IT Cybersecurity Compliance Analyst

Komatsu

Chicago (IL)

On-site

USD 80,000 - 95,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
401k and/or employee savings programs
Paid vacation and holidays
Employee assistance programs
Disability benefits
Life insurance
Learning and development programs

Job summary

Komatsu is seeking an IT Cybersecurity Compliance Analyst to lead the Cybersecurity Awareness Program, drive employee education, phishing simulations, and engagement while supporting Legal Hold and eDiscovery activities within Microsoft 365. The role emphasizes cross-functional collaboration, data-driven metrics, and strong confidentiality for sensitive information.

The ideal candidate has 2+ years in cybersecurity compliance, excellent communication, and a solid understanding of phishing

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Information Assurance, Communications, Business, or related field.
  • Two+ years of experience in cybersecurity compliance, awareness, eDiscovery, information governance, security ops, or related function.
  • Experience with Microsoft 365 eDiscovery, including Purview.
  • Excellent communication, interpersonal skills, capable of translating cybersecurity concepts to all business levels.
  • Ability to maintain security control documentation.
  • Experience with phishing simulation tools.
  • Strong understanding of email header analysis for phishing indicators.

Responsibilities

  • Own the Cybersecurity Awareness Program: strategy, communications, engagement, phishing simulations, training, metrics, and program maturity.
  • Administer Legal Hold and eDiscovery lifecycle with Legal, HR, and IT: intake, custodian ID, preservation, tracking, validation, release coordination, documentation, chain-of-custody.
  • Maintain cybersecurity controls, procedures, evidence, and documentation for audits and certifications (SOC 2, ISO 27001).
  • Develop and analyze awareness, training, phishing, and compliance metrics; identify risks and improvements.
  • Support forensic and investigative activities while protecting confidentiality and custody of evidence.
  • Build cross-functional relationships to communicate cyber risks and drive awareness initiatives.
  • Develop and execute annual Cybersecurity Awareness Program plan and materials.
  • Coordinate translations of awareness content with global liaisons and business partners.
  • Collaborate with communications, marketing, and technical teams to produce branded materials.
  • Maintain or support eDiscovery in Microsoft 365 (Exchange, OneDrive, SharePoint, Teams) and preserve matter records.
  • Support forensic imaging activities and maintain chain-of-custody documentation.
  • Support audits by gathering and producing evidence related to awareness, training, and controls.
  • Analyze cybersecurity compliance data to identify risks and drive continuous improvement.

Skills

Cybersecurity awareness
Phishing simulations
Communication skills
Security controls

Education

Bachelor's degree in CS/IS/Cybersecurity

Tools

Microsoft Purview
Exchange/OneDrive/SharePoint/Teams

Job description

IT Cybersecurity Compliance Analyst
Job Overview

We are seeking an IT Cybersecurity Compliance Analyst to join our Cybersecurity team and play a key role in strengthening our security culture, compliance posture, and investigative readiness. This role will own and mature the organization's Cybersecurity Awareness Program, driving employee education, phishing simulations, communications, metrics, and engagement across the business. In addition, this individual will support cybersecurity compliance activities, Legal Hold and eDiscovery processes, audit evidence collection, and authorized forensic support while ensuring sensitive information and evidence are handled with the highest level of confidentiality and care.

This is a great opportunity for someone who enjoys blending cybersecurity, compliance, communication, and cross-functional partnership to help employees understand cyber risk and build stronger security behaviors across the organization.

Key Job Responsibilities
  • Serve as the primary owner for the Cybersecurity Awareness Program, responsible for strategy, communications, employee engagement, phishing simulations, training, metrics, and continuous program maturity across the organization.
  • Administer the cybersecurity responsibilities associated with the Legal Hold and eDiscovery lifecycle in partnership with Legal, HR, and IT, including intake, custodian identification, preservation, tracking, periodic validation, release coordination, documentation, and chain-of-custody requirements.
  • Maintain assigned cybersecurity controls, procedures, evidence, and documentation in support of the organization's compliance, certification, and internal and external audit activities.
  • Develop and analyze cybersecurity awareness, training, phishing, Legal Hold, and compliance metrics to measure effectiveness, identify behavioral and compliance risks, and recommend improvements.
  • Support authorized forensic and investigative activities while protecting confidentiality, integrity, appropriate custody, and secure handling of sensitive information, devices, and evidence.
  • Build relationships across business units to effectively communicate cyber risks, coordinate awareness initiatives, and drive employee understanding and behavioral change.
  • Develop and execute the annual Cybersecurity Awareness Program plan, including enterprise communications, training, phishing simulations, events, campaigns, and targeted education.
  • Develop and publish effective cybersecurity awareness materials that educate employees about current cybersecurity risks, threats, policies, and expected behaviors.
  • Coordinate translations of cybersecurity awareness and education content with global awareness liaisons and appropriate business partners.
  • Collaborate with communications, marketing, technical teams, and business stakeholders to produce accurate, accessible, and appropriately branded awareness materials.
  • Develop and analyze awareness, training, phishing, and engagement metrics to measure effectiveness, identify behavioral risks, and recommend program improvements.
  • Administer the operational lifecycle of approved Legal Hold and eDiscovery requests in partnership with Legal, HR, and IT, including intake, custodian identification, preservation coordination, tracking, periodic validation, release coordination, and final documentation.
  • Administer or support eDiscovery and Legal Hold activities within Microsoft 365, including relevant content maintained in Exchange, OneDrive, SharePoint, and Teams.
  • Maintain Legal Hold and eDiscovery procedures, matter records, preservation documentation, status tracking, and stakeholder communications.
  • Support authorized forensic imaging activities, maintain chain-of-custody documentation, and manage the secure labeling, storage, custody status, and tracking of devices, evidence, and retained assets associated with Legal Hold and forensic matters.
  • Maintain assigned cybersecurity controls, procedures, evidence, and related documentation in support of SOC 2, ISO 27001, and other applicable compliance and certification activities.
  • Support internal and external audits by gathering and producing evidence associated with cybersecurity awareness, training, Legal Hold, eDiscovery, and assigned security controls.
  • Analyze cybersecurity compliance data and develop metrics that identify risks, demonstrate control effectiveness, and support continuous improvement.
Qualifications/Requirements
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Information Assurance, Communications, Business, or a related field, or an equivalent combination of education and relevant experience.
  • Two or more years of experience in cybersecurity compliance, cybersecurity awareness, eDiscovery, information governance, security operations, or related cybersecurity function.
  • Experience administering or supporting Legal Hold and eDiscovery activities within Microsoft 365, including Microsoft Purview and content maintained in Exchange, OneDrive, SharePoint, and Teams, preferred.[DC6.1]
  • Excellent communication, interpersonal skills, especially the translation of cybersecurity concepts to all levels of the business
  • Ability to maintain security control documentation
  • Experience with industry recognized phishing simulation tools
  • Strong understanding of email header analysis to look for indicators of phishing
Hiring Range

