Job Description
IT Cybersecurity Compliance Analyst
Posting Start Date:  9/2/26
Job Location (Short):  Chicago, Illinois, USA, 60631 | Milwaukee, Wisconsin, USA, 53204-2941
Requisition ID:  36849
Onsite or Remote:  Onsite Position

Join Komatsu and Be Part of Something Big!

Job Overview

We are seeking an IT Cybersecurity Compliance Analyst to join our Cybersecurity team and play a key role in strengthening our security culture, compliance posture, and investigative readiness. This role will own and mature the organization’s Cybersecurity Awareness Program, driving employee education, phishing simulations, communications, metrics, and engagement across the business. In addition, this individual will support cybersecurity compliance activities, Legal Hold and eDiscovery processes, audit evidence collection, and authorized forensic support while ensuring sensitive information and evidence are handled with the highest level of confidentiality and care.

This is a great opportunity for someone who enjoys blending cybersecurity, compliance, communication, and cross-functional partnership to help employees understand cyber risk and build stronger security behaviors across the organization.

Key Job Responsibilities

•    Serve as the primary owner for the Cybersecurity Awareness Program, responsible for strategy, communications, employee engagement, phishing simulations, training, metrics, and continuous program maturity across the organization.
•    Administer the cybersecurity responsibilities associated with the Legal Hold and eDiscovery lifecycle in partnership with Legal, HR, and IT, including intake, custodian identification, preservation, tracking, periodic validation, release coordination, documentation, and chain-of-custody requirements.
•    Maintain assigned cybersecurity controls, procedures, evidence, and documentation in support of the organization’s compliance, certification, and internal and external audit activities.
•    Develop and analyze cybersecurity awareness, training, phishing, Legal Hold, and compliance metrics to measure effectiveness, identify behavioral and compliance risks, and recommend improvements.
•    Support authorized forensic and investigative activities while protecting confidentiality, integrity, appropriate custody, and secure handling of sensitive information, devices, and evidence.
•    Build relationships across business units to effectively communicate cyber risks, coordinate awareness initiatives, and drive employee understanding and behavioral change.

•    Develop and execute the annual Cybersecurity Awareness Program plan, including enterprise communications, training, phishing simulations, events, campaigns, and targeted education.
•    Develop and publish effective cybersecurity awareness materials that educate employees about current cybersecurity risks, threats, policies, and expected behaviors.
•    Coordinate translations of cybersecurity awareness and education content with global awareness liaisons and appropriate business partners.
•    Collaborate with communications, marketing, technical teams, and business stakeholders to produce accurate, accessible, and appropriately branded awareness materials.
•    Develop and analyze awareness, training, phishing, and engagement metrics to measure effectiveness, identify behavioral risks, and recommend program improvements.
•    Administer the operational lifecycle of approved Legal Hold and eDiscovery requests in partnership with Legal, HR, and IT, including intake, custodian identification, preservation coordination, tracking, periodic validation, release coordination, and final documentation.
•    Administer or support eDiscovery and Legal Hold activities within Microsoft 365, including relevant content maintained in Exchange, OneDrive, SharePoint, and Teams.
•    Maintain Legal Hold and eDiscovery procedures, matter records, preservation documentation, status tracking, and stakeholder communications.
•    Support authorized forensic imaging activities, maintain chain-of-custody documentation, and manage the secure labeling, storage, custody status, and tracking of devices, evidence, and retained assets associated with Legal Hold and forensic matters.
•    Maintain assigned cybersecurity controls, procedures, evidence, and related documentation in support of SOC 2, ISO 27001, and other applicable compliance and certification activities.
•    Support internal and external audits by gathering and producing evidence associated with cybersecurity awareness, training, Legal Hold, eDiscovery, and assigned security controls.
•    Analyze cybersecurity compliance data and develop metrics that identify risks, demonstrate control effectiveness, and support continuous improvement.

Qualifications/Requirements

•    Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Information Assurance, Communications, Business, or a related field, or an equivalent combination of education and relevant experience.
•    Two or more years of experience in cybersecurity compliance, cybersecurity awareness, eDiscovery, information governance, security operations, or related cybersecurity function.
•    Experience administering or supporting Legal Hold and eDiscovery activities within Microsoft 365, including Microsoft Purview and content maintained in Exchange, OneDrive, SharePoint, and Teams, preferred.[DC6.1]
•    Excellent communication, interpersonal skills, especially the translation of cybersecurity concepts to all levels of the business
•    Ability to maintain security control documentation
•    Experience with industry recognized phishing simulation tools
•    Strong understanding of email header analysis to look for indicators of phishing

Additional Information

 

Hiring Range 

At Komatsu, your base pay is one part of your total compensation package. This role pays $80,000-95,000. The actual offer will consider a wide range of factors, including experience and location.

 

Company Benefits 

Komatsu provides an extensive and robust employee benefits package that is designed to enhance the well-being of our employees and family members. We embrace a positive and empowering employee experience with a culture that prides itself on a diverse and inclusive environment.

  • Health benefits: Medical, dental, vision, HSA, wellness programs, etc.
  • 401k and/or employee savings programs
  • Employee time off (vacation and designated holidays)
  • Employee and family assistance programs
  • Disability benefits
  • Life insurance
  • Employee learning and development programs

 

Diversity & Inclusion Commitment 

At Komatsu, we come from diverse backgrounds, with unique perspectives, experiences and contributions.  We believe that our people are part of our shared purpose. Connected by our core values of ambition, perseverance, collaboration and authenticity, we are committed to continually advancing in our support of diversity and inclusion. United, we are on a journey towards a sustainable future that creates value together.  

 

Company Information 

Komatsu develops and supplies technologies, equipment and services for the construction, mining, forklift, industrial and forestry markets. Headquartered in Tokyo, Japan, Komatsu employs more than 64,000 people worldwide, operating in more than 140 countries. For more than a century, the company has been creating value for its customers through manufacturing and technology innovation, partnering with others to empower a sustainable future where people, business and the planet thrive together. Since the company’s founding in 1921, Komatsu has been committed to supporting individuals and communities through job training, skills development and giving back. As a Komatsu employee, you will be encouraged to grow alongside our global company, contributing to a more sustainable future for all. If you are looking for a company that values your talent and potential, join Komatsu to be a part of something big and help advance modern society. Learn more at www.komatsu.com.  

 

EEO Statement 

Komatsu is an Equal Opportunity Workplace and an Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.