Manage ad-hoc SOC 1 and SOC 2 audit engagements for newly acquired products not yet in scope of the enterprise SOC reports * Coordinate document requests, evidence collection timelines, and ...
Manage ad-hoc SOC 1 and SOC 2 audit engagements for newly acquired products not yet in scope of the enterprise SOC reports * Coordinate document requests, evidence collection timelines, and ...
GRC Analyst - 100% Remote - 6+ Month Contract
Rosemont, IL · On-site
$50 - $75/hr
We're hiring two GRC Analysts for a 6+ month contract role helping our end client with an ... Perform a SOC Type 2 Audit/Assessment for their InfoSec environment with a focus on meeting ...
Quick apply
GRC Analyst - 100% Remote - 6+ Month Contract
Rosemont, IL · On-site
$50 - $75/hr
We're hiring two GRC Analysts for a 6+ month contract role helping our end client with an ... Perform a SOC Type 2 Audit/Assessment for their InfoSec environment with a focus on meeting ...
Senior IT Audit & Assurance Analyst
Raleigh, NC · On-site +1
Manage ad-hoc SOC 1 and SOC 2 audit engagements for newly acquired products not yet in scope of the enterprise SOC reports * Coordinate document requests, evidence collection timelines, and ...
Quick apply
Senior IT Audit & Assurance Analyst
Raleigh, NC · On-site +1
Manage ad-hoc SOC 1 and SOC 2 audit engagements for newly acquired products not yet in scope of the enterprise SOC reports * Coordinate document requests, evidence collection timelines, and ...
Senior IT Audit & Assurance Analyst
Raleigh, NC · On-site +1
Manage ad-hoc SOC 1 and SOC 2 audit engagements for newly acquired products not yet in scope of the enterprise SOC reports * Coordinate document requests, evidence collection timelines, and ...
Senior IT Audit & Assurance Analyst
Raleigh, NC · On-site +1
Manage ad-hoc SOC 1 and SOC 2 audit engagements for newly acquired products not yet in scope of the enterprise SOC reports * Coordinate document requests, evidence collection timelines, and ...
Senior IT Audit & Assurance Analyst
Raleigh, NC · On-site +1
Manage ad-hoc SOC 1 and SOC 2 audit engagements for newly acquired products not yet in scope of the enterprise SOC reports * Coordinate document requests, evidence collection timelines, and ...
Senior IT Audit & Assurance Analyst
Raleigh, NC · On-site +1
Manage ad-hoc SOC 1 and SOC 2 audit engagements for newly acquired products not yet in scope of the enterprise SOC reports * Coordinate document requests, evidence collection timelines, and ...
Ensure documentation is audit-ready, consistent, and aligned with SOC 2 Trust Services Criteria ... Contract Duration: 6M Work Setting: Remote (US) Some overlap with Eastern and PST time zones is ...
Ensure documentation is audit-ready, consistent, and aligned with SOC 2 Trust Services Criteria ... Contract Duration: 6M Work Setting: Remote (US) Some overlap with Eastern and PST time zones is ...
Proven, hands-on experience leading SOC 2 audits (direct ownership, not advisory roles) * Strong ... Experience supporting Legal in security-related contract negotiations and DPAs * Professional ...
Proven, hands-on experience leading SOC 2 audits (direct ownership, not advisory roles) * Strong ... Experience supporting Legal in security-related contract negotiations and DPAs * Professional ...
Key Responsibilities • Own assigned areas of ISO 27001 and/or SOC 2 audits as technical control owner. • Act as primary technical point of contact for auditors, leading walkthroughs and ...
Quick apply
Key Responsibilities • Own assigned areas of ISO 27001 and/or SOC 2 audits as technical control owner. • Act as primary technical point of contact for auditors, leading walkthroughs and ...
Cybersecurity Account Associate
Bozeman, MT · On-site
$15 - $20/hr
Serve as a primary point of contact for day-to-day client questions during SOC 2 audit projects, ensuring timely and professional communication. * Coordinate and track audit evidence requests ...
Cybersecurity Account Associate
Bozeman, MT · On-site
$15 - $20/hr
Serve as a primary point of contact for day-to-day client questions during SOC 2 audit projects, ensuring timely and professional communication. * Coordinate and track audit evidence requests ...
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Quick apply
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Lead SOC 2 Type II audits, including Trust Services Criteria (Security, Availability, Confidentiality, Privacy) * Oversee HIPAA/HITECH compliance and third-party risk management for customers ...
Lead SOC 2 Type II audits, including Trust Services Criteria (Security, Availability, Confidentiality, Privacy) * Oversee HIPAA/HITECH compliance and third-party risk management for customers ...
GRC Analyst
Dallas, TX · On-site
Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding ...
