logo

Information Security Senior Specialist

Astana/Almaty · Central Services, Quality Risk Management
Apply

We’re currently seeking an Information Security Senior Specialist to join our Quality Risk Management (QRM) team. In this role, you will work on projects across the CASA region, covering 11 countries, performing information security and technology risk assessments, reviewing technology solutions and processes, identifying security risks, and working with technical and business teams to ensure appropriate security controls are considered and implemented.

Responsibilities

  • Perform security reviews and assessments of technology solutions, applications, cloud services, infrastructure, and third-party services.
  • Support technology, architecture, and solution reviews to identify and manage security risks.
  • Conduct information security and technology risk assessments.
  • Review security requirements throughout the Software Development Life Cycle (SDLC) and technology change processes.
  • Support vendor, supplier, client, and contractual security reviews.
  • Support client security questionnaires, audits, and assurance requests.
  • Review emerging technologies, including Artificial Intelligence (AI) solutions, from a security and risk perspective.
  • Prepare security assessment reports and recommendations.
  • Monitor remediation activities and follow up on identified risks.
  • Collaborate with Technology, Risk, Procurement, Privacy, Legal, and business teams.
  • Contribute to the continuous improvement of information security processes and practices.

Requirements

  • Have 3–5+ years of professional experience in Information Security, Cybersecurity, IT, or a related discipline.
  • Hold a Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related discipline.
  • Are fluent in English, both written and spoken.
  • Have a good understanding of information security principles and technology risks.
  • Have knowledge of the Software Development Life Cycle (SDLC).
  • Have a basic understanding of cloud and enterprise technologies, infrastructure, networking, operating systems, and databases.
  • Understand Identity and Access Management (IAM) concepts, application security, and security requirements throughout the SDLC.
  • Have a basic understanding of vulnerability management, security testing, and third-party risk management.
  • Are familiar with Artificial Intelligence (AI) security and governance concepts.
  • Have knowledge of information security frameworks and standards such as ISO 27001, NIST, or CIS.
  • Are proactive, collaborative, and able to work independently as part of a regional team.

Conditions

  • Continuous Learning
    Grow professionally with internal and external training programs, certifications, and opportunities to develop both soft and hard skills.
  • Bravo Recognition Program
    Be recognized for your outstanding contributions with the Bravo program, rewarding exceptional dedication and commitment to the firm.
  • Health & Life Insurance
    Get access to top-tier medical services and life insurance, ensuring stability and security.
  • Annual Bonuses
    Earn performance-based bonuses that reward your individual achievements and contributions to the company’s success.
  • Exclusive Discounts
    Take advantage of special discounts to stay active, comfortable, and enjoy great deals on various services.
  • Extended Vacation
    Take advantage of 30 days off annually, including 5 additional sick leave days, ensuring you have time to rest and recharge.
Share this job opening

Application:

I agree to the processing of my personal data in accordance with the KPMG Caucasus and Central Asia Privacy Policy