Business Information Security Officer, Advisory
Full-time
Overview
At KPMG in Canada, our people bring their unique perspectives to Canada's most important challenges. Here, you can build momentum that reaches beyond our business, develop skills for the future, and take ownership of your career with support at every stage. Join a firm where your career can make a difference. KPMG Canada is seeking an experienced professional to fulfill the role of Business Information Security Officer (BISO) - Advisory. This role reports to the Firm's Chief Information Security Officer and operates within the Advisory Business Unit, serving as the primary liaison between the central security function and the business. This is an exciting opportunity for an individual with deep, cutting-edge experience in assessing security risks related to modern AI-enabled technology solutions and designing security guardrails to enable their safe and effective use. Advisory at KPMG is a fast-paced environment, offering Risk and Management Consulting, Cyber Security, and Deal Advisory services to drive value and success. KPMG Canada's Digital Security Group is responsible for governing and overseeing the Firm's data and information security programme. The BISO will collaborate with Business, Risk, Privacy, and Technology teams to assess and analyze cybersecurity risks. The individual will provide security recommendations based on identified threats and risks, while considering compliance and regulatory requirements relevant to the Business Unit. Additionally, the individual will document and track identified risks and recommendations and obtain necessary risk and security approvals where required. The ideal candidate will demonstrate strong knowledge of modern application lifecycle practices, security architecture, cloud platforms, Generative AI tools, frontier models, API security, and application security standards such as OWASP, along with familiarity with frameworks such as ISO 42001. What you will do
Our Values, The KPMG Way
Integrity , we do what is right | Excellence , we never stop learning and improving | Courage , we think and act boldly | Together , we respect each other and draw strength from our differences | For Better , we do what matters KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice. Adjustments and accommodations throughout the recruitment process
At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. Adjustments (informal requests), such as extra preparation time or the option for micro breaks during interviews, and accommodations (formal requests), such as accessible communication supports or technology aids, are tailored to individual needs and role requirements. You will have an opportunity to request an adjustment or accommodation at any point throughout the recruitment process. If you require support, please contact KPMG's Employee Relations Service team by calling View phone number on onjobcentre.ca. AI Usage
Weembrace the use of artificial intelligence (AI) to enhance the candidate experience and streamline our recruitment processes. AI tools may help with organizing applications or surfacing relevant qualifications. However, no hiring decisions are made using AI. Every hiring decision is made by our hiring managers and recruitment professionals, who are equipped with training that empowers them to use these tools responsibly. AI technologies used in our recruitment process undergo detailed risk assessments, including security and privacy requirements, that align with KPMG's Trusted AI framework. We believe technology should empower human judgment, not replace it. It's one of the many ways we're delivering on our vision of being a technology-first, people-driven firm.
At KPMG in Canada, our people bring their unique perspectives to Canada's most important challenges. Here, you can build momentum that reaches beyond our business, develop skills for the future, and take ownership of your career with support at every stage. Join a firm where your career can make a difference. KPMG Canada is seeking an experienced professional to fulfill the role of Business Information Security Officer (BISO) - Advisory. This role reports to the Firm's Chief Information Security Officer and operates within the Advisory Business Unit, serving as the primary liaison between the central security function and the business. This is an exciting opportunity for an individual with deep, cutting-edge experience in assessing security risks related to modern AI-enabled technology solutions and designing security guardrails to enable their safe and effective use. Advisory at KPMG is a fast-paced environment, offering Risk and Management Consulting, Cyber Security, and Deal Advisory services to drive value and success. KPMG Canada's Digital Security Group is responsible for governing and overseeing the Firm's data and information security programme. The BISO will collaborate with Business, Risk, Privacy, and Technology teams to assess and analyze cybersecurity risks. The individual will provide security recommendations based on identified threats and risks, while considering compliance and regulatory requirements relevant to the Business Unit. Additionally, the individual will document and track identified risks and recommendations and obtain necessary risk and security approvals where required. The ideal candidate will demonstrate strong knowledge of modern application lifecycle practices, security architecture, cloud platforms, Generative AI tools, frontier models, API security, and application security standards such as OWASP, along with familiarity with frameworks such as ISO 42001. What you will do
- Serve as the primary information security liaison between the Business Unit and the Digital Security Group
- Translate Firm security policies, procedures, and standards into practical, risk-based controls for the Business Unit technology ecosystem
- Proactively unblock and manage security, risk, and compliance issues by bringing together Advisory, ITS, Risk, Security stakeholders, driving decisions, tracking actions, and ensuring issues are worked through to a clear and timely end state
- Monitor compliance with KPMG security policies, standards, and control requirements; identify non-compliance, initiate remediation actions, and track exceptions through formal risk acceptance processes with appropriate compensating controls
- Act as the BU key point of contact to understand security risks related to evolving business requirements for technology and solutions, and apply security-by-design principles to provide proactive, business-focused, guidance aligned with Firm's security policies and standards
- In coordination with Platform Security team, assess and review business-requested software, tools, and AI capabilities (including SaaS and Generative AI solutions) for security, privacy, and compliance risks; lead intake, risk evaluation, and provide delegated approval or whitelisting where necessary
- Collaborate with Project, Technology, Business, and Risk teams to gather requirements and support the Security Assessment Review (SAR) process, led by Platform Security
- Develop and maintain a business unit Risk Register to track security risks
- Coordinate with stakeholders to ensure security requirements are documented and tracked throughout the project lifecycle
- Maintain a strong understanding of KPMG security policies (e.g., GISP, AUP, ATO), requirements, and guidance from the CISO, Risk Management Partner, and Office of the General Counsel
- Maintain and validate a comprehensive inventory of business applications, tools, and technology assets (on-premises and cloud), ensuring alignment with Firm security standards
- Coordinate implementation and onboarding of new security programs and capabilities as directed by the CISO
- Contribute to annual business planning processes and recommend initiatives to enhance security posture and operational efficiency
- Represent the business unit and provide key metrics in monthly security governance forums
- Own BU-level vulnerability management, including identification, prioritization, and remediation tracking across applications, endpoints, and cloud environments (including CSPM)
- Partner with Technology teams to drive timely remediation of identified vulnerabilities
- Manage responses to security incidents following KPMG's incident management processes
- Represent the business unit in SEV1 incident response bridges
- Monitor adherence to KPMG security policies and standards
- Review compliance reports generated by security tools and address identified issues
- Perform regular reviews of installed applications to identify prohibited software and initiate remediation actions
- Maintain an accurate and up-to-date inventory of business applications (on-premises and cloud environments including Azure, AWS, and GCP)
- Monitor control effectiveness across all technology assets within the business unit
- Bachelor's or Master's degree in Information Technology, Computer Science, Cyber Security or a related field, or equivalent experience•
- 10+ years of experience in application, technology, or solution design, architecture, development, and implementation
- 5+ years of experience in secure design/architecture and project risk assessments across modern cloud and on-premises environments, including SaaS solutions
- 5+ years of experience as a security practitioner in a leadership role
- Deep understanding of modern application development ecosystems, open systems, Generative AI, and emerging technologies
- Strong knowledge of information security standards and frameworks (e.g., CSA CCM, ISO 27001/27017/27018/42001, PCI DSS, NIST CSF, NIST 800-53) and data protection principles
- Experience working with modern AI tools and capabilities
- Proven experience in a consulting or advisory role, collaborating with Technology, Project, and Business stakeholders
- Holding any of the following certifications would be considered an asset but not required: CISSP, CISA, CRISC, CISM
Our Values, The KPMG Way
Integrity , we do what is right | Excellence , we never stop learning and improving | Courage , we think and act boldly | Together , we respect each other and draw strength from our differences | For Better , we do what matters KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice. Adjustments and accommodations throughout the recruitment process
At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. Adjustments (informal requests), such as extra preparation time or the option for micro breaks during interviews, and accommodations (formal requests), such as accessible communication supports or technology aids, are tailored to individual needs and role requirements. You will have an opportunity to request an adjustment or accommodation at any point throughout the recruitment process. If you require support, please contact KPMG's Employee Relations Service team by calling View phone number on onjobcentre.ca. AI Usage
Weembrace the use of artificial intelligence (AI) to enhance the candidate experience and streamline our recruitment processes. AI tools may help with organizing applications or surfacing relevant qualifications. However, no hiring decisions are made using AI. Every hiring decision is made by our hiring managers and recruitment professionals, who are equipped with training that empowers them to use these tools responsibly. AI technologies used in our recruitment process undergo detailed risk assessments, including security and privacy requirements, that align with KPMG's Trusted AI framework. We believe technology should empower human judgment, not replace it. It's one of the many ways we're delivering on our vision of being a technology-first, people-driven firm.
