SOC2 Compliance Specialist

Remote • Posted 2 hours ago • Updated 2 hours ago
Contract W2
Remote
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Professional Services
  • Embedded Systems
  • System Integration Testing
  • Scratch
  • Gap Analysis
  • Regulatory Compliance
  • System On A Chip
  • Fluency
  • Identity Management
  • Change Management
  • Incident Management
  • Vendor Management
  • Management
  • Collaboration
  • Bridging
  • SAP GRC
  • Amazon Web Services
  • Encryption
  • Network
  • Continuous Integration
  • Continuous Delivery
  • Artificial Intelligence

Summary

Our client, a large professional services firm, is looking to hire a remote SOC2 Compliance Specialist for a 6-month contract. The SOC2 compliance Specialist is being brought in to expand the scope of our SOC2 Type II program to cover additional systems built by the client's Client Apps team. This is a hands-on, embedded engagement in which the consultant will sit with the Client Apps product team day to day and act as its primary interface to the internal security organization (ITSec), which owns the corporate program.

This is not a readiness-from-scratch project. The company maintains SOC2 compliance today, with the corporate program owned and managed by ITSec. The work is scope expansion, ensuring newly added systems conform to that program, inheriting corporate-level controls where possible, and standing up team-level controls only where needed.

Responsibilities:

  • Assess Client Apps systems against the AICPA Trust Services Criteria (Security at minimum) and produce a gap analysis with a pragmatic remediation plan.
  • Design and document team-level controls where corporate controls can't be inherited, covering access management, change management, logging and monitoring, incident response, and vendor management.
  • Prepare control narratives, evidence, and monitoring materials in the format ITSec expects, aligned to how their compliance platform structures controls and evidence.
  • Serve as the working interface between the Client Apps team and ITSec: answer their questions credibly, adapt controls to their requirements, and build a productive relationship.
  • Support auditor requests through the observation period, answering questions from primary sources rather than secondhand summaries.
  • Verify how controls are actually implemented by reading our application code and AWS CloudFormation templates (read-only), including IAM, encryption, network boundaries, and CI/CD gates.
  • Deliver clear written artifacts throughout: control narratives, gap analyses, and status updates that auditors, ITSec, and engineers can all consume.

Required Skills:

  • SOC2 Type II experience. Hands-on experience driving SOC2 compliance through at least one full Type II observation period: control design, evidence collection, operating controls consistently, and handling auditor requests.
  • Scope-expansion experience. Experience adding new products or systems to an existing SOC2 program, not just greenfield readiness. You know how to inherit corporate-level controls where possible and stand up team-level controls only where needed.
  • Trust Services Criteria fluency. Working knowledge of the AICPA Trust Services Criteria (Security at minimum) and the ability to translate them into concrete technical controls: access management, change management, logging and monitoring, incident response, and vendor management.
  • Drata familiarity. Familiarity with Drata or a directly comparable platform (Vanta, Secureframe). ITSec manages client's program in Drata, and direct access for this role isn't guaranteed, so you must understand how Drata structures controls, evidence, and monitoring well enough to prepare materials in the format ITSec expects, whether or not you're working in the platform directly.
  • Collaboration and diplomacy. Strong collaboration skills with internal security teams. You'll be the primary interface between our team and ITSec, building trust where the relationship has friction, answering their questions credibly, and adapting our controls to meet their requirements. Prior success bridging a product team and a security/GRC organization is a strong signal, and it matters as much as the technical qualifications.
  • Technical literacy. Enough technical depth to answer ITSec and auditor questions from primary sources. Comfortable using read-only access to application code and AWS CloudFormation templates to verify how controls are implemented: IAM, encryption, network boundaries, and CI/CD gates.
  • AI-assisted tooling. Comfortable using AI-assisted tooling (we use Claude) to search and interrogate our codebase
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10121117
  • Position Id: 19164
  • Posted 2 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Full-time

USD 130,000.00 - 150,000.00 per year

Remote

Today

Full-time

USD 117,500.00 - 166,250.00 per year

Remote

Today

Full-time

USD 84,000.00 - 117,000.00 per year

Remote

10d ago

Easy Apply

Contract

Depends on Experience

Search all similar jobs