IT Risk and Controls Testing Analyst, Deloitte Global Technology

Deloitte

• $69K — $114K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in information security, IT risk management, internal audit, or controls testing roles.
  • Experience with compliance testing against standards like ISO 27001, NIST, or SOC 2.
  • Familiarity with automated control testing tools such as Qualys or Tenable.
  • Proficient in GRC or ITSM platforms like ServiceNow for tracking controls and remediation.
  • Knowledge of Microsoft security tools and KQL query writing is a plus.
  • Experience in a large, global organization is advantageous.
  • Strong analytical and communication skills, with the ability to convey complex information clearly.

Responsibilities

  • Support the execution of the Control Testing Program, including automated and manual testing of security controls.
  • Maintain and update the control testing framework and pass/fail criteria.
  • Perform control testing across various security domains, including evidence collection and documentation.
  • Apply risk management principles to assess control effectiveness and prioritize remediation activities.
  • Validate compliance of risk remediation activities and track progress with stakeholders.
  • Identify and report control gaps and non-compliance issues to relevant parties.
  • Collaborate with cross-functional teams to ensure testing aligns with industry standards.

Benefits

  • $4,000 per year for mental health support benefits.
  • $1,300 flexible benefit spending account.
  • Firm-wide closures known as 'Deloitte Days'.
  • Dedicated days for learning and development.
  • Flexible work arrangements and a hybrid work structure.
Full Job Description
10/1/26

Apply now
  • Start applying with LinkedIn
  • Apply Now


  • Start

  • Please wait...


Job Type: Permanent Work Model: Remote Reference code: 135343 Primary Location: Toronto, ON All Available Locations: Toronto, ON

What will your typical day look like?

Work you'll do
  • Support execution of the Control Testing Program, including automated control testing (e.g. identifying tool integration opportunities and mapping source systems so they can provide continuous automated results), alongside manual, effectiveness-based testing of security controls.
  • Maintain and update the control testing framework, including control-to-standard mappings, technical test queries, policy configuration checks, and clearly defined pass/fail criteria.
  • Perform control testing across identity, endpoint, network, and infrastructure-based controls, including evidence collection, validation, and documentation.
  • Apply risk management experience to understand how tested controls contribute to risk reduction, assess the impact of control gaps, and support risk-based prioritization of remediation activities.
  • Perform compliance validation of risk remediation activities submitted by risk and control owners, assessing whether the evidence provided adequately closes the identified gap.
  • Follow up proactively with risk and control owners on outstanding remediation activities, tracking progress through to closure and escalating overdue items where required.
  • Identify, track, and report control gaps, risks, and non-compliance issues to stakeholders, and support the development of remediation recommendations.
  • Maintain ServiceNow (or an equivalent GRC/ITSM platform) workflows for remediation tracking and control lifecycle management.
  • Collaborate with cross-functional technical and compliance stakeholders to ensure testing is consistent, well-evidenced, and aligned to industry standards (e.g., ISO 27001, NIST SP 80053, CIS Controls, SOC 2).
  • Support the Compliance Manager in preparing testing updates, KPI and dashboard inputs, and reporting materials for senior leadership, and contribute to standardized testing templates and methodologies.
  • Stay current on control testing methodologies, regulatory developments, and industry best practices to inform testing priorities.


About the team

Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in what is but rather what can be to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.

Enough about us, let's talk about you

Qualifications

Required:

  • Proven experience in information security, IT risk management, internal audit, compliance, or controls testing roles.
  • Experience conducting compliance testing, audits, or control assessments against internal or external standards (e.g., ISO 27001, NIST, CIS Controls, SOC 2).
  • Working knowledge of automated control testing tools (e.g., Qualys, Tenable, Rapid7, or similar platforms).
  • Experience with GRC or ITSM platforms such as ServiceNow, Archer, MetricStream, or similar for control and remediation tracking.
  • Experience with Microsoft security tooling (e.g., Defender for Endpoint, Intune, Sentinel) and/or KQL query writing is advantageous.
  • Experience working in a large, global, matrixed organization is an advantage.
  • Knowledge of risk and compliance methodologies and cybersecurity fundamentals.
  • Strong analytical, problem-solving, and critical thinking skills.
  • Excellent written and verbal communication skills, with the ability to summarize complex technical information for diverse stakeholders.
  • Strong organizational skills with the ability to manage multiple priorities in a fast-paced environment.
  • Collaborative mindset and ability to work effectively across global teams and cultures.
  • Proficiency with tools such as ServiceNow, GRC platforms, or compliance testing tools.


Preferred:

  • Bachelor's degree, or equivalent, in Information Systems, Computer Science, Cybersecurity, Engineering, or a related field.
  • Relevant certifications such as ISO 27001 Lead Auditor, CISA, CRISC, Security+, or similar
  • Experience with scripting or automation (e.g., PowerShell) to support testing efficiency.


Total Rewards

The salary range for this position is $69,000 - $114,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels. Our approach is grounded on recognizing people's unique strengths and contributions and rewarding the value that they deliver.

Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. On top of our regular paid vacation days, some examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, firm-wide closures known as "Deloitte Days", dedicated days of for learning (known as Development and Innovation Days), flexible work arrangements and a hybrid work structure.

Similar Jobs

More Jobs at Deloitte

More Information Technology Jobs

Find similar IT Risk and Controls Testing Analyst, Deloitte Global Technology jobs: