Komatsu

IT Cybersecurity Compliance Analyst

Komatsu$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in related field or equivalent experience
  • 2+ years in cybersecurity compliance or related function
  • Experience with eDiscovery and Legal Hold in Microsoft 365 preferred
  • Strong communication skills for conveying cybersecurity concepts
  • Familiarity with phishing simulation tools
  • Ability to maintain documentation of security controls

Responsibilities

  • Own and enhance the Cybersecurity Awareness Program incorporating strategy and training
  • Manage Legal Hold and eDiscovery processes with cross-functional teams
  • Maintain cybersecurity procedures and documentation for compliance activities
  • Analyze metrics related to cybersecurity awareness and training effectiveness
  • Support forensic investigations ensuring confidentiality and integrity
  • Foster relationships across departments to communicate cyber risks
  • Develop annual plan for cybersecurity awareness initiatives and campaigns

Benefits

  • Comprehensive health benefits including medical, dental, and vision
  • 401k or employee savings programs offered
  • Generous employee time off including vacation and holidays
  • Access to employee and family assistance programs
  • Disability and life insurance coverage available
  • Opportunities for employee learning and development programs
Full Job Description
IT Cybersecurity Compliance Analyst Posting Start Date: 9/2/26 Requisition ID: 36849 Onsite or Remote: Onsite Position Job Overview We are seeking an IT Cybersecurity Compliance Analyst to join our Cybersecurity team and play a key role in strengthening our security culture, compliance posture, and investigative readiness. This role will own and mature the organization's Cybersecurity Awareness Program, driving employee education, phishing simulations, communications, metrics, and engagement across the business. In addition, this individual will support cybersecurity compliance activities, Legal Hold and eDiscovery processes, audit evidence collection, and authorized forensic support while ensuring sensitive information and evidence are handled with the highest level of confidentiality and care. This is a great opportunity for someone who enjoys blending cybersecurity, compliance, communication, and cross-functional partnership to help employees understand cyber risk and build stronger security behaviors across the organization. Key Job Responsibilities • Serve as the primary owner for the Cybersecurity Awareness Program, responsible for strategy, communications, employee engagement, phishing simulations, training, metrics, and continuous program maturity across the organization. • Administer the cybersecurity responsibilities associated with the Legal Hold and eDiscovery lifecycle in partnership with Legal, HR, and IT, including intake, custodian identification, preservation, tracking, periodic validation, release coordination, documentation, and chain-of-custody requirements. • Maintain assigned cybersecurity controls, procedures, evidence, and documentation in support of the organization's compliance, certification, and internal and external audit activities. • Develop and analyze cybersecurity awareness, training, phishing, Legal Hold, and compliance metrics to measure effectiveness, identify behavioral and compliance risks, and recommend improvements. • Support authorized forensic and investigative activities while protecting confidentiality, integrity, appropriate custody, and secure handling of sensitive information, devices, and evidence. • Build relationships across business units to effectively communicate cyber risks, coordinate awareness initiatives, and drive employee understanding and behavioral change. • Develop and execute the annual Cybersecurity Awareness Program plan, including enterprise communications, training, phishing simulations, events, campaigns, and targeted education. • Develop and publish effective cybersecurity awareness materials that educate employees about current cybersecurity risks, threats, policies, and expected behaviors. • Coordinate translations of cybersecurity awareness and education content with global awareness liaisons and appropriate business partners. • Collaborate with communications, marketing, technical teams, and business stakeholders to produce accurate, accessible, and appropriately branded awareness materials. • Develop and analyze awareness, training, phishing, and engagement metrics to measure effectiveness, identify behavioral risks, and recommend program improvements. • Administer the operational lifecycle of approved Legal Hold and eDiscovery requests in partnership with Legal, HR, and IT, including intake, custodian identification, preservation coordination, tracking, periodic validation, release coordination, and final documentation. • Administer or support eDiscovery and Legal Hold activities within Microsoft 365, including relevant content maintained in Exchange, OneDrive, SharePoint, and Teams. • Maintain Legal Hold and eDiscovery procedures, matter records, preservation documentation, status tracking, and stakeholder communications. • Support authorized forensic imaging activities, maintain chain-of-custody documentation, and manage the secure labeling, storage, custody status, and tracking of devices, evidence, and retained assets associated with Legal Hold and forensic matters. • Maintain assigned cybersecurity controls, procedures, evidence, and related documentation in support of SOC 2, ISO 27001, and other applicable compliance and certification activities. • Support internal and external audits by gathering and producing evidence associated with cybersecurity awareness, training, Legal Hold, eDiscovery, and assigned security controls. • Analyze cybersecurity compliance data and develop metrics that identify risks, demonstrate control effectiveness, and support continuous improvement. Qualifications/Requirements • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Information Assurance, Communications, Business, or a related field, or an equivalent combination of education and relevant experience. • Two or more years of experience in cybersecurity compliance, cybersecurity awareness, eDiscovery, information governance, security operations, or related cybersecurity function. • Experience administering or supporting Legal Hold and eDiscovery activities within Microsoft 365, including Microsoft Purview and content maintained in Exchange, OneDrive, SharePoint, and Teams, preferred.[DC6.1] • Excellent communication, interpersonal skills, especially the translation of cybersecurity concepts to all levels of the business • Ability to maintain security control documentation • Experience with industry recognized phishing simulation tools • Strong understanding of email header analysis to look for indicators of phishing Additional Information Hiring Range At Komatsu, your base pay is one part of your total compensation package. This role pays $80,000-95,000. The actual offer will consider a wide range of factors, including experience and location. Company Benefits Komatsu provides an extensive and robust employee benefits package that is designed to enhance the well-being of our employees and family members. We embrace a positive and empowering employee experience with a culture that prides itself on a diverse and inclusive environment. • Health benefits: Medical, dental, vision, HSA, wellness programs, etc. • 401k and/or employee savings programs • Employee time off (vacation and designated holidays) • Employee and family assistance programs • Disability benefits • Life insurance • Employee learning and development programs

About Komatsu

Komatsu Ltd. is a Japanese multinational corporation that manufactures construction, mining, forestry, and military equipment, as well as diesel engines and industrial equipment like press machines, lasers and thermoelectric generators. Its headquarters are in Minato, Tokyo, Japan. The corporation was named after the city of Komatsu, Ishikawa, where the company was founded in 1921. Worldwide, the Komatsu Group consists of Komatsu Ltd. and 258 other companies (215 consolidated subsidiaries and 42 companies accounted for by the equity method). Komatsu is the world's second largest manufacturer of construction equipment and mining equipment after Caterpillar Inc.
Learn more about Komatsu
Size
62,774 employees
Industry
NASDAQ

Similar Jobs

More Jobs at Komatsu

More Information Technology Jobs

Find similar IT Cybersecurity Compliance Analyst jobs: