Manager - SOC 2 Assurance and Cybersecurity Advisory
Full-time
Montreal, QC, Canada
At KPMG in Canada, our people bring their unique perspectives to Canada’s most important challenges. Here, you can build momentum that reaches beyond our business, develop skills for the future, and take ownership of your career with support at every stage. Join a firm where your career can make a difference.
Our Technology Risk Consulting practice in Montréal is seeking a Manager, SOC 2 Assurance and Cybersecurity Advisory. This is a client-facing leadership role for an experienced professional who combines a strong understanding of cybersecurity and technology controls with practical experience delivering SOC 2 assurance, readiness and related advisory engagements.
The successful candidate will lead complex engagements for technology companies, cloud service providers, financial-services organizations and other businesses that need to demonstrate the security, availability, confidentiality, processing integrity or privacy of their systems. The Manager will work closely with client executives, cybersecurity leaders, technology teams, control owners and KPMG engagement leaders to deliver high-quality, practical and business-focused outcomes.
This role is intended for a professional who can translate technical cybersecurity matters into clear control, risk and assurance conclusions. It is not a Security Operations Centre monitoring role.
What you will do
Lead SOC 2 assurance engagements
- Plan, manage and deliver SOC 2 Type 1 and Type 2 assurance engagements from initial scoping through reporting.
- Evaluate management’s description of its system and assess its alignment with the applicable AICPA Description Criteria.
- Assess whether controls are suitably designed and, for Type 2 engagements, whether they operated effectively throughout the review period.
- Review control matrices, process narratives, system descriptions, testing documentation and supporting evidence.
- Evaluate control exceptions, determine their significance and support the development of clear, balanced and technically sound reporting conclusions.
- Oversee the preparation and review of engagement documentation in accordance with applicable professional standards, firm methodology and quality-management requirements.
- Support SOC 3 reporting and other related assurance services, where applicable.
- Coordinate with engagement partners, quality reviewers, specialists and component teams to resolve complex technical or reporting matters.
Deliver cybersecurity and SOC 2 readiness advisory services
- Lead readiness assessments for organizations preparing for their first SOC 2 examination or expanding the scope of an existing report.
- Assess cybersecurity governance, risk management and control environments against the AICPA Trust Services Criteria and other relevant frameworks.
- Identify control design and documentation gaps and develop practical remediation roadmaps.
- Advise clients on scoping decisions, system boundaries, service commitments, subservice organizations and complementary user entity controls.
- Facilitate workshops and walkthroughs with cybersecurity, infrastructure, software development, human resources, legal, privacy and business stakeholders.
- Help clients establish sustainable evidence, monitoring and control-owner accountability processes.
- Support related engagements involving ISO/IEC 27001, cybersecurity risk assessments, third-party risk management, cloud security and technology controls.
- Translate technical findings into clear recommendations that are proportionate to the client’s risks, maturity and business objectives.
Manage engagements and client relationships
- Serve as the principal day-to-day contact for assigned clients.
- Establish engagement plans, budgets, milestones, resource requirements and reporting timelines.
- Monitor engagement economics, scope changes, risks, dependencies and deliverable quality.
- Lead status meetings and communicate emerging issues promptly and constructively.
- Build trusted relationships with client executives, technology leaders, internal audit teams and control owners.
- Present observations and recommendations to senior management, audit committees or other governance bodies, as required.
- Identify opportunities to provide additional value to clients while maintaining professional independence and complying with applicable assurance requirements.
- Participate in proposals, client presentations, scoping discussions and other business-development activities.
Develop and lead our people
- Manage, coach and review the work of Senior Consultants and Consultants.
- Provide timely, specific and constructive feedback.
- Support team members in developing SOC 2, cybersecurity, engagement-management and professional-judgment capabilities.
- Promote consistent engagement execution, effective project management and high-quality documentation.
- Contribute to the development of templates, methodologies, training materials and knowledge-sharing activities within the practice.
- Foster an inclusive, collaborative and high-performing team environment.
What you bring to the role
Required qualifications and experience
- Approximately 6 to 10 years of relevant professional experience in technology risk, cybersecurity, IT audit, controls assurance or a related field.
- Meaningful experience leading or managing SOC 2 Type 1 and/or Type 2 engagements, whether in assurance, readiness or both.
- Strong knowledge of the AICPA Trust Services Criteria, including the Common Criteria and the additional criteria for availability, confidentiality, processing integrity and privacy.