Vacancy posted 9 hours ago
Similar jobs that could be interesting for youBased on the Business Information Security Officer, Advisory in Toronto, ON vacancy
- ...Position: Business Security Consultant/ Project Security Consultant (Application Security) Client: Enterprise Canadian Banking Client Type: 6 m contract + extensions Location: 2 days a week on site downtown Toronto Rate: 55-60/hr incorporated (60 is MAX rate)...SuggestedContract work2 days per week
$102.64k - $153.96k per year
...Bennett Jones is one of Canada’s premier business law firms and home to 500 lawyers and... ...transactions and litigation matters, and offices in Calgary, Edmonton, Montréal, Toronto... ...complex legal matters. GRC Analyst, Information security The Role The information security...Suggested- ...end onsite deskside support for our Toronto office and serves as a service desk escalation... ...managed service desk partners to support business and laboratory computing environments.... ...software, and local network issues, and maintain secure system configurations as needed. Manage...SuggestedWork at officeLocal area
- ...specialist financial and software businesses. While our roots are in... ...in one of our international offices (such as Sydney or Toronto),... ...Analysts to join our growing cyber security function. This role will be... ...Go and/or Java. ~ A Cyber/Information Security related degree and/...SuggestedWorldwideVisa sponsorshipWork visaFlexible hours
- ...outputs related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios... ...For details about the interview process and platform information, please check: For any help or support, reach out to: support...SuggestedRemote jobHourly payContract workSummer work
- ...willingness to make a difference and help protect business areas and data Nice to have Industry related certification – eg. Security+, CC certified with ISC2 Knowledge of... ...associated applications and processes Information Technology standards, methodologies, and audit...Full timeFlexible hours
$70k - $95k per year
...solutions across the GO Transit network. What You'll Do The Information Management Specialist will support the delivery of a portfolio... ...specific governance frameworks. Ensure compliance with data security, confidentiality, and data retention policies across all...For subcontractor- ...The Enforcement Officer is a frontline role responsible for ensuring safety, security, and regulatory compliance across airport,... ...appropriately handle sensitive information and confidential materials.... ...format, creating and delivering business presentations. • Highly organized...Work at office
$100 - $105 per hour
.... Job ID: 26-18139 Job Title: Business Architect - Senior Location: Toronto... ...deliverables, ensuring alignment between business, information, and solution architectures, and... ...and technical recruitment and staffing advisory organization. We are comprised of...Hourly pay$66.72k - $85.32k per year
...day to day operations of the office including key and fob requests... ...related to the front desk/business office. The incumbent will be... ...and others including Campus Security. Your responsibilities will... ...Experience using a financial information system. Experience processing...Full timeWork at office- ...Toronto. The ideal candidate will have at least four years' experience working on a variety of matters including corporate tax planning, business succession, restructuring, M&A, sales/commodity tax, etc. Interested candidates should contact Travis Usher with a CV at tusher@...
$144.2k - $320.3k per year
...value of their data by leveraging SAP’s Business Data Cloud, Clean Core principles, and cloud... ...Consultant, Business Data Strategy & Advisory, you’ll lead customer engagements to bring... ..., and maintain trusted feedback loops to inform the evolution of SAP products and concepts...Permanent employmentFull timeLocal areaWorldwideFlexible hours- ...Certified SUMMARY About the Role - Security Officer As a Security Officer at Park Hyatt... ...play a key role in maintaining a safe, secure, and welcoming environment for our guests... ...contacted for a job opportunity, please inform the Human Resources department if you...Full timeFlexible hoursShift workNight shift
- ...Summary We are seeking a Bilingual Security Officer-GRC to join Bell’s Cyber team, which enables the digital transformation of businesses and governments across Canada through solutions... ...Subject matter expert in information security governance, risk management and...Full timeContract workWork at office3 days per week
- ...platform seeking a Chief Compliance Officer (CCO) to join its executive... ..., and supporting continued business growth. The successful... ...requirements and applicable securities regulations while acting as a... ...compliance, including managed and advisory accounts Strong...
