Job Description:Project OverviewThe Policy, Audits, and Questionnaires (PAQ) team plays a critical role in maintaining enterprise compliance and strengthening customer and regulatory confidence. The team manages the lifecycle of information security policies, supports customer security inquiries, and coordinates internal and external cybersecurity audits and certification activities.
This role will support the organization's audit readiness and compliance efforts by coordinating evidence collection, maintaining accurate documentation, identifying compliance gaps, and working with cross-functional stakeholders to meet the requirements of global information security standards and certification frameworks, including ISO 27001, Cyber Essentials, SOC, ENS (Spain), and other applicable cybersecurity standards.
Key Responsibilities- Support cybersecurity audit, compliance, and certification projects, ensuring activities and deliverables are completed accurately and on schedule.
- Support certification and compliance initiatives such as ISO 27001, ENS Spanish security requirements, Cyber Essentials, SOC, and other global information security frameworks and standards.
- Prepare the organization for internal and external information security audits and coordinate various stages of the audit lifecycle.
- Partner with cross-functional teams, external advisors, auditors, and vendors to collect, organize, review, validate, and present audit evidence.
- Analyze cybersecurity requirements across applicable standards, regulations, and corporate policies and provide guidance to stakeholders on compliance expectations.
- Perform requirements assessments and gap analyses to identify areas of non-compliance or control deficiencies.
- Develop and recommend appropriate corrective and remediation actions and track identified issues through closure.
- Evaluate information security provisions within vendor and customer contracts and provide guidance regarding alignment with corporate security policies and standards.
- Maintain accurate, current, well-organized, and audit-ready compliance documentation, evidence repositories, policies, and supporting records.
- Coordinate with control owners and business stakeholders to ensure required documentation and evidence are provided within established timelines.
- Monitor remediation activities and follow up with stakeholders to ensure identified audit findings and compliance gaps are addressed.
- Assist with initiatives focused on improving the efficiency, quality, consistency, and productivity of cybersecurity compliance, certification, and audit processes.
- Communicate audit requirements, findings, risks, and remediation status clearly to technical and non-technical stakeholders.
Required Skills & Experience- 7 to 10 years of strong experience in cybersecurity audit, governance, risk, and compliance (GRC) activities.
- 3 to 5 years of working knowledge of ISO/IEC 27001 and associated information security controls and certification requirements.
- Familiarity with cybersecurity and information security frameworks and standards such as SOC, Cyber Essentials, ENS, NIST, or similar frameworks.
- 3 to 5 years of experience supporting internal/external audits and security certification programs.
- 5 years of strong experience with audit evidence collection, review, validation, and documentation.
- Ability to interpret security standards and regulatory requirements and translate them into actionable compliance requirements.
- Experience conducting requirements assessments, control assessments, and gap analyses.
- Experience tracking audit findings, corrective actions, and remediation plans through completion.
- Strong project coordination and organizational skills with the ability to manage multiple compliance activities and deadlines simultaneously.
- Demonstrated ability to work effectively with cross-functional teams, control owners, auditors, vendors, and external advisors.
- Excellent documentation skills with strong attention to detail and accuracy.
- Strong written and verbal communication skills, including the ability to communicate cybersecurity and compliance requirements to diverse stakeholders.
Preferred Qualifications- Relevant cybersecurity, audit, risk, or compliance certifications such as CISA, CISSP, CRISC, ISO 27001 Lead Auditor/Lead Implementer, or equivalent are preferred.
- Experience working within a large, global enterprise environment.
- Experience supporting multiple cybersecurity certification or assurance programs concurrently.
- Familiarity with reviewing cybersecurity requirements in customer and vendor contracts.
- Experience using GRC, audit management, or compliance tracking platforms is an advantage.
Ideal Candidate ProfileThe ideal candidate is a detail-oriented Cybersecurity Audit & Compliance professional with hands-on experience supporting ISO 27001 and other security certification programs. The candidate should be comfortable coordinating audits, gathering and validating evidence, performing compliance gap assessments, managing remediation activities, and collaborating with technical and business stakeholders across the organization.
NTT DATA provides a reasonable range of compensation for U.S.-based positions. The starting pay range for this remote role is $50/Hr to $55/Hr. This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on a number of factors, including the candidate's actual work location, relevant experience, technical skills, and other qualifications. This position is eligible for company benefits including participation in medical, dental, and vision insurance, flexible spending or health savings account, and AD&D insurance, employee assistance, participation in a 401k program, and additional voluntary or legally-required benefits.
NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.