BDO USA, LLP

Exp. Associate, Cyber Risk & Compliance

BDO USA, LLP$75K — $95K *
Business Services
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science, Engineering, Cybersecurity, or Information Technology required
  • 2+ years in a data or information governance field
  • 1+ year leading stakeholder interviews and documenting processes
  • 6+ months conducting data mapping, control assessments, or governance reviews
  • 6+ months experience with SDLC delivery models
  • Experience presenting findings to senior stakeholders

Responsibilities

  • Participate in client interviews and document data governance processes
  • Conduct assessments of privacy and governance programs using established frameworks
  • Work on data mapping exercises to identify data handling practices
  • Review data handling against best practices in governance and security
  • Assess security controls related to data access and protection
  • Analyze metadata and access reports to make recommendations
  • Draft policies and procedures aligned with governance objectives

Benefits

  • Opportunity to work with multi-national clients
  • Access to a global network and expert resources
  • Engagement in a client-centric and agile working environment
  • Chance to develop and implement governance solutions
  • Exposure to cutting-edge technology in data management
  • Professional growth and collaboration opportunities with engagement teams
Full Job Description
Job Description

Job Summary:

We are currently looking for an Experienced Associate for our Data & Information Governance team. BDO is a go-to firm for multi-national companies to meet their complex cyber, data protection, and compliance needs. Leveraging our global network, expertise, and technology, our professionals deploy a client centric, agile approach to work seamlessly and efficiently to identify, mitigate and manage risk within client organizations. Our professionals work with clients to implement holistic data governance programs that can adapt to global data protection requirements and obligations while aligning them to their business strategies. Professionals will support client engagements related to data and information governance, data handling, and information protection practices.

Job Duties:
• Participates in client interviews with data owners, data stewards, and other stakeholders to document data governance processes, data flows, and control activities
• Conducts assessments of client privacy and data governance programs using established frameworks, regulations, and data governance standards, including DAMA-based concepts and practices
• Works with data mapping exercises to identify data creation, storage, access, transmission, sharing, and retention practices
• Reviews data handling practices against established data governance, security, and records management best practices
• Assesses data classification processes and data asset classification requirements across client environments
• Reviews CASB logs and reporting to identify potential policy violations, data exposure trends, and anomalous data sharing activity and makes recommendations based on findings
• Assesses security controls related to data access, retention, sharing, and protection across collaboration platforms and repositories and makes recommendations based on findings
• Pulls and analyzes metadata and access reports from SharePoint and Microsoft Teams and makes recommendations based on findings
• Generates and reviews reports (e.g., Netskope, Purview) to support assessments of data movement, access, and policy compliance
• Assesses data sharing practices to identify inappropriate access, external exposure, and governance control gaps
• Records and assesses compliance with data retention requirements, access controls, and information handling standards
• Identifies remediation opportunities and develops practical recommendations for control enhancement and process improvement
• Drafts policies, standards, procedures, and process documentation aligned with governance objectives and applicable legal and regulatory requirements
• Prepares project documentation, findings summaries, status updates, and client deliverables
• Presents findings, risks, and recommendations to management-level client stakeholders
• Tracks project activities, findings, dependencies, and status updates in JIRA
• Collaborate with internal engagement teams and client stakeholders to support project execution and timely delivery
• Supports multiple client engagements while maintaining quality, accuracy, and adherence to deadlines
• Communicate status, issues, and priorities to client stakeholders and leadership.
• Ability to travel up to 20%, required
• Other duties as required

Supervisory Responsibilities:
• N/A

Qualifications, Knowledge, Skills, and Abilities:

Education:
• Bachelor's Degree in Computer Science, Engineering, Cybersecurity, or Information Technology, required

Experience:
• Two (2) or more years of experience in a data or information governance related field (e.g., information security, IT, or data privacy), required
• One (1) or more years experience leading stakeholder interviews and documenting business and technical processes, required
• Six (6) months or more experience conducting data mapping, control assessments, or information governance reviews, required
• Six (6) months or more experience with SDLC delivery models, specifically working within them in blended resource pools (i.e. client resources, BDO resources, and third-party vendors), required
• Experience presenting findings and recommendations to senior client stakeholders, required
• Experience assessing data classification, access controls, data sharing, and retention practices, required
• Experience in a client-facing professional services environment, preferred

License/Certification:
• Other certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Privacy Professional (CIPP), or Certified Information Security Manager (CISM), Certified Data Management Professional (CDMP), preferred

Software:
• Proficiency in Microsoft office suite, required
• Experience with scanning tools, such as Microsoft Purview, Varonis, preferred
• Experience with ServiceNow, JIRA, and other project management and ticketing tools, preferred

Languages:
• N/A

Other Knowledge, Skills, and Abilities:
• Demonstrated consulting, interpersonal and client relationships skills
• Excellent verbal and written communication skills
• Ability to identify issues and anomalies through review of supporting information
• Solid organizational skills, especially ability to meet project deadlines with a focus on details
• Ability to multi-task while working independently or within a group environment
• Ability to work in a deadline-driven environment and contribute to multiple projects simultaneously

Individual salaries that are offered to a candidate are determined after consideration of numerous factors including but not limited to the candidate's qualifications, experience, skills, and geography.

National Range: $75,000 - $95,000
Maryland Range: $75,000 - $95,000
NYC/Long Island/Westchester Range: $75,000 - $95,000

About BDO USA, LLP

BDO USA, LLP is a professional services firm providing assurance, tax, and advisory services to a wide range of publicly traded and privately held companies. The company was founded in 1910 and is headquartered in Chicago, Illinois. BDO USA has more than 60 offices and over 5,000 employees throughout the United States. The company is a member of the BDO International network, which has more than 1,500 offices in over 160 countries.
Learn more about BDO USA, LLP
Size
10,000 employees
Industry
Founded
1910

Similar Jobs

More Jobs at BDO USA, LLP

More Business Services Jobs

Find similar Exp. Associate, Cyber Risk & Compliance jobs: