NTT DATA  Services

Cybersecurity Audit & Compliance Specialist - REMOTE

NTT DATA Services$68K — $118K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in cybersecurity audit, governance, risk, and compliance (GRC) activities.
  • 3+ years of hands-on knowledge with ISO/IEC 27001 and its certification processes.
  • 3+ years supporting internal/external audits and security certifications.
  • 5+ years with proficiency in audit evidence collection, validation, and documentation.
  • 3+ years familiar with cybersecurity standards like SOC, Cyber Essentials, and ENS.

Responsibilities

  • Support cybersecurity audit and compliance projects to ensure timely deliverables.
  • Prepare the organization for internal and external security audits, coordinating the audit lifecycle.
  • Partner with teams to gather, validate, and present audit evidence effectively.
  • Analyze compliance requirements and provide guidance to stakeholders on expectations.
  • Conduct gap analyses to identify compliance deficiencies and recommend remediation actions.
  • Maintain organized, audit-ready compliance documentation and evidence repositories.
  • Monitor remediation efforts and collaborate with stakeholders on addressing audit findings.

Benefits

  • Customizable health and dental coverage with telemedicine.
  • Wellness credits and gym discounts.
  • Life, disability, and optional insurance plans for income protection.
  • Access to a 24/7 Employee Assistance Program.
  • Remote work allowance and various perks including discounts and travel insurance.
Full Job Description
Req ID: 387325

We are currently seeking a Cybersecurity Audit & Compliance Specialist - REMOTE to join our team in Ottawa, Ontario (CA-ON), Canada (CA).

Cybersecurity Audit & Compliance Specialist

Project Overview

The Policy, Audits, and Questionnaires (PAQ) team plays a critical role in maintaining enterprise compliance and strengthening customer and regulatory confidence. The team manages the lifecycle of information security policies, supports customer security inquiries, and coordinates internal and external cybersecurity audits and certification activities.

This role will support the organization's audit readiness and compliance efforts by coordinating evidence collection, maintaining accurate documentation, identifying compliance gaps, and working with cross-functional stakeholders to meet the requirements of global information security standards and certification frameworks, including ISO 27001, Cyber Essentials, SOC, ENS (Spain), and other applicable cybersecurity standards

Day to Day Responsibilities:
  • Support cybersecurity audit, compliance, and certification projects, ensuring activities and deliverables are completed accurately and on schedule.
  • Support certification and compliance initiatives such as ISO 27001, ENS Spanish security requirements, Cyber Essentials, SOC, and other global information security frameworks and standards.
  • Prepare the organization for internal and external information security audits and coordinate various stages of the audit lifecycle.
  • Partner with cross-functional teams, external advisors, auditors, and vendors to collect, organize, review, validate, and present audit evidence.
  • Analyze cybersecurity requirements across applicable standards, regulations, and corporate policies and provide guidance to stakeholders on compliance expectations.
  • Perform requirements assessments and gap analyses to identify areas of non-compliance or control deficiencies.
  • Develop and recommend appropriate corrective and remediation actions and track identified issues through closure.
  • Evaluate information security provisions within vendor and customer contracts and provide guidance regarding alignment with corporate security policies and standards.
  • Maintain accurate, current, well-organized, and audit-ready compliance documentation, evidence repositories, policies, and supporting records.
  • Coordinate with control owners and business stakeholders to ensure required documentation and evidence are provided within established timelines.
  • Monitor remediation activities and follow up with stakeholders to ensure identified audit findings and compliance gaps are addressed.
  • Assist with initiatives focused on improving the efficiency, quality, consistency, and productivity of cybersecurity compliance, certification, and audit processes.
  • Communicate audit requirements, findings, risks, and remediation status clearly to technical and non-technical stakeholders.


Minimum Requirements:
  • 7+ years of strong experience in cybersecurity audit, governance, risk, and compliance (GRC) activities.
  • 3+ years of working knowledge of ISO/IEC 27001 and associated information security controls and certification requirements.
  • 3+ years of experience supporting internal/external audits and security certification programs.
  • 5+ years of strong experience with audit evidence collection, review, validation, and documentation.
  • 3+ years with cybersecurity and information security frameworks and standards such as SOC, Cyber Essentials, ENS, NIST, or similar frameworks.


Preferred Skills:
  • Ability to interpret security standards and regulatory requirements and translate them into actionable compliance requirements.
  • Experience conducting requirements assessments, control assessments, and gap analyses.
  • Experience tracking audit findings, corrective actions, and remediation plans through completion.
  • Strong project coordination and organizational skills with the ability to manage multiple compliance activities and deadlines simultaneously.
  • Demonstrated ability to work effectively with cross-functional teams, control owners, auditors, vendors, and external advisors.
  • Excellent documentation skills with strong attention to detail and accuracy.
  • Strong written and verbal communication skills, including the ability to communicate cybersecurity and compliance requirements to diverse stakeholders.
  • Relevant cybersecurity, audit, risk, or compliance certifications such as CISA, CISSP, CRISC, ISO 27001 Lead Auditor/Lead Implementer, or equivalent are preferred.
  • Experience working within a large, global enterprise environment.
  • Experience supporting multiple cybersecurity certification or assurance programs concurrently.
  • Familiarity with reviewing cybersecurity requirements in customer and vendor contracts.
  • Experience using GRC, audit management, or compliance tracking platforms is an advantage


NTT DATA provides a reasonable range of compensation for Canada-based positions. The starting pay range for this role is $68,076 - $118,188. Actual compensation will depend on a number of factors, including the candidate's relevant experience, technical skills, and other qualifications.

This position may also be eligible for incentive compensation based on individual and/or company performance.

This position is eligible for the Company's comprehensive benefits program in Canada, including customizable health and dental coverage with telemedicine, wellness credits, and gym discounts. Employees receive income protection through life, disability, and optional insurance plans, plus access to a 24/7 Employee Assistance Program. Additional perks include retirement savings, a remote work allowance for eligible employees, and various discounts and travel insurance.

#LI-NorthAmerica

Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client's needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use [redacted].com, [redacted].com and [redacted].nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us.

NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us.

About NTT DATA Services

NTT DATA Corporation is a Japanese multinational information technology service and consulting company headquartered in Tokyo, Japan. It is partially-owned subsidiary of Nippon Telegraph and Telephone. Japan Telegraph and Telephone Public Corporation, a predecessor of NTT, started Data Communications business in 1967. NTT, following its privatization in 1985, spun off the Data Communications division as NTT DATA in 1988, which has now become the largest of the IT Services companies headquartered in Japan.
Learn more about NTT DATA Services
Size
151,991 employees
Industry
Founded
1988
NASDAQ

Similar Jobs

More Jobs at NTT DATA Services

More Information Technology Jobs

Find similar Cybersecurity Audit & Compliance Specialist - REMOTE jobs: