Role Overview:
The role involves end-to-end ownership of SOC 2 Type I and Type II audits, control design and testing, audit coordination, remediation, compliance documentation, and stakeholder management.
Key Responsibilities:
- Own the SOC 2 Type I & Type II audit lifecycle from readiness assessment through audit completion.
- Conduct SOC 2 gap assessments, control reviews, and remediation planning.
- Define and maintain controls aligned with the SOC 2 Trust Services Criteria.
- Coordinate with external auditors and manage audit evidence and information requests.
- Perform control testing, sampling, evidence validation, and control effectiveness reviews.
- Track control gaps, remediation actions, owners, and deadlines.
- Maintain audit-ready policies, procedures, controls, and compliance documentation.
- Report compliance status, control health, risks, and remediation progress to leadership.
- Partner with Engineering, IT, Security, HR, Legal, and business teams on compliance requirements.
- Support continuous improvement and automation of the GRC program.
- Guide junior analysts and control owners on compliance requirements and evidence management.
Required Skills:
- Experience in GRC, IT Audit, Security Compliance, Risk, or Information Security.
- Hands-on experience managing or driving SOC 2 Type I / Type II audits.
- Strong understanding of the SOC 2 Trust Services Criteria.
- Experience in control design, testing, evidence collection, and remediation.
- Experience working with external auditors and internal stakeholders.
- Strong documentation, communication, stakeholder management, and project management skills.
Good to Have:
- Experience with ISO 27001, HIPAA, PCI DSS, or DPDP Act.
- Experience with Vanta, Drata, Scrut, Secureframe, or similar GRC platforms.
- Understanding of security controls across AWS, Azure, or GCP.
- Experience in SaaS, FinTech, B2B technology, or startup environments.
Didn’t find the job appropriate? Report this Job