if you... 
    Full time
    Flexible hours
    Shift work
    Night shift

    Park Hyatt Toronto

    Toronto, ON
    1 day ago
  •  ...Summary We are seeking a Bilingual Security Officer-GRC to join Bell’s Cyber team, which enables the digital transformation of businesses and governments across Canada through solutions...  ...Subject matter expert in information security governance, risk management and... 
    Full time
    Contract work
    Work at office
    3 days per week

    Bell

    Toronto, ON
    15 days ago
  •  ...platform seeking a Chief Compliance Officer (CCO) to join its executive...  ..., and supporting continued business growth. The successful...  ...requirements and applicable securities regulations while acting as a...  ...compliance, including managed and advisory accounts Strong... 

    BJRC Recruiting

    Toronto, ON
    19 days ago
  • $69k - $129k per year

    Application Deadline: 07/29/2026 Address: 250 Yonge Street Job Family Group: Business Management Supports Operations business units including Collections and Strategic Initiatives & Enablement , each with distinct risk profiles and regulatory requirements.... 
    Full time
    Contract work
    Part time
    Toronto, ON
    5 days ago
  • $91.68k per year

     ...closely with the Associate Director and Program Manager,, the Business Officer is responsible for overseeing CANSSI ON business and...  ...forecasting, managing, and analyzing budgets and statistical information; reporting, monitoring and reconciling financial activity and... 
    Part time
    For contractors
    Work at office

    University of Toronto

    Toronto, ON
    5 days ago
  • $92.64k per year

     ...Position Title : Strategic Communications Officer Position Status: Permanent Posting...  ..., while maintaining the integrity, security, and transparency of the electoral process...  ...executive messaging, and other public-facing information that reflect EO’s mandate and uphold its... 
    Permanent employment
    Work at office

    Elections Ontario

    Toronto, ON
    5 days ago
  • $100k - $150k per year

     ...and surrounding communities. Our business success relies on strong execution and...  ...large‑scale site development. As the Security Officer, ACSO, you will support Aecon’s Chief...  ...overseeing project, site, personnel, and information security programs across assigned Aecon... 
    For subcontractor
    Local area

    AECON

    Toronto, ON
    11 days ago
  •  ...re-engineering/ lean concepts to promote business improvements through alternative, cost...  ...approaches Highly proficient using MS Office products and collaborative tools such as...  ...vendor and ministry teams · Present complex information equally well to technical and non-... 
    Long term contract
    Fixed term contract

    ThoughtStorm

    Toronto, ON
    15 days ago
  • $123.76k per year

     ...producing high-impact research that is driving the future of tech in the country. Your opportunity: The Research and Business Development Officer serves as the primary liaison between industry partners, faculty researchers, and graduate students, identifying and developing... 
    Long term contract
    Full time
    Internship
    Work at office
    Local area

    University of Toronto

    Toronto, ON
    5 days ago
  •  ...Your team’s dynamic: The Information Architecture, Intelligence & Analytics, or IAIA for...  ...operational decision-making. The goal of the Business Information Architect is to define the...  ...Establish policies for data quality, security, privacy, and lifecycle management;... 
    Full time
    Flexible hours

    Genetec

    Toronto, ON
    a month ago
  • $160k - $170k per year

     ...role:  The Director of Cybersecurity & Information Security will provide specialized expertise and...  .... The position actively interacts with business management, Legal and Compliance, Operations...  ...will report to the Chief Compliance Officer. What you'll do: ~Implementing and... 
    Work at office
    Remote work
    Flexible hours

    Financeit Inc.

    Toronto, ON
    more than 2 months ago
  •  ...with supporting Early Works. What is the Opportunity? The Security Coordinator is responsible for assisting the Security and Site...  ...Oversee the maintenance and upkeep of site facilities, including offices, restrooms, and common areas. Ensure all site facilities comply... 
    Contract work
    For subcontractor
    Work at office

    Trillium Guideway Partners

    Toronto, ON
    5 days ago
  • $45 per hour

     ...delivery. Process Mapping and Analysis - Understanding and mapping business processes to identify inefficiencies and opportunities for...  ...or new solutions. Critical Thinking - Ability to analyze information, identify issues, and make sound judgments. Stakeholder Management... 
    Hourly pay
    Full time
    Fixed term contract

    GG Tech Global Inc

    Toronto, ON
    1 day ago
  •  ...with supporting Early Works. What is the Opportunity? The Office Administrator supports the daily administrative and operational...  ...school diploma required; post-secondary education in administration, business, hospitality, or a related field is considered an asset. • 1–2... 
    Contract work
    Work at office

    Trillium Guideway Partners

    Toronto, ON
    15 days ago
  • $90k - $140k per year

     ...seeking an experienced full-time Securities Law Clerk to join their...  ...Practice Group in their Toronto office. This is an exciting...  ...occasional work outside standard business hours may be required. The first...  ...discussion and analysis, annual information forms, management information... 
    Long term contract
    Full time
    Temporary work
    Interim role
    Casual work
    Work at office
    3 days per week

    ZSA Canada

    Toronto, ON
    5 days ago
  •  ...Company: Mitrex & Cladify Position: Office Project Manager Location : 41 Racine Rd, Etobicoke. Ontario Job Type: Full-time (...  ...through innovation. Please visit Mitrex.com & Cladify.com for more information on our products and services as we look forward to connecting... 
    Full time
    For contractors
    Internship
    Work at office

    Mitrex - Building-Integrated Solar Technology

    Toronto, ON
    2 days ago
  • $101k - $169k per year

     ...opportunity. It builds consumer and business confidence, empowers...  ...and workforce analysis in an advisory context, providing strategic value...  ...Eligibility for Government of Canada security clearance  Excellent English...  .... Deloitte Canada has 20 offices with representation across... 
    Permanent employment
    Apprenticeship
    Flexible hours

    Deloitte

    Toronto, ON
    3 hours ago
  • $85k - $95k per year

     ...serving the transaction, advocacy and advisory needs of Canada’s most dynamic business sectors. We have one of the...  ...national and mid-market clients from our offices in Toronto, Vancouver and Calgary....  ...professionals to make data‑informed decisions about where the firm invests... 
    Permanent employment
    Full time
    Casual work
    Work at office

    Cassels Brock & Blackwell LLP

    Toronto, ON
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Business Information Security Officer, Advisory. Be the first to apply!