About the Role
As a member of Grant Thornton’s Cybersecurity Internal Audit team, you will collaborate with clients to deliver consulting and advisory services across a broad spectrum of cybersecurity areas. You will support clients in evaluating and enhancing their Cybersecurity risk posture through internal audits, control testing, and maturity assessments, working closely with cross-functional teams to assess risks, test controls, and provide actionable insights aligned with industry standards and regulatory frameworks.
Responsibilities
- Assist in planning and executing Cybersecurity internal audits, risk assessments, and control testing engagements.
- Lead walkthroughs, interviews, and workshops with client stakeholders to understand security processes and technology environments.
- Perform Cybersecurity control testing and Cybersecurity program capability assessments.
- Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC 27001, COBIT, and HITRUST.
- Support assessments for regulatory compliance including HIPAA, FedRAMP, GLBA, GDPR, and state-led data breach notification laws.
- Document process, risk and control improvement considerations, develop risk-based recommendations, and develop client deliverables.
- Identify emerging technology risks (i.e., AI, Cloud, Quantum-computing risks), deep-dive into AI model risks, supply-chain risks, document control deficiencies and develop risk mitigation strategies.
- Develop roadmaps to help clients mitigate Cyber risks and enhance overall Cybersecurity posture.
- Stay current on Cybersecurity trends, threat landscapes, and regulatory developments, including technical familiarity with common Cybersecurity tools, cloud environment/architecture, and threat vectors.
- Provide mentorship and training to junior team members by reviewing their work, offering guidance on risk assessment methodologies, and supporting their professional development.
- Contribute to project management tasks such as scheduling, documentation, and status reporting.
- Support client engagements from start to finish, including planning, fieldwork (including control testing), and reporting.
- Participate in professional development activities and training sessions on a regular basis.
- Assist with business development initiatives, including proposal preparation, research, and developing client presentations.
- Adhere to the highest degree of professional standards and strict client confidentiality.
- Other job duties as assigned.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field is required.
- Experience as a client serving professional for a consulting firm desired.
- Ability to travel to client locations (as needed).
Skills
- Cybersecurity
- Internal Audit
- IT Risk
- NIST CSF
- NIST 800-53
- NIST 800-171
- NIST AI RMF
- CSA CCM
- ISO/IEC 27001
- ISO/IEC 27002
- HIPAA
- FedRAMP
- GLBA
- COBIT
- HITRUST
- PCI DSS
- IT
- AI
- Cloud Security
- Data Protection
- Vulnerability Management
- Incident Response
- Cloud Shared Responsibility Model
- Communication (oral and written)
- Presentation Delivery
- Project Management
Location
- Hybrid
Work Type
- Hybrid
Experience Level
- 3+ years of experience in Cybersecurity, internal audit, or IT risk.
Education Level
- Master’s degree in Cybersecurity related field preferred
- CISA, CISSP or similar professional certifications preferred
Salary/Compensations
- $101,200 - $129,030
Benefits
- Personalized and comprehensive benefits that recognize and empower all the identities, roles and aspirations that make you, well, you.
- Work location, weekly schedule, or flex time off options.
- In-person attendance at least three days per week, either at a GT office or client site.
- Work-life integration options.
- Medical, dental and vision insurance programs for interns and seasonal employees.
- Employee assistance program for interns and seasonal employees.
- Paid sick leave for interns and seasonal employees.
- Firm holidays for interns.
- 401(k) savings plan and employee retirement plan for seasonal employees (in accordance with applicable plan terms and eligibility requirements).
- Discretionary, annual bonus based on individual and firm performance (subject to terms, conditions and eligibility criteria).
About the Company
- Grant Thornton believes in making business more personal and building trust into every result.
- Offers a career path with more opportunity, more flexibility, and more support.
- In the U.S., Grant Thornton delivers professional services through Grant Thornton LLP (audit and assurance) and Grant Thornton Advisors LLC (tax and advisory).
- Part of a multinational, multidisciplinary platform with Grant Thornton Ireland, offering a premier Trans-Atlantic advisory and tax practice.
- Platform has $2.7 billion in revenues and more than 50 offices spanning the U.S., Ireland and other territories.
- Provides a singular client experience with enhanced solutions and capabilities, backed by powerful technologies and 12,000 quality-driven professionals.
- Part of the Grant Thornton International Limited network, providing access to member firms in more than 150 global markets.
Equal Opportunity
- All personnel decisions are made without regard to race, color, religion, national origin, sex, age, marital or civil union status, pregnancy or pregnancy-related condition, sexual orientation, gender identity or expression, citizenship status, veteran status, disability, handicap, genetic predisposition or any other characteristic protected by applicable federal, state, or local law.
- Provides reasonable accommodation when requested by a qualified applicant or employee with a disability, unless such accommodation would cause an undue hardship.
- For Los Angeles Applicants only: Will consider for employment all qualified Applicants, including those with Criminal Histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance.
- For Massachusetts Applicants only: It is unlawful in Massachusetts to require or administer a lie detector test as condition of employment or continued employment. Gran Thornton does not require or administer lie detector tests as a condition of employments or continued employment.
