Senior Security Engineer

Sofia, Bulgaria (Hybrid)

The world of global advisory, audit and tax compliance services for large multi-nationals is rapidly changing and heavily dependent on technology.    

The KPMG Delivery Network (KDN) is a KPMG special purpose member firm offering a way for clients to leverage KPMG top talent and technology platforms through regional teams of specialists, enabling economies of scale and a new way of working that expands beyond local capability

Together with KDN, KPMG member firms can drive the sales and delivery of global solutions at a competitive price and in a repeatable and consistent manner. As a member of KDN, you’ll be a part of the KPMG family working alongside some of our profession’s most skilled practitioners on rewarding programs and initiatives that are changing the way business operates, delivering value to our clients, and driving positive change in the communities we serve.

You’ll be enabling KDN accelerate new ways of working, using cutting-edge technology and working together with our member firms located in nearly 150 countries to help us achieve our ambition to be the most trusted and trustworthy professional services firm. 

And through your work, you’ll build a global network and unlock opportunities that you may not have thought possible with access to great support, vast resources, and an inclusive, supportive environment to help you reach your full potential.

Our KDN Bulgaria Cloud Services Unit is focused on designing, building, securing and managing cloud native & hybrid platforms for the KPMG group of member firms, as well as providing cloud advisory and engineering services to external clients.

Your Responsibilities: 

  • Provide daily operational oversight of Incident Response & Investigations Team (IRIT) in relation to technical incidents for the more junior members of the team.
  • Play a leading role in the management of P1 and P2 Security Incident investigation, including identifying key enquiries and allocating IRIT resources.
  • Support the development of IR&I team members.
  • Lead Post Incident Reviews into KPMG UK Security Incidents; sharing IR&I team findings and outputs with key stakeholders.
  • Maximise the effectiveness of the IRIT in the preventing, identifying, and managing of Security Incidents by continual liaison with Monitoring and CTI teams.
  • Ensure Incident Response Investigation procedures and documentation are up to date, maintained and followed (process documentation, playbooks, standard operating procedures, etc).
  • Be responsible for building and maintaining strong relationships with key stakeholders, such as Information Security leadership, Business Information Security Officer's and Engagement/Capability Leads.
  • Work closely with the Global SOC to share information and manage globally identified incidents.
  • Provide tailored approach to investigations involving a range of stakeholders by proportionately applying security capabilities in response to identified risks.
  • Act as an SME for complex information security incident response concerns, issues and problems.
  • Be responsible for collaborating with any designated direct staff to ensure performance objectives, career path options, and work assignments are all clearly documented, understood and reviewed.
  • Stay informed about the latest cyber security trends, threats, and technologies to continuously enhance the firm's security posture.

What you bring in:

  • Substantial hands-on experience in Information Security Incident Response and Investigation.
  • Substantial experience leading and supervising serious and complex investigations.
  • Strong experience of managing investigative teams.
  • Experience leading teams in high pressured environments.
  • Strong experience of investigative techniques and evidence gathering.
  • Experience in managing and responding to complex security incidents and data breaches.
  • Robust understanding of security issues, mitigations, and a strong understanding of the current global threat environment.
  • Good understanding of cyber security regulations, standards, and best practices.
  • Experience working in a highly regulated industry such as finance, healthcare, or energy is a plus.
  • Strong analytical and problem-solving skills, with the ability to assess and mitigate risks effectively.
  • Good communication and interpersonal skills, with the ability to work collaboratively with diverse stakeholders.
  • High level of integrity and professionalism, with a commitment to ethical conduct and confidentiality.
  • Ability to stay calm and focused under pressure, especially during security incidents and emergencies in the face of ambiguity and imperfect knowledge.
  • Relevant certifications such as CISSP, CISM, or CEH are highly desirable.
  • Fluent English lanugage skills is a must

What we offer:

  • The chance to work in a top talent team
  • Attractive remuneration
  • Build knowledge in cutting-edge technologies
  • Opportunity for continuous training, learning and certification
  • Experience in an international and multicultural organization
  • Work on challenging projects with clients in various industries around the globe
  • Modern office environment
  • Additional health insurance
  • Life insurance
  • 50+ benefits and services to choose from
  • Hybrid working policy

Senior Security Engineer

Job description

Senior Security Engineer

Personal information
Details