NTT DATA
Cybersecurity Audit & Compliance Specialist - REMOTE (Ottawa, ON, CA)
Canada · Remote
About this role
Req ID: 387325 NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Cybersecurity Audit & Compliance Specialist - REMOTE to join our team in Ottawa, Ontario (CA-ON), Canada (CA). Cybersecurity Audit & Compliance Specialist Project Overview The Policy, Audits, and Questionnaires (PAQ) team plays a critical role in maintaining enterprise compliance and strengthening customer and regulatory confidence. The team manages the lifecycle of information security policies, supports customer security inquiries, and coordinates internal and external cybersecurity audits and certification activities. This role will support the organization’s audit readiness and compliance efforts by coordinating evidence collection, maintaining accurate documentation, identifying compliance gaps, and working with cross-functional stakeholders to meet the requirements of global information security standards and certification frameworks, including ISO 27001, Cyber Essentials, SOC, ENS (Spain), and other applicable cybersecurity standards Day to Day Responsibilities: Support cybersecurity audit, compliance, and certification projects , ensuring activities and deliverables are completed accurately and on schedule. Support certification and compliance initiatives such as ISO 27001, ENS Spanish security requirements, Cyber Essentials, SOC, and other global information security frameworks and standards . Prepare the organization for internal and external information security audits and coordinate various stages of the audit lifecycle. Partner with cross-functional teams, external advisors, auditors, and vendors to collect, organize, review, validate, and present audit evidence . Analyze cybersecurity requirements across applicable standards, regulations, and corporate policies and provide guidance to stakeholders on compliance expectations. Perform requirements assessments and gap analyses to identify areas of non-compliance or control deficiencies. Develop and recommend appropriate corrective and remediation actions and track identified issues through closure. Evaluate information security provisions within vendor and customer contracts and provide guidance regarding alignment with corporate security policies and standards. Maintain accurate, current, well-organized, and audit-ready compliance documentation, evidence repositories, policies, and supporting records . Coordinate with control owners and business stakeholders to ensure required documentation and evidence are provided within established timelines. Monitor remediation activities and follow up with stakeholders to ensure identified audit findings and compliance gaps are addressed. Assist with initiatives focused on improving the efficiency, quality, consistency, and productivity of cybersecurity compliance, certification, and audit processes. Communicate audit requirements, findings, risks, and remediation status clearly to technical and non-technical stakeholders. Minimum Requirements: 7+ years of strong experience in cybersecurity audit, governance, risk, and compliance (GRC) activities. 3+ years of working knowledge of ISO/IEC 27001 and associated information security controls and certification requirements. 3+ years of experience supporting internal/external audits and security certification programs . 5+ years of strong experience with audit evidence collection, review, validation, and documentation . 3+ years with cybersecurity and information security frameworks and standards such as SOC, Cyber Essentials, ENS, NIST, or similar frameworks . Preferred Skills: Ability to interpret security standards and regulatory requirements and translate them into actionable compliance requirements. Experience conducting requirements assessments, control assessments, and gap analyses . Experience tracking audit findings, corrective actions,
Skills and categories
Listing provided by Himalayas. Verify availability on the source board before applying — Kartavyam aggregates public listings as they appear and does not manage this application.