Senior IT Risk & Compliance Advisor

Sofia, Bulgaria (Hybrid)

Senior IT Risk & Compliance Advisor

Sofia, Ref №: SrITRC0226E

KPMG Bulgaria is looking to welcome a Senior IT Risk & Compliance Advisor to join our growing team. In this role, you will work closely with major international and local clients, providing expert insights on IT risk, technology controls, and regulatory compliance. You will play a key part in identifying risks, assessing controls, and delivering clear, actionable recommendations that help organizations strengthen their IT environments.

You will join a strong, collaborative team dedicated to IT risk management, compliance, and technology optimization — and you will have the opportunity to deepen your expertise across a wide range of modern platforms and environments.


Key responsibilities include: 

  • Testing the design and operational effectiveness of IT General controls (ITGCs), IT Application controls and IT-dependent business controls in accordance with established standards and best practices,
  • Identifying and documenting technology infrastructure risks, controls, and audit findings,
  • Participating in ICFR Sarbanes-Oxley (SOX), Statement of Controls (SOC), Digital Resilience, Data Privacy, Cybersecurity, and IT due diligence engagements,
  • Expanding IT assurance expertise across contemporary technologies and platforms, including Microsoft Entra ID (Azure), AWS, Google Cloud, Windows Server, Microsoft SQL Server, Oracle Database, SAP, Dynamics 365, ServiceNow, and related systems,
  • Coordinating, mentoring, and supporting junior team members in executing project tasks and daily responsibilities.


Through close client interaction and cross‑industry exposure, you will enhance your expertise in:

  • Fundamental processes and controls around Systems Security, Change Management, and Computer Operations, and their related controls,
  • IT General Controls (ITGCs) testing– Logical Access Management, Change Management, Program Development, Computer Operations, and IT Risk & Governance,
  • Technology risk principles around cloud platforms, operating systems (Windows, Unix/Linux), databases (MS SQL/Oracle Server), ERPs (SAP, Oracle, Dynamics 365),
  • Regulatory compliance standards, Cyber Security, Data Privacy, ERPs, etc.


What we are looking for:

  • University degree in Information Technology, Business Administration, or a related field
  • Minimum 3 years of relevant professional experience
  • Strong written and verbal communication skills in English
  • An advisory mindset - proactive, analytical, and solution‑oriented
  • Professional ethics, integrity, objectivity, and self‑motivation
  • Qualifications such as CISA, CISM, CISSP or other relevant IT audit qualification, or certifications in contemporary technologies will be considered an advantage


What we offer: 

  • Work-Life Balance
    • Hybrid working model
    • Flexible hours, and
    • Extra holidays
  • Learning & Development
    • Structured onboarding
    • Support for professional certifications
    • Access to online and on‑site training programs
    • Clear performance development and promotion pathways
  • Compensation & Benefits
    • Competitive remuneration with regular salary reviews
    • Performance-based bonuses
    • Referral bonus program
    • Food vouchers, additional health insurance, sports card, corporate discounts
    • Fresh fruit, wellbeing initiatives, teambuilding events
    • Fuel vouchers or public transport card


If you’re ready to advance your career in IT Risk & Compliance and work with industry-leading clients, we’d love to meet you.


KPMG has committed to achieve net-zero carbon emissions by 2030 as per Our Impact Plan. We have also committed to advocate for equal opportunity, protecting the physical and mental health of our people, supporting education and lifelong learning in our communities. We act lawfully, ethically and in the public interest.

 

Your application package will be treated with strict confidentiality. Only shortlisted applicants will be contacted.

Some of the information that you provide upon submission of your application is personal data and is covered by the special protection regime under the General Data Protection Regulation (EU 2016/679). KPMG may process your personal data for the purpose of search and selection of suitable candidates for the position as set out above. Your personal data will be stored during the recruitment campaign and afterwards upon your explicit consent or as required by the applicable law. Additional information about the personal data we process in recruitment campaigns, legal reasons and purposes for processing, your rights and other useful information can be found in our Privacy Statement for job applicants. Please read it carefully before submitting your application. 

© 2026 KPMG Bulgaria OOD, a Bulgarian limited liability company and a member firm of the KPMG global organization of independent member firms affiliated with KPMG International Limited, a private English company limited by guarantee. All rights reserved.

Senior IT Risk & Compliance Advisor

Job description

Senior IT Risk & Compliance Advisor

Personal information
Professional data