IT Cybersecurity Compliance Analyst
Listed on 2026-09-06
-
IT/Tech
Cybersecurity, Information Security & Data Protection
IT Cybersecurity Compliance Analyst Job Overview
We are seeking an IT Cybersecurity Compliance Analyst to join our Cybersecurity team and play a key role in strengthening our security culture, compliance posture, and investigative readiness. This role will own and mature the organization's Cybersecurity Awareness Program, driving employee education, phishing simulations, communications, metrics, and engagement across the business. In addition, this individual will support cybersecurity compliance activities, Legal Hold and eDiscovery processes, audit evidence collection, and authorized forensic support while ensuring sensitive information and evidence are handled with the highest level of confidentiality and care.
This is a great opportunity for someone who enjoys blending cybersecurity, compliance, communication, and cross-functional partnership to help employees understand cyber risk and build stronger security behaviors across the organization.
Key Job Responsibilities- Serve as the primary owner for the Cybersecurity Awareness Program, responsible for strategy, communications, employee engagement, phishing simulations, training, metrics, and continuous program maturity across the organization.
- Administer the cybersecurity responsibilities associated with the Legal Hold and eDiscovery lifecycle in partnership with Legal, HR, and IT, including intake, custodian identification, preservation, tracking, periodic validation, release coordination, documentation, and chain-of-custody requirements.
- Maintain assigned cybersecurity controls, procedures, evidence, and documentation in support of the organization's compliance, certification, and internal and external audit activities.
- Develop and analyze cybersecurity awareness, training, phishing, Legal Hold, and compliance metrics to measure effectiveness, identify behavioral and compliance risks, and recommend improvements.
- Support authorized forensic and investigative activities while protecting confidentiality, integrity, appropriate custody, and secure handling of sensitive information, devices, and evidence.
- Build relationships across business units to effectively communicate cyber risks, coordinate awareness initiatives, and drive employee understanding and behavioral change.
- Develop and execute the annual Cybersecurity Awareness Program plan, including enterprise communications, training, phishing simulations, events, campaigns, and targeted education.
- Develop and publish effective cybersecurity awareness materials that educate employees about current cybersecurity risks, threats, policies, and expected behaviors.
- Coordinate translations of cybersecurity awareness and education content with global awareness liaisons and appropriate business partners.
- Collaborate with communications, marketing, technical teams, and business stakeholders to produce accurate, accessible, and appropriately branded awareness materials.
- Develop and analyze awareness, training, phishing, and engagement metrics to measure effectiveness, identify behavioral risks, and recommend program improvements.
- Administer the operational lifecycle of approved Legal Hold and eDiscovery requests in partnership with Legal, HR, and IT, including intake, custodian identification, preservation coordination, tracking, periodic validation, release coordination, and final documentation.
- Administer or support eDiscovery and Legal Hold activities within Microsoft 365, including relevant content maintained in Exchange, One Drive, SharePoint, and Teams.
- Maintain Legal Hold and eDiscovery procedures, matter records, preservation documentation, status tracking, and stakeholder communications.
- Support authorized forensic imaging activities, maintain chain-of-custody documentation, and manage the secure labeling, storage, custody status, and tracking of devices, evidence, and retained assets associated with Legal Hold and forensic matters.
- Maintain assigned cybersecurity controls, procedures, evidence, and related documentation in support of SOC 2, ISO 27001, and other applicable compliance and certification activities.
- Support internal and external audits by gathering and producing evidence associated with…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).