At Komatsu, your base pay is one part of your total compensation package. This role pays $80,000-95,000. The actual offer will consider a wide range of factors, including experience and location.

Company Benefits

Komatsu provides an extensive and robust employee benefits package that is designed to enhance the well-being of our employees and family members. We embrace a positive and empowering employee experience with a culture that prides itself on a diverse and inclusive environment.

  • Health benefits: Medical, dental, vision, HSA, wellness programs, etc.
  • 401k and/or employee savings programs
  • Employee time off (vacation and designated holidays)
  • Employee and family assistance programs
  • Disability benefits
  • Life insurance
  • Employee learning and development programs
Diversity & Inclusion Commitment

At Komatsu, we come from diverse backgrounds, with unique perspectives, experiences and contributions. We believe that our people are part of our shared purpose. Connected by our core values of ambition, perseverance, collaboration and authenticity, we are committed to continually advancing in our support of diversity and inclusion. United, we are on a journey towards a sustainable future that creates value together.

Company Information

Komatsu develops and supplies technologies, equipment and services for the construction, mining, forklift, industrial and forestry markets. Headquartered in Tokyo, Japan, Komatsu employs more than 64,000 people worldwide, operating in more than 140 countries. For more than a century, the company has been creating value for its customers through manufacturing and technology innovation, partnering with others to empower a sustainable future where people, business and the planet thrive together. Since the company's founding in 1921, Komatsu has been committed to supporting individuals and communities through job training, skills development and giving back. As a Komatsu employee, you will be encouraged to grow alongside our global company, contributing to a more sustainable future for all. If you are looking for a company that values your talent and potential, join Komatsu to be a part of something big and help advance modern society. Learn more at www.komatsu.com.

EEO Statement

Komatsu is an Equal Opportunity Workplace and an Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Cybersecurity Compliance Analyst
IT Cybersecurity Compliance Analyst

Komatsu • Milwaukee (WI)

On-site
USD 80,000 - 95,000
Health benefits
401k and/or employee savings
Vacation and holidays
+4
IT Cybersecurity Compliance Analyst
IT Cybersecurity Compliance Analyst

Komatsu America Corp. • United States

On-site
USD 80,000 - 95,000
401k plan
Paid time off
Employee assistance program
+3
Legal Operations Coordinator
Legal Operations Coordinator

Komatsu • Chicago (IL)

Hybrid
USD 55,000 - 68,000
Health benefits
401k matching
Paid time off
+4
Legal Operations Coordinator
Legal Operations Coordinator

Komatsu America Corp. • Chicago (IL)

Hybrid
USD 55,000 - 68,000
401k and savings programs
Employee time off
Assistance programs
+3
Senior Technical Information Specialist
Senior Technical Information Specialist

Komatsu • Longview (TX)

On-site
USD 90,000 - 120,000
Health benefits
401k and/or savings programs
Vacation and holidays
+4
Senior Technical Information Specialist
Senior Technical Information Specialist

Komatsu • Milwaukee (WI)

On-site
USD 90,000 - 130,000
Health benefits
401k and/or employee savings programs
Vacation and holidays
Human Resources Manager
Human Resources Manager

Komatsu North America • Milwaukee (WI)

On-site
USD 100,000 - 124,000
401(k) and savings programs
Vacation and holidays
Employee assistance programs
+3
Senior Technical Information Specialist
Senior Technical Information Specialist

Joy Global Longview Ops • Milwaukee (WI)

On-site
USD 90,000 - 120,000
401k benefits
Vacation & holidays
Employee assistance programs
+3
IT Manager, WFM/HCM
IT Manager, WFM/HCM

Komatsu Mining Corp. • Chicago (IL)

On-site
USD 140,000 - 170,000
401k/retirement plan
Paid time off
Senior HR Manager
Senior HR Manager

Komatsu • Mesa (AZ)

On-site
USD 120,000 - 180,000
Health benefits
401k plan
Paid time off
+1