BDO USA, LLP

Exp. Associate, Cyber Risk & Compliance

BDO USA, LLP$75K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science, Engineering, Cybersecurity, or Information Technology required
  • 2+ years in data or information governance, IT, or data privacy
  • 1+ year leading stakeholder interviews and documenting processes
  • 6+ months in conducting data mapping or control assessments
  • 6+ months experience in SDLC delivery models
  • Client-facing experience preferred
  • Relevant certifications (e.g., CISSP, CIPP, CISM) preferred

Responsibilities

  • Participate in client interviews to document data governance processes
  • Conduct assessments of client privacy and data governance programs
  • Work on data mapping exercises to identify data practices
  • Review data handling against best practices
  • Assess classification processes across client environments
  • Generate and review reports for data movement and compliance
  • Present findings and recommendations to management-level clients

Benefits

  • Professional development opportunities
  • Collaborative work environment
  • Exposure to diverse clients and challenges
  • Access to a global network of resources
  • Potential travel opportunities
Full Job Description
Job Description

Job Summary:

We are currently looking for an Experienced Associate for our Data & Information Governance team. BDO is a go-to firm for multi-national companies to meet their complex cyber, data protection, and compliance needs. Leveraging our global network, expertise, and technology, our professionals deploy a client centric, agile approach to work seamlessly and efficiently to identify, mitigate and manage risk within client organizations. Our professionals work with clients to implement holistic data governance programs that can adapt to global data protection requirements and obligations while aligning them to their business strategies. Professionals will support client engagements related to data and information governance, data handling, and information protection practices.

Job Duties:
• Participates in client interviews with data owners, data stewards, and other stakeholders to document data governance processes, data flows, and control activities
• Conducts assessments of client privacy and data governance programs using established frameworks, regulations, and data governance standards, including DAMA-based concepts and practices
• Works with data mapping exercises to identify data creation, storage, access, transmission, sharing, and retention practices
• Reviews data handling practices against established data governance, security, and records management best practices
• Assesses data classification processes and data asset classification requirements across client environments
• Reviews CASB logs and reporting to identify potential policy violations, data exposure trends, and anomalous data sharing activity and makes recommendations based on findings
• Assesses security controls related to data access, retention, sharing, and protection across collaboration platforms and repositories and makes recommendations based on findings
• Pulls and analyzes metadata and access reports from SharePoint and Microsoft Teams and makes recommendations based on findings
• Generates and reviews reports (e.g., Netskope, Purview) to support assessments of data movement, access, and policy compliance
• Assesses data sharing practices to identify inappropriate access, external exposure, and governance control gaps
• Records and assesses compliance with data retention requirements, access controls, and information handling standards
• Identifies remediation opportunities and develops practical recommendations for control enhancement and process improvement
• Drafts policies, standards, procedures, and process documentation aligned with governance objectives and applicable legal and regulatory requirements
• Prepares project documentation, findings summaries, status updates, and client deliverables
• Presents findings, risks, and recommendations to management-level client stakeholders
• Tracks project activities, findings, dependencies, and status updates in JIRA
• Collaborate with internal engagement teams and client stakeholders to support project execution and timely delivery
• Supports multiple client engagements while maintaining quality, accuracy, and adherence to deadlines
• Communicate status, issues, and priorities to client stakeholders and leadership.
• Ability to travel up to 20%, required
• Other duties as required

Supervisory Responsibilities:
• N/A

Qualifications, Knowledge, Skills, and Abilities:

Education:
• Bachelor's Degree in Computer Science, Engineering, Cybersecurity, or Information Technology, required

Experience:
• Two (2) or more years of experience in a data or information governance related field (e.g., information security, IT, or data privacy), required
• One (1) or more years experience leading stakeholder interviews and documenting business and technical processes, required
• Six (6) months or more experience conducting data mapping, control assessments, or information governance reviews, required
• Six (6) months or more experience with SDLC delivery models, specifically working within them in blended resource pools (i.e. client resources, BDO resources, and third-party vendors), required
• Experience presenting findings and recommendations to senior client stakeholders, required
• Experience assessing data classification, access controls, data sharing, and retention practices, required
• Experience in a client-facing professional services environment, preferred

License/Certification:
• Other certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Privacy Professional (CIPP), or Certified Information Security Manager (CISM), Certified Data Management Professional (CDMP), preferred

Software:
• Proficiency in Microsoft office suite, required
• Experience with scanning tools, such as Microsoft Purview, Varonis, preferred
• Experience with ServiceNow, JIRA, and other project management and ticketing tools, preferred

Languages:
• N/A

Other Knowledge, Skills, and Abilities:
• Demonstrated consulting, interpersonal and client relationships skills
• Excellent verbal and written communication skills
• Ability to identify issues and anomalies through review of supporting information
• Solid organizational skills, especially ability to meet project deadlines with a focus on details
• Ability to multi-task while working independently or within a group environment
• Ability to work in a deadline-driven environment and contribute to multiple projects simultaneously

Individual salaries that are offered to a candidate are determined after consideration of numerous factors including but not limited to the candidate's qualifications, experience, skills, and geography.

National Range: $75,000 - $95,000
Maryland Range: $75,000 - $95,000
NYC/Long Island/Westchester Range: $75,000 - $95,000

About BDO USA, LLP

BDO USA, LLP is a professional services firm providing assurance, tax, and advisory services to a wide range of publicly traded and privately held companies. The company was founded in 1910 and is headquartered in Chicago, Illinois. BDO USA has more than 60 offices and over 5,000 employees throughout the United States. The company is a member of the BDO International network, which has more than 1,500 offices in over 160 countries.
Learn more about BDO USA, LLP
Size
10,000 employees
Industry
Founded
1910

Similar Jobs

More Jobs at BDO USA, LLP

More Information Technology Jobs

Find similar Exp. Associate, Cyber Risk & Compliance jobs: