10/1/26
Apply now
- Start applying with LinkedIn
- Apply Now
Start
- Please wait...
Job Type: Permanent
Work Model: Remote
Reference code: 135343
Primary Location: Toronto, ON
All Available Locations: Toronto, ON
What will your typical day look like?Work you'll do- Support execution of the Control Testing Program, including automated control testing (e.g. identifying tool integration opportunities and mapping source systems so they can provide continuous automated results), alongside manual, effectiveness-based testing of security controls.
- Maintain and update the control testing framework, including control-to-standard mappings, technical test queries, policy configuration checks, and clearly defined pass/fail criteria.
- Perform control testing across identity, endpoint, network, and infrastructure-based controls, including evidence collection, validation, and documentation.
- Apply risk management experience to understand how tested controls contribute to risk reduction, assess the impact of control gaps, and support risk-based prioritization of remediation activities.
- Perform compliance validation of risk remediation activities submitted by risk and control owners, assessing whether the evidence provided adequately closes the identified gap.
- Follow up proactively with risk and control owners on outstanding remediation activities, tracking progress through to closure and escalating overdue items where required.
- Identify, track, and report control gaps, risks, and non-compliance issues to stakeholders, and support the development of remediation recommendations.
- Maintain ServiceNow (or an equivalent GRC/ITSM platform) workflows for remediation tracking and control lifecycle management.
- Collaborate with cross-functional technical and compliance stakeholders to ensure testing is consistent, well-evidenced, and aligned to industry standards (e.g., ISO 27001, NIST SP 80053, CIS Controls, SOC 2).
- Support the Compliance Manager in preparing testing updates, KPI and dashboard inputs, and reporting materials for senior leadership, and contribute to standardized testing templates and methodologies.
- Stay current on control testing methodologies, regulatory developments, and industry best practices to inform testing priorities.
About the teamDeloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in what is but rather what can be to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
Enough about us, let's talk about youQualificationsRequired:- Proven experience in information security, IT risk management, internal audit, compliance, or controls testing roles.
- Experience conducting compliance testing, audits, or control assessments against internal or external standards (e.g., ISO 27001, NIST, CIS Controls, SOC 2).
- Working knowledge of automated control testing tools (e.g., Qualys, Tenable, Rapid7, or similar platforms).
- Experience with GRC or ITSM platforms such as ServiceNow, Archer, MetricStream, or similar for control and remediation tracking.
- Experience with Microsoft security tooling (e.g., Defender for Endpoint, Intune, Sentinel) and/or KQL query writing is advantageous.
- Experience working in a large, global, matrixed organization is an advantage.
- Knowledge of risk and compliance methodologies and cybersecurity fundamentals.
- Strong analytical, problem-solving, and critical thinking skills.
- Excellent written and verbal communication skills, with the ability to summarize complex technical information for diverse stakeholders.
- Strong organizational skills with the ability to manage multiple priorities in a fast-paced environment.
- Collaborative mindset and ability to work effectively across global teams and cultures.
- Proficiency with tools such as ServiceNow, GRC platforms, or compliance testing tools.
Preferred:- Bachelor's degree, or equivalent, in Information Systems, Computer Science, Cybersecurity, Engineering, or a related field.
- Relevant certifications such as ISO 27001 Lead Auditor, CISA, CRISC, Security+, or similar
- Experience with scripting or automation (e.g., PowerShell) to support testing efficiency.
Total RewardsThe salary range for this position is $69,000 - $114,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels. Our approach is grounded on recognizing people's unique strengths and contributions and rewarding the value that they deliver.
Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. On top of our regular paid vacation days, some examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, firm-wide closures known as "Deloitte Days", dedicated days of for learning (known as Development and Innovation Days), flexible work arrangements and a hybrid work structure.