Cybersecurity Associate Consultant (Cyber Audit)
Summary
Assist senior consultants with cybersecurity audits (ISO 27001, MAS TRM, Cyber Trust Mark) and compliance exercises, documenting controls and preparing reports while learning security frameworks and client interactions.
Responsibilities:
• Support Seniors and Consultants with onsite assessments, such as Cyber Trust Mark, MAS TRM, Cyber Hygiene notices/circulars, ISO 27001, ISO 42001. Maturity Assessment, Data Privacy advisory, Social Engineering exercises and NIST CSF engagements
• Learn and manage client relationships and expectations with effective communication
• Coordinate day-to-day operations with Seniors, Consultants and clients (i.e. schedule and participate in meetings; create agendas; develop document request lists; document walkthrough narratives, control designs and tests of operating effectiveness)
• Assist Senior Consultants and Consultants with the preparation and review of draft reports
• Assist with audit quality and assurance procedures
• Utilise base knowledge of information security systems, risks and controls
• Perform other administrative duties and assist with internal initiatives as assigned
Requirements:
• Bachelor’s degree or Diploma from an accredited institution in IT, cybersecurity, accounting, data analytics, information systems or a related field
• Coursework, final-year projects, internships, CTF participation or self-directed study touching on information security, IT audit or a related field will be viewed favourably
• Awareness of ISO 27001 / Cyber Trust Mark / MAS TRM / SOC / ISO 42001 / NIST — familiarity is welcome, but formal knowledge will be taught
• Working knowledge of Windows OS, Linux and at least one cloud platform (AWS, GCP or Azure); exposure to SQL Server is an advantage
• Understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, the OSI model, defence-in-depth and common security elements
• Excellent interpersonal, written and verbal communication skills
• Strong time-management skills, with the ability to juggle multiple tasks and priorities
• A self-starter with a solution-oriented mindset, comfortable in a fast-paced environment where goals are well-defined but formal procedures may be limited
• A team player, receptive to feedback and coaching, passionate about the BDO mission, with an innovative mindset
• Working toward, or intending to work toward, certifications such as CISA, CISSP, CISM, CRISC, CDPSE, CIPM, CIPT, CSX-F, PCI QSA or others related to information security, AI governance and audit