9/23/26
Apply now
- Start applying with LinkedIn
- Apply Now
Start
- Please wait...
Job Type: Permanent
Work Model: Hybrid
Reference code: 135170
Primary Location: Toronto, ON
All Available Locations: Toronto, ON; Calgary, AB; Edmonton, AB; Fredericton, NB; Halifax, NS; Moncton, NB; Ottawa, ON; Saint John, NB
What will your typical day look like?As a Cybersecurity Controls Testing Analyst, you will support DT's Controls Assurance Testing Programme by validating the design and operating effectiveness of security controls through a combination of automated and manual testing. Working closely with the Cyber Compliance Manager and technical stakeholders, you will help translate regulatory, policy, and industry-standard requirements into measurable controls, identify opportunities to automate testing through data and system integrations, and perform evidence-based assessments where automation is not feasible. You will also support the validation of remediation activities, helping drive control deficiencies through to closure and contributing to reporting and governance activities.
The ideal candidate will bring a combination of technical cyber security experience and GRC or compliance expertise. You will have hands-on experience in areas such as cyber operations, infrastructure, cloud, security engineering, or security administration, and the technical acumen to understand how controls are designed, implemented, and evidenced in practice. Experience supporting compliance, audit, controls assurance, or risk management activities is essential, along with the ability to assess whether technical controls effectively satisfy regulatory, policy, and industry-standard requirements.
Key Responsibilities- Support the execution of DT's Controls Assurance Testing Programme through a combination of automated and manual control testing activities.
- Translate regulatory, policy, and industry standard requirements into measurable control objectives, helping define how compliance requirements should be implemented and evidenced within technology environments.
- Partner with technical teams to understand the design and operation of security controls across identity, endpoint, network, infrastructure, cloud, and security operations domains.
- Identify opportunities to automate control testing through integrations with security and technology platforms, leveraging system data wherever possible to support continuous assurance and reduce manual testing effort.
- Develop and maintain automated testing logic, technical validation queries, control mappings, and evidence requirements to support repeatable and scalable testing activities.
- Perform manual control effectiveness testing where automation is not feasible, including evidence collection, validation, sampling, and assessment against defined testing criteria.
- Assess whether implemented controls meet the intent of applicable policies, standards, and compliance requirements, documenting findings and testing outcomes.
- Validate remediation activities submitted by control owners, reviewing technical and procedural evidence to determine whether identified deficiencies have been effectively addressed.
- Track control deficiencies and remediation activities through to closure, proactively engaging with stakeholders and escalating overdue actions where appropriate.
- Maintain control testing documentation, findings, remediation records, and workflow activities within ServiceNow IRM.
- Collaborate with DT Cyber Risk, IT Risk Management, Cyber Security, Engineering, and Operational teams to ensure control testing activities are technically accurate, well evidenced, and consistently executed.
- Support the Compliance Manager in evolving and maturing the Controls Assurance Testing Programme, including the development of testing methodologies, automation capabilities, reporting, and quality standards.
- Contribute to management reporting, KPI development, dashboard production, and assurance insights for compliance and risk stakeholders.
- Stay current with emerging technologies, cyber security practices, control assurance methodologies, and relevant regulatory and industry standards.
About the teamDeloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
Enough about us, let's talk about youQualificationsDo you possess the following?:
- Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Engineering, or a related field.
- Relevant certifications such as ISO 27001 Lead Auditor, CISA, CRISC, Security+, or similar are desirable
- 2-4 years of professional experience in information security, IT risk management, internal audit, compliance, or controls testing roles.
- Experience conducting compliance testing, audits, or control assessments against internal or external standards (e.g., ISO 27001, NIST, CIS Controls, SOC 2).
- Working knowledge of automated control testing tools (e.g., Qualys, Tenable, Rapid7, or similar platforms).
- Experience with GRC or ITSM platforms such as ServiceNow, Archer, MetricStream, or similar for control and remediation tracking.
- Experience with Microsoft security tooling (e.g., Defender for Endpoint, Intune, Sentinel) and/or KQL query writing is advantageous.
- Experience working in a large, global, matrixed organisation is an advantage.
Total RewardsThe salary range for this position is $69,000 - $114,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels. Our approach is grounded on recognizing people's unique strengths and contributions and rewarding the value that they deliver.
Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. On top of our regular paid vacation days, some examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, firm-wide closures known as "Deloitte Days", dedicated days of for learning (known as Development and Innovation Days), flexible work arrangements and a hybrid work structure.