Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

Location: 

London

Category:  KPMGI
Business Unit: 

About the role 

 

KPMG International sets strategy, supports collaboration and protects the reputation of a global network of independent professional services firms. Within Global Digital, the Global Information Security Group provides trusted security services that support KPMG’s digital transformation and help protect the network and its clients from cyber threats. 

The Global Cyber Security Incident Response Team forms part of Information Security Services and works alongside the Global Security Operations Centre to detect, investigate and support the remediation of potential threats. In this senior operational role, you will support the strategic direction, effectiveness and continued maturity of the global incident response capability. You will provide calm, credible leadership during major incidents, strengthen collaboration across member firms and deliver improvements that enhance cyber resilience and operational excellence. The role includes participation in an on-call rota and out-of-hours support for critical incidents when required. 

 

Roles and responsibilities 

 

• Lead major and crisis-level cyber security incident response, ensuring clear command, timely escalation, coordinated decision-making and effective service restoration. 

• Act as deputy to the Global Cyber Security Incident Response Team Lead when required, representing the function and supporting strategic priorities and executive decisions. 

• Coordinate technical, legal, privacy, risk, communications and operational stakeholders to deliver an effective global response to complex incidents. 

• Strengthen governance, reporting and service quality so stakeholders have clear oversight of incident response performance, risks and improvement priorities. 

• Drive capability improvements through automation, orchestration, artificial intelligence-enabled investigations, tooling enhancements and modern security operations practices. 

• Build trusted relationships across KPMG member firms to improve consistency, collaboration and alignment in incident response approaches. 

• Guide and influence incident response teams in the UK and US, promoting effective practices, operational excellence and continuous learning. 

• Coach and mentor team members, support talent development and help create an inclusive, collaborative and high-performing environment. 

 

Experience and skills needed 

 

• Demonstrable leadership of complex cyber security incidents, including incident command, technical investigation oversight, cross-functional coordination, crisis communications and post-incident reviews. 

• Experience leading an incident response, security operations centre or cyber defence function, with evidence of developing people and improving team capability. 

• Experience advising and working with senior stakeholders across information security, technology, legal, privacy, risk, compliance and corporate communications during major incidents. 

• Strong knowledge of cyber defence operations and incident response, including the use of endpoint detection and response, security information and event management, incident response management and case management platforms. 

• Evidence of improving security operations through governance, service improvement, automation, orchestration, tooling or artificial intelligence-enabled investigation and response. 

• Strong analytical, decision-making and stakeholder management skills, with the ability to remain composed, communicate clearly and lead with empathy under pressure. 

 

Qualifications required 

 

A bachelor’s degree, master’s degree or doctorate in computer science, computer engineering, information technology, cyber security or a related field, or equivalent relevant industry experience. Professional information security certifications such as CISM, CISSP, GCIA, GCIH, GREM or GCFA are desirable.