На проект 2-3 месяца требуется ML Engineer (Senior) Обязанности: - Проектирование и разработка production-ready ML, LLM, NLP и Computer Vision решений для ...
Information Security Senior Specialist
Описание вакансии
We’re currently seeking an Information Security Senior Specialist to join our Quality Risk Management (QRM) team. In this role, you will work on projects across the CASA region, covering 11 countries, performing information security and technology risk assessments, reviewing technology solutions and processes, identifying security risks, and working with technical and business teams to ensure appropriate security controls are considered and implemented.
As an Information Security Senior Specialist You Will:
- Perform security reviews and assessments of technology solutions, applications, cloud services, infrastructure, and third-party services.
- Support technology, architecture, and solution reviews to identify and manage security risks.
- Conduct information security and technology risk assessments.
- Review security requirements throughout the Software Development Life Cycle (SDLC) and technology change processes.
- Support vendor, supplier, client, and contractual security reviews.
- Support client security questionnaires, audits, and assurance requests.
- Review emerging technologies, including Artificial Intelligence (AI) solutions, from a security and risk perspective.
- Prepare security assessment reports and recommendations.
- Monitor remediation activities and follow up on identified risks.
- Collaborate with Technology, Risk, Procurement, Privacy, Legal, and business teams.
- Contribute to the continuous improvement of information security processes and practices.
You’re the Perfect Match if You:
- Have 3–5+ years of professional experience in Information Security, Cybersecurity, IT, or a related discipline.
- Hold a Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related discipline.
- Are fluent in English, both written and spoken.
- Have a good understanding of information security principles and technology risks.
- Have knowledge of the Software Development Life Cycle (SDLC).
- Have a basic understanding of cloud and enterprise technologies, infrastructure, networking, operating systems, and databases.
- Understand Identity and Access Management (IAM) concepts, application security, and security requirements throughout the SDLC.
- Have a basic understanding of vulnerability management, security testing, and third-party risk management.
- Are familiar with Artificial Intelligence (AI) security and governance concepts.
- Have knowledge of information security frameworks and standards such as ISO 27001, NIST, or CIS.
- Are proactive, collaborative, and able to work independently as part of a regional team.
It Would Be a Plus If You Have:
- Certifications such as CISSP, CISM, CISA, CRISC, CCSP, or ISO/IEC 27001 Lead Auditor / Lead Implementer.
- Microsoft Azure, AWS, or other cloud and technology certifications.
- Other cybersecurity-related certifications.
О компании «KPMG»

KPMG is a global network of professional firms providing Audit, Tax and Advisory services. We have 219,000 outstanding professionals working together to deliver value in 147 countries worldwide.
KPMG has been working in Kazakhstan since 1996, and our essential principle has always been to use the firm’s global intellectual capital, combined with the practical experience of our local professionals. We have about 600 employees and full operating offices in Almaty, Nur-Sultan, Atyrau and Bishkek.
Our global experience is thus complemented by the skills of local professionals, an invaluable asset for any client operating in or considering a move into a new and unfamiliar market. Our teams can offer realistic but internationally strategic sophisticated recommendations in line with local market conditions.