- Experience assessing cybersecurity and technology controls in areas such as:
- security governance and risk management;
- identity and access management;
- privileged access;
- change management and secure software development;
- vulnerability and patch management;
- logging, monitoring and incident response;
- cloud infrastructure and cloud security;
- backup, resilience and disaster recovery;
- third-party and subservice-organization risk; and
- data protection and privacy.
- Demonstrated experience managing multiple engagements, project teams, budgets and competing deadlines.
- Strong report-writing, issue-analysis and quality-review capabilities.
- Ability to communicate technical and assurance matters clearly to both technical and non-technical stakeholders.
- Strong professional judgment, attention to detail and commitment to quality.
- Ability to work effectively in a hybrid environment and travel to client locations when required.
- Professional fluency in French and English, as the role will support clients and engagement teams in both languages.
Education and professional designations
- University degree in accounting, information systems, computer science, cybersecurity, engineering, business administration or another relevant discipline.
- One or more relevant professional designations, such as CPA, CISA, CISSP, CISM, CRISC, CIA or ISO 27001 Lead Auditor, is preferred.
- Experience in a public accounting, professional services or regulated environment is strongly preferred.
- Experience applying Canadian or U.S. assurance standards to controls-reporting engagements is an asset.
Attributes of a Successful Candidate
The successful candidate will be:
- Technically credible: Able to understand cybersecurity architecture, processes and risks while remaining focused on controls, evidence and assurance implications.
- A strong engagement leader: Organized, accountable and able to manage complex engagements without losing sight of quality or client experience.
- An effective communicator: Able to explain technical findings, control gaps and reporting implications in direct, business-oriented language.
- Pragmatic: Focused on recommendations that are implementable and proportionate to the organization’s risks and maturity.
- Quality-minded: Comfortable challenging evidence, conclusions and documentation when professional standards require it.
- Commercially aware: Able to identify client needs, contribute to proposals and support the continued growth of the practice.
- A people developer: Motivated to coach team members and build sustainable capability within the practice.
- Collaborative: Comfortable working across assurance, cybersecurity, privacy, cloud, internal audit and other specialist teams.
Why Join Our Practice
This role offers the opportunity to:
- Lead high-impact SOC 2 assurance and readiness engagements for growing and established organizations.
- Work at the intersection of cybersecurity, technology risk, controls assurance and business transformation.
- Advise clients on complex and evolving technology-control environments.
- Develop broad exposure to cloud platforms, SaaS environments, cybersecurity operations and governance frameworks.
- Work with multidisciplinary professionals in Canada and across KPMG’s global network.
- Help shape the continued growth, methodologies and market profile of our SOC 2 and cybersecurity assurance practice.
- Coach talented professionals and contribute directly to building the next generation of technology-risk leaders.
Application
If you are an experienced SOC 2, technology-risk or cybersecurity professional who enjoys leading teams, solving complex control issues and helping clients build trust in their technology environments, we encourage you to apply.
KPMG is committed to providing a respectful, inclusive and accessible recruitment experience. The final posting should include the current standard KPMG Canada legal, accessibility, inclusion, language and compensation language required by People and Culture for the applicable province and hiring process.
This position requires written and oral fluency in English because it involves interpretation and application of English standards, guidance, laws and regulations, servicing of English-speaking clients located across Canada and collaboration with English Speaking colleagues located outside of Quebec.
Providing you with the support you need to be at your best
Our Values, The KPMG Way
Integrity, we do what is right | Excellence, we never stop learning and improving | Courage, we think and act boldly | Together, we respect each other and draw strength from our differences | For Better, we do what matters
KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice.
Adjustments and accommodations throughout the recruitment process
At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. Adjustments (informal requests), such as extra preparation time or the option for micro breaks during interviews, and accommodations (formal requests), such as accessible communication supports or technology aids, are tailored to individual needs and role requirements. You will have an opportunity to request an adjustment or accommodation at any point throughout the recruitment process. If you require support, please contact KPMG’s Employee Relations Service team by calling 1-888-466-4778.
AI Usage
We embrace the use of artificial intelligence (AI) to enhance the candidate experience and streamline our recruitment processes. AI tools may help with organizing applications or surfacing relevant qualifications. However, no hiring decisions are made using AI. Every hiring decision is made by our hiring managers and recruitment professionals, who are equipped with training that empowers them to use these tools responsibly. AI technologies used in our recruitment process undergo detailed risk assessments, including security and privacy requirements, that align with KPMG’s Trusted AI framework.
We believe technology should empower human judgment, not replace it. It’s one of the many ways we’re delivering on our vision of being a technology-first, people-driven firm.
