IT Cybersecurity Compliance Analyst

Komatsu

Milwaukee (WI)

On-site

USD 80,000 - 95,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
401k and/or employee savings
Vacation and holidays
Employee assistance programs
Disability benefits
Life insurance
Learning and development

Job summary

Komatsu is seeking an IT Cybersecurity Compliance Analyst to strengthen security culture, compliance posture, and investigative readiness. You will own the Cybersecurity Awareness Program, drive employee education, phishing simulations, communications, metrics, and engagement across the business.

Additionally, you will support cybersecurity compliance activities, Legal Hold, and eDiscovery processes with a focus on confidentiality and data handling.

Qualifications

  • Bachelor's degree in CS/IS/Cybersecurity or related field.
  • 2+ years in cybersecurity compliance or related field.
  • Experience with Microsoft 365 Legal Hold/eDiscovery.
  • Excellent communication and ability to translate concepts across the business.
  • Experience with phishing simulation tools.
  • Strong email header analysis skills.

Responsibilities

  • Own Cybersecurity Awareness Program strategy, communications, and metrics.
  • Administer Legal Hold and eDiscovery in partnership with Legal, HR, IT.
  • Maintain controls, procedures, evidence, and audit documentation.
  • Develop and analyze awareness metrics and program improvements.
  • Collaborate with cross-functional teams to communicate cyber risks.
  • Support forensic activities with proper custody and confidentiality.
  • Develop annual Awareness Program plan and materials.

Skills

Communication
Phishing simulations
Email header analysis
Cross-functional collaboration
Security awareness

Education

Bachelor's degree

Tools

Microsoft 365
Microsoft Purview

Job description

IT Cybersecurity Compliance Analyst
Job Overview

We are seeking an IT Cybersecurity Compliance Analyst to join our Cybersecurity team and play a key role in strengthening our security culture, compliance posture, and investigative readiness. This role will own and mature the organization's Cybersecurity Awareness Program, driving employee education, phishing simulations, communications, metrics, and engagement across the business. In addition, this individual will support cybersecurity compliance activities, Legal Hold and eDiscovery processes, audit evidence collection, and authorized forensic support while ensuring sensitive information and evidence are handled with the highest level of confidentiality and care.

This is a great opportunity for someone who enjoys blending cybersecurity, compliance, communication, and cross-functional partnership to help employees understand cyber risk and build stronger security behaviors across the organization.

Key Job Responsibilities
  • Serve as the primary owner for the Cybersecurity Awareness Program, responsible for strategy, communications, employee engagement, phishing simulations, training, metrics, and continuous program maturity across the organization.
  • Administer the cybersecurity responsibilities associated with the Legal Hold and eDiscovery lifecycle in partnership with Legal, HR, and IT, including intake, custodian identification, preservation, tracking, periodic validation, release coordination, documentation, and chain-of-custody requirements.
  • Maintain assigned cybersecurity controls, procedures, evidence, and documentation in support of the organization's compliance, certification, and internal and external audit activities.
  • Develop and analyze cybersecurity awareness, training, phishing, Legal Hold, and compliance metrics to measure effectiveness, identify behavioral and compliance risks, and recommend improvements.
  • Support authorized forensic and investigative activities while protecting confidentiality, integrity, appropriate custody, and secure handling of sensitive information, devices, and evidence.
  • Build relationships across business units to effectively communicate cyber risks, coordinate awareness initiatives, and drive employee understanding and behavioral change.
  • Develop and execute the annual Cybersecurity Awareness Program plan, including enterprise communications, training, phishing simulations, events, campaigns, and targeted education.
  • Develop and publish effective cybersecurity awareness materials that educate employees about current cybersecurity risks, threats, policies, and expected behaviors.
  • Coordinate translations of cybersecurity awareness and education content with global awareness liaisons and appropriate business partners.
  • Collaborate with communications, marketing, technical teams, and business stakeholders to produce accurate, accessible, and appropriately branded awareness materials.
  • Develop and analyze awareness, training, phishing, and engagement metrics to measure effectiveness, identify behavioral risks, and recommend program improvements.
  • Administer the operational lifecycle of approved Legal Hold and eDiscovery requests in partnership with Legal, HR, and IT, including intake, custodian identification, preservation coordination, tracking, periodic validation, release coordination, and final documentation.
  • Administer or support eDiscovery and Legal Hold activities within Microsoft 365, including relevant content maintained in Exchange, OneDrive, SharePoint, and Teams.
  • Maintain Legal Hold and eDiscovery procedures, matter records, preservation documentation, status tracking, and stakeholder communications.
  • Support authorized forensic imaging activities, maintain chain-of-custody documentation, and manage the secure labeling, storage, custody status, and tracking of devices, evidence, and retained assets associated with Legal Hold and forensic matters.
  • Maintain assigned cybersecurity controls, procedures, evidence, and related documentation in support of SOC 2, ISO 27001, and other applicable compliance and certification activities.
  • Support internal and external audits by gathering and producing evidence associated with cybersecurity awareness, training, Legal Hold, eDiscovery, and assigned security controls.
  • Analyze cybersecurity compliance data and develop metrics that identify risks, demonstrate control effectiveness, and support continuous improvement.
Qualifications/Requirements
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Information Assurance, Communications, Business, or a related field, or an equivalent combination of education and relevant experience.
  • Two or more years of experience in cybersecurity compliance, cybersecurity awareness, eDiscovery, information governance, security operations, or related cybersecurity function.
  • Experience administering or supporting Legal Hold and eDiscovery activities within Microsoft 365, including Microsoft Purview and content maintained in Exchange, OneDrive, SharePoint, and Teams, preferred.[DC6.1]
  • Excellent communication, interpersonal skills, especially the translation of cybersecurity concepts to all levels of the business
  • Ability to maintain security control documentation
  • Experience with industry recognized phishing simulation tools
  • Strong understanding of email header analysis to look for indicators of phishing
Hiring Range

At Komatsu, your base pay is one part of your total compensation package. This role pays $80,000-95,000. The actual offer will consider a wide range of factors, including experience and location.

Company Benefits

Komatsu provides an extensive and robust employee benefits package that is designed to enhance the well-being of our employees and family members. We embrace a positive and empowering employee experience with a culture that prides itself on a diverse and inclusive environment.

  • Health benefits: Medical, dental, vision, HSA, wellness programs, etc.
  • 401k and/or employee savings programs
  • Employee time off (vacation and designated holidays)
  • Employee and family assistance programs
  • Disability benefits
  • Life insurance
  • Employee learning and development programs
Diversity & Inclusion Commitment

At Komatsu, we come from diverse backgrounds, with unique perspectives, experiences and contributions. We believe that our people are part of our shared purpose. Connected by our core values of ambition, perseverance, collaboration and authenticity, we are committed to continually advancing in our support of diversity and inclusion. United, we are on a journey towards a sustainable future that creates value together.

Company Information

Komatsu develops and supplies technologies, equipment and services for the construction, mining, forklift, industrial and forestry markets. Headquartered in Tokyo, Japan, Komatsu employs more than 64,000 people worldwide, operating in more than 140 countries. For more than a century, the company has been creating value for its customers through manufacturing and technology innovation, partnering with others to empower a sustainable future where people, business and the planet thrive together. Since the company's founding in 1921, Komatsu has been committed to supporting individuals and communities through job training, skills development and giving back. As a Komatsu employee, you will be encouraged to grow alongside our global company, contributing to a more sustainable future for all. If you are looking for a company that values your talent and potential, join Komatsu to be a part of something big and help advance modern society. Learn more at www.komatsu.com.

EEO Statement

Komatsu is an Equal Opportunity Workplace and an Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Cybersecurity Compliance Analyst
IT Cybersecurity Compliance Analyst

Komatsu • Chicago (IL)

On-site
USD 80,000 - 95,000
Health benefits
401k and/or employee savings programs
Paid vacation and holidays
+4
IT Cybersecurity Compliance Analyst
IT Cybersecurity Compliance Analyst

Komatsu America Corp. • United States

On-site
USD 80,000 - 95,000
401k plan
Paid time off
Employee assistance program
+3
Legal Operations Coordinator
Legal Operations Coordinator

Komatsu • Chicago (IL)

Hybrid
USD 55,000 - 68,000
Health benefits
401k matching
Paid time off
+4
Legal Operations Coordinator
Legal Operations Coordinator

Komatsu America Corp. • Chicago (IL)

Hybrid
USD 55,000 - 68,000
401k and savings programs
Employee time off
Assistance programs
+3
Senior Technical Information Specialist
Senior Technical Information Specialist

Komatsu • Longview (TX)

On-site
USD 90,000 - 120,000
Health benefits
401k and/or savings programs
Vacation and holidays
+4
Senior Technical Information Specialist
Senior Technical Information Specialist

Komatsu • Milwaukee (WI)

On-site
USD 90,000 - 130,000
Health benefits
401k and/or employee savings programs
Vacation and holidays
Human Resources Manager
Human Resources Manager

Komatsu North America • Milwaukee (WI)

On-site
USD 100,000 - 124,000
401(k) and savings programs
Vacation and holidays
Employee assistance programs
+3
Senior Technical Information Specialist
Senior Technical Information Specialist

Joy Global Longview Ops • Milwaukee (WI)

On-site
USD 90,000 - 120,000
401k benefits
Vacation & holidays
Employee assistance programs
+3
IT Manager, WFM/HCM
IT Manager, WFM/HCM

Komatsu Mining Corp. • Chicago (IL)

On-site
USD 140,000 - 170,000
401k/retirement plan
Paid time off
Human Resources Manager
Human Resources Manager

Komatsu Mining Corp. • Chicago (IL)

On-site
USD 100,000 - 130,000
401k plan
Vacation & holidays
Employee assistance programs
+3