IT Governance, Risk and Compliance Specialist

Sofia, Bulgaria (Hybrid)

KPMG IT Service OOD is an IT service provider with a mission to digitalize the core business of KPMG IT Service GmbH and KPMG AG in Germany and their clients across the globe. We employ more than 200 people in Sofia and deliver the full spectrum of IT services to our clients, including Software Engineering, Application & Platform Operations, Infrastructure and Cloud and Digital Process Compliance.

We are looking to hire an ambitious and forward-thinking person to join our team of digital process compliance consultants. The role focuses on assessing and improving governance frameworks, business and IT processes, risk management practices, and regulatory compliance across international organizations. You will work with clients in evaluating both business and technology-related risks, supporting compliance with regulations, industry standards, and leading practices.

We welcome candidates from business, finance, accounting, and related disciplines, as well as technology backgrounds. Whether your experience is in audit, internal controls, business process management, risk management, compliance, cybersecurity, ERP systems or IT governance, we encourage you to apply.

The role:

Are you a motivated professional with experience in business processes, risk management, internal controls, audit, compliance, or IT governance? Do you enjoy understanding how business operations and technology work together to manage risk and achieve organizational objectives?

If so, this may be a role for you!

As an IT Governance, Risk & Compliance (GRC) Specialist, you will help international organizations strengthen their governance, risk management and compliance capabilities across business and technology environments. Working with cross-functional teams, you will assess business processes, internal controls, IT systems and security frameworks while supporting compliance with international standards, regulations and industry-leading practices.

As an  IT Governance Risk and Compliance Specialist, you will focus on:

  • Being part of cross-national and cross-functional teams working to analyze and evaluate IT processes and security structures in accordance with relevant control frameworks, standards and assurance methodologies including General IT Controls (GITCs), SOC 1, SOC 2, ISAE 3402, ISAE 3000, BSI C5, ISO 27001, ISO 42001 and ISO 22301.
  • Working with leading international organizations across multiple industries, helping them improve governance, risk management, compliance, resilience and digital trust.
  • Providing professional advice to clients through constant collaboration and assisting in implementing best practices for IT processes and security based on guidelines and frameworks including NIST, COBIT5, ITIL.
  • Exposure to emerging areas such as Artificial Intelligence Governance (ISO 42001), Digital Operational Resilience (DORA) and Cybersecurity Regulation (NIS2).
  • Assessing, addressing and coordinating related business and system risks.
  • Performing risk and gap assessments for end-to-end business processes such as Procure-to-Pay (P2P), Quote-to-Cash (Q2C), Record-to-Report (R2R) etc, and related IT systems.
  • Assessing governance, risk management and internal control frameworks across business and IT processes.
  • Contributing to compliance programs, control design reviews, and process improvement initiatives.
  • Supporting clients in identifying, documenting and mitigating operational, regulatory and technology risks.
  • Collaborating closely with KPMG colleagues in Germany and other international locations as part of project delivery.

What you bring in:

  • University degree in Information Technologies, Cyber Security, Economics, Finance, Accounting, Business or Audit and Compliance related discipline.
  • Fluency in English.
  • Strong analytical and problem-solving skills, with the ability to navigate complex environments and develop effective solutions.
  • Customer-focused mindset with excellent stakeholder management, collaboration, and networking skills, enabling the delivery of trusted, value-driven advisory services.
  • Strong learning agility and adaptability, with the ability to quickly understand new technologies, regulatory requirements, and business processes, while embracing digital innovation and continuous improvement.
  • Commercial awareness and business acumen, with the ability to identify growth opportunities, contribute to strategic initiatives, and create value for clients.
  • Proactive and results-oriented approach, demonstrating ownership, innovation, and a drive to improve processes and ways of working. 

Beneficial: 

  • Professional experience with risk management, internal controls, compliance, audit, or IT governance concepts within business and/or IT environments.
  • Experience with control frameworks, standards and assurance methodologies including General IT Controls (GITCs), SOC 1, SOC 2, ISAE 3402, ISAE 3000, BSI C5, ISO 27001, ISO 42001 and ISO 22301.
  • Experience in business processes such as Finance, Record-to-Report (R2R), Procure-to-Pay (P2P), Quote-to-Cash (Q2C), Supply Chain, Human Resources, or comparable operational processes.
  • Interest in the following certifications: CISA, CISSP, GIAC, ISO 27001, ISO 22301, ISO 42001, CISM.
  • Experience with ERP systems such as SAP, Oracle (e.g. NetSuite), Microsoft Dynamics 365 suite, or others.

What we offer:

  • The opportunity to work in a highly talented team part of a global organization
  • Attractive remuneration
  • Build expertise in emerging technologies, digital governance and compliance.
  • Opportunity for continuous training, learning and certification
  • Working on challenging projects with clients in various industries across the globe
  • Modern office environment
  • Additional health insurance
  • Life insurance
  • 50+ benefits and services to choose from
  • Hybrid working policy

If you are interested in further exploring this career opportunity, please send us your CV.

Only shortlisted candidates will be contacted.

IT Governance, Risk and Compliance Specialist

Job description

IT Governance, Risk and Compliance Specialist

Personal information
Details