Responsibilities:- Assist in the design, engineering, and implementation of Zero Trust architectures (ZTA) across enterprise environments, ensuring alignment with CISA Zero Trust Maturity Models and federal mandates
- Collaborate with senior architects to integrate security controls into systems design, evaluating new tools / technologies to support a comprehensive defense-in-depth strategy
- Integrate security controls into the software development lifecycle (DevSecOps), perform application vulnerability assessments, and establish secure application onboarding processes for enterprise environments
- Support secure cloud migration initiatives, ensuring on-premise infrastructures and applications are safely transitioned to cloud environments (AWS, Azure, GCP) without compromising security postures or compliance requirements
- Implement / manage robust identity solutions, focusing on Identity, Credential, and Access Management (ICAM), Multi-Factor Authentication (MFA), and least-privilege access frameworks
- Ensure all security architectures and implementations comply with federal frameworks / standards, including NIST SP 800-53, NIST SP 800-207, Risk Management Framework (RMF), and Dod Cloud Computing Security Requirements Guide (SRG)
- Develop and tune use cases for Security Information and Event Management (SIEM) platforms and automate incident response workflows using Security Orchestration, Automation, and Response (SOAR) tools
- Monitor enterprise environments for anomalous activity, analyze security alerts, and assist in incident remediation efforts
Qualifications:- A minimum of eight years of cyber security engineering / solutions architecture experience; U.S. Federal government consulting experience preferred
- Bachelor's degree from an accredited college/university
- Preferred Certifications: CISSP (Certified Information Systems Security Professional), other relevant certifications (e.g. - CCSP, AWS Certified Security, Azure Security Engineer)
- Experience working within federal, DoD, or highly regulated environments with a strong understanding of federal compliance frameworks (NIST, RMF, FedRAMP)
- Experience planning and executing secure cloud migrations and managing native cloud security controls
- Experience / knowledge implementing and managing SIEM and SOAR platforms (e.g. - Splunk, Sentinel, Cortex XSOAR)
- Strong background in Identity and Access Management (e.g. - Okta, CyberArk, Microsoft Entra ID)
- Ability to travel as required to support firm engagements
- Applicant must possess a U.S. Government Secret clearance
KPMG LLP and its affiliates and subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work .
Follow this link to obtain salary ranges by city outside of CA:
https://kpmg.com/us/en/how-we-work/pay-transparency.html/?id=M105ADV_2_26
KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.