Job Description
Job Summary:
We are currently looking for an Experienced Associate for our Data & Information Governance team. BDO is a go-to firm for multi-national companies to meet their complex cyber, data protection, and compliance needs. Leveraging our global network, expertise, and technology, our professionals deploy a client centric, agile approach to work seamlessly and efficiently to identify, mitigate and manage risk within client organizations. Our professionals work with clients to implement holistic data governance programs that can adapt to global data protection requirements and obligations while aligning them to their business strategies. Professionals will support client engagements related to data and information governance, data handling, and information protection practices.
Job Duties:
• Participates in client interviews with data owners, data stewards, and other stakeholders to document data governance processes, data flows, and control activities
• Conducts assessments of client privacy and data governance programs using established frameworks, regulations, and data governance standards, including DAMA-based concepts and practices
• Works with data mapping exercises to identify data creation, storage, access, transmission, sharing, and retention practices
• Reviews data handling practices against established data governance, security, and records management best practices
• Assesses data classification processes and data asset classification requirements across client environments
• Reviews CASB logs and reporting to identify potential policy violations, data exposure trends, and anomalous data sharing activity and makes recommendations based on findings
• Assesses security controls related to data access, retention, sharing, and protection across collaboration platforms and repositories and makes recommendations based on findings
• Pulls and analyzes metadata and access reports from SharePoint and Microsoft Teams and makes recommendations based on findings
• Generates and reviews reports (e.g., Netskope, Purview) to support assessments of data movement, access, and policy compliance
• Assesses data sharing practices to identify inappropriate access, external exposure, and governance control gaps
• Records and assesses compliance with data retention requirements, access controls, and information handling standards
• Identifies remediation opportunities and develops practical recommendations for control enhancement and process improvement
• Drafts policies, standards, procedures, and process documentation aligned with governance objectives and applicable legal and regulatory requirements
• Prepares project documentation, findings summaries, status updates, and client deliverables
• Presents findings, risks, and recommendations to management-level client stakeholders
• Tracks project activities, findings, dependencies, and status updates in JIRA
• Collaborate with internal engagement teams and client stakeholders to support project execution and timely delivery
• Supports multiple client engagements while maintaining quality, accuracy, and adherence to deadlines
• Communicate status, issues, and priorities to client stakeholders and leadership.
• Ability to travel up to 20%, required
• Other duties as required
Supervisory Responsibilities:
• N/A
Qualifications, Knowledge, Skills, and Abilities:
Education:
• Bachelor's Degree in Computer Science, Engineering, Cybersecurity, or Information Technology, required
Experience:
• Two (2) or more years of experience in a data or information governance related field (e.g., information security, IT, or data privacy), required
• One (1) or more years experience leading stakeholder interviews and documenting business and technical processes, required
• Six (6) months or more experience conducting data mapping, control assessments, or information governance reviews, required
• Six (6) months or more experience with SDLC delivery models, specifically working within them in blended resource pools (i.e. client resources, BDO resources, and third-party vendors), required
• Experience presenting findings and recommendations to senior client stakeholders, required
• Experience assessing data classification, access controls, data sharing, and retention practices, required
• Experience in a client-facing professional services environment, preferred
License/Certification:
• Other certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Privacy Professional (CIPP), or Certified Information Security Manager (CISM), Certified Data Management Professional (CDMP), preferred
Software:
• Proficiency in Microsoft office suite, required
• Experience with scanning tools, such as Microsoft Purview, Varonis, preferred
• Experience with ServiceNow, JIRA, and other project management and ticketing tools, preferred
Languages:
• N/A
Other Knowledge, Skills, and Abilities:
• Demonstrated consulting, interpersonal and client relationships skills
• Excellent verbal and written communication skills
• Ability to identify issues and anomalies through review of supporting information
• Solid organizational skills, especially ability to meet project deadlines with a focus on details
• Ability to multi-task while working independently or within a group environment
• Ability to work in a deadline-driven environment and contribute to multiple projects simultaneously
Individual salaries that are offered to a candidate are determined after consideration of numerous factors including but not limited to the candidate's qualifications, experience, skills, and geography.
National Range: $75,000 - $95,000
Maryland Range: $75,000 - $95,000
NYC/Long Island/Westchester Range: $75,000 - $95,000
*Benefits may be subject to eligibility requirements.
Click here to find out more!