- Company Name
- BDO Canada
- Job Title
- Consultant/ Senior Consultant, IT Auditor
- Job Description
-
Job title: Consultant / Senior Consultant – IT Auditor
Role Summary: Conduct and lead IT audit engagements focused on cybersecurity maturity, regulatory compliance, and IT governance, applying frameworks such as CIS Top 18, NIST, ISO 27001, COBIT, and local regulatory guidelines.
Expectations: Deliver high‑quality audit reports and executive summaries, present findings to client stakeholders, support remediation planning, and maintain strong client relationships while managing multiple engagements within deadlines.
Key Responsibilities:
- Review and assess alignment with CIS Top 18, ISO 27001, NIST Cybersecurity Frameworks and Canadian regulatory guidance (DGCM, OSFI, BCFSA).
- Perform maturity scoring and safeguard validation for cybersecurity controls.
- Evaluate user and system access permissions, controls, and physical access across critical systems (GLs, CRM, banking platforms).
- Assess IT governance structures, board oversight, strategy alignment, and policy implementation.
- Evaluate BCP, DRP, and IRP completeness and integration.
- Verify Interac Annual Compliance Certificate requirements.
- Prepare audit reports, executive summaries, and deliver presentations to client stakeholders.
- Collaborate with internal teams for engagement scoping and quality assurance.
Required Skills:
- Proficiency in cybersecurity frameworks (CIS Top 18, NIST, ISO 27001, COBIT).
- Strong analytical, detail‑oriented mindset with gap analysis and maturity modelling expertise.
- Excellent written and verbal communication, including report writing and client presentation skills.
- Ability to manage multiple engagements and meet deadlines.
- Collaborative and client‑focused approach.
Required Education & Certifications:
- Bachelor’s degree in Information Systems, Cybersecurity, or related field.
- Professional certifications preferred: CISA, CISM, CRISC, or equivalent.
- 3–6 years of experience in IT audit, cybersecurity assurance, or risk advisory.
---