$69k - $129k per year
Application Deadline: 07/29/2026 Address: 250 Yonge Street Job Family Group: Business Management Supports Operations business units including Collections and Strategic Initiatives & Enablement , each with distinct risk profiles and regulatory requirements....Full timeContract workPart time$91.68k per year
...closely with the Associate Director and Program Manager,, the Business Officer is responsible for overseeing CANSSI ON business and... ...forecasting, managing, and analyzing budgets and statistical information; reporting, monitoring and reconciling financial activity and...Part timeFor contractorsWork at office$92.64k per year
...Position Title : Strategic Communications Officer Position Status: Permanent Posting... ..., while maintaining the integrity, security, and transparency of the electoral process... ...executive messaging, and other public-facing information that reflect EO’s mandate and uphold its...Permanent employmentWork at office$100k - $150k per year
...and surrounding communities. Our business success relies on strong execution and... ...large‑scale site development. As the Security Officer, ACSO, you will support Aecon’s Chief... ...overseeing project, site, personnel, and information security programs across assigned Aecon...For subcontractorLocal area- ...re-engineering/ lean concepts to promote business improvements through alternative, cost... ...approaches Highly proficient using MS Office products and collaborative tools such as... ...vendor and ministry teams · Present complex information equally well to technical and non-...Long term contractFixed term contract
$123.76k per year
...producing high-impact research that is driving the future of tech in the country. Your opportunity: The Research and Business Development Officer serves as the primary liaison between industry partners, faculty researchers, and graduate students, identifying and developing...Long term contractFull timeInternshipWork at officeLocal area- ...Your team’s dynamic: The Information Architecture, Intelligence & Analytics, or IAIA for... ...operational decision-making. The goal of the Business Information Architect is to define the... ...Establish policies for data quality, security, privacy, and lifecycle management;...Full timeFlexible hours
$160k - $170k per year
...role: The Director of Cybersecurity & Information Security will provide specialized expertise and... .... The position actively interacts with business management, Legal and Compliance, Operations... ...will report to the Chief Compliance Officer. What you'll do: ~Implementing and...Work at officeRemote workFlexible hours- ...with supporting Early Works. What is the Opportunity? The Security Coordinator is responsible for assisting the Security and Site... ...Oversee the maintenance and upkeep of site facilities, including offices, restrooms, and common areas. Ensure all site facilities comply...Contract workFor subcontractorWork at office
$45 per hour
...delivery. Process Mapping and Analysis - Understanding and mapping business processes to identify inefficiencies and opportunities for... ...or new solutions. Critical Thinking - Ability to analyze information, identify issues, and make sound judgments. Stakeholder Management...Hourly payFull timeFixed term contract- ...with supporting Early Works. What is the Opportunity? The Office Administrator supports the daily administrative and operational... ...school diploma required; post-secondary education in administration, business, hospitality, or a related field is considered an asset. • 1–2...Contract workWork at office
$90k - $140k per year
...seeking an experienced full-time Securities Law Clerk to join their... ...Practice Group in their Toronto office. This is an exciting... ...occasional work outside standard business hours may be required. The first... ...discussion and analysis, annual information forms, management information...Long term contractFull timeTemporary workInterim roleCasual workWork at office3 days per week- ...Company: Mitrex & Cladify Position: Office Project Manager Location : 41 Racine Rd, Etobicoke. Ontario Job Type: Full-time (... ...through innovation. Please visit Mitrex.com & Cladify.com for more information on our products and services as we look forward to connecting...Full timeFor contractorsInternshipWork at office
$101k - $169k per year
...opportunity. It builds consumer and business confidence, empowers... ...and workforce analysis in an advisory context, providing strategic value... ...Eligibility for Government of Canada security clearance Excellent English... .... Deloitte Canada has 20 offices with representation across...Permanent employmentApprenticeshipFlexible hours$85k - $95k per year
...serving the transaction, advocacy and advisory needs of Canada’s most dynamic business sectors. We have one of the... ...national and mid-market clients from our offices in Toronto, Vancouver and Calgary.... ...professionals to make data‑informed decisions about where the firm invests...Permanent employmentFull timeCasual workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Business Information Security Officer, Advisory. Be the first to apply!
Related searches
- ciso Toronto, ON
- chief information security officer ciso Toronto, ON
- business valuation Toronto, ON
- business sales Toronto, ON
- remote business Toronto, ON
- business marketing Toronto, ON
- pega business architect Toronto, ON
- business analysis Toronto, ON
- entry level business Toronto, ON
- sport business Toronto, ON