GRC Analyst
Dallas, TX · On-site
Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding ...
Senior Manager, SOC and Postal Audits
Boston, MA · On-site
$88K - $108K/yr
We are seeking a Senior Manager of Compliance to lead and manage Quadient's USPS SOC 1 and SOC 2 programs. This role is responsible for audit execution, control design, and ongoing risk assessment ...
Senior Manager, SOC and Postal Audits
Boston, MA · On-site
$88K - $108K/yr
We are seeking a Senior Manager of Compliance to lead and manage Quadient's USPS SOC 1 and SOC 2 programs. This role is responsible for audit execution, control design, and ongoing risk assessment ...
Senior Manager, SOC and Postal Audits
Boston, MA · On-site +1
$88K - $108K/yr
We are seeking a Senior Manager of Compliance to lead and manage Quadient's USPS SOC 1 and SOC 2 programs. This role is responsible for audit execution, control design, and ongoing risk assessment ...
Senior Manager, SOC and Postal Audits
Boston, MA · On-site +1
$88K - $108K/yr
We are seeking a Senior Manager of Compliance to lead and manage Quadient's USPS SOC 1 and SOC 2 programs. This role is responsible for audit execution, control design, and ongoing risk assessment ...
Senior Manager, SOC and Postal Audits
$88K - $108K/yr
We are seeking a Senior Manager of Compliance to lead and manage Quadient's USPS SOC 1 and SOC 2 programs. This role is responsible for audit execution, control design, and ongoing risk assessment ...
Quick apply
Senior Manager, SOC and Postal Audits
$88K - $108K/yr
We are seeking a Senior Manager of Compliance to lead and manage Quadient's USPS SOC 1 and SOC 2 programs. This role is responsible for audit execution, control design, and ongoing risk assessment ...
Security Manager II - GRC
Tampa, FL · On-site
$145K - $160K/yr
... SOC 2 Type II audit readiness and evidence collection end-to-end -- including control mapping, auditor liaising, and remediation tracking. · Own HIPAA Security Rule and Privacy Rule compliance ...
Quick apply
Security Manager II - GRC
Tampa, FL · On-site
$145K - $160K/yr
... SOC 2 Type II audit readiness and evidence collection end-to-end -- including control mapping, auditor liaising, and remediation tracking. · Own HIPAA Security Rule and Privacy Rule compliance ...
The Information Security Manager (GRC) will oversee LVT's SOC 2 audit processes and drive operational GRC initiatives while fostering collaboration across teams to integrate GRC standards into ...
The Information Security Manager (GRC) will oversee LVT's SOC 2 audit processes and drive operational GRC initiatives while fostering collaboration across teams to integrate GRC standards into ...
Our capabilities include Program Management, Program Oversight, Process Audit, Intelligence ... TestPros is looking for expert level SOC 2 Auditor with experience performing SOC 2 Type 2 ...
Quick apply
Our capabilities include Program Management, Program Oversight, Process Audit, Intelligence ... TestPros is looking for expert level SOC 2 Auditor with experience performing SOC 2 Type 2 ...
Contract Soc Two Audit information
See salary details
$63K - $73K
7% of jobs
$73K - $82.9K
4% of jobs
$82.9K - $92.9K
4% of jobs
$96.8K is the 25th percentile. Wages below this are outliers.
$92.9K - $102.8K
23% of jobs
The median wage is $112.3K / yr.
$102.8K - $112.8K
12% of jobs
$112.8K - $122.7K
12% of jobs
$122.7K - $132.7K
9% of jobs
$136.3K is the 75th percentile. Wages above this are outliers.
$132.7K - $142.6K
9% of jobs
$142.6K - $152.6K
9% of jobs
$152.6K - $162.5K
6% of jobs
$162.5K - $172.5K
3% of jobs
$63K
$117.7K
$172.5K
How much do contract soc two audit jobs pay per year?

Full-time
Medical, Retirement, PTO
Posted 14 days ago
Job description
At Abrigo, we provide market-leading compliance, credit risk and lending software solutions that financial institutions use to manage risk and drive growth. Our solutions automate key processes and allow our customers to maintain compliance, fight financial crime, process loans quicker, and leverage data to strengthen their portfolio.
Abrigo is seeking a Senior IT Audit & Assurance Analyst to join our IT Risk & Assurance team, leading the execution of SOC audit engagements, IT internal audit coordination, IT internal control testing and monitoring, and risk assessment activities for a fast-paced fintech SaaS company serving community financial institutions nationwide.
This position is remote-primary based in Raleigh, NC, with quarterly on-site team engagements (three days each) and periodic on-site visits during external audit fieldwork (up to three weeks annually). This role reports to leadership within the IT Risk & Assurance Team, within an organization that operates under a security-first model under the Chief Information Security Officer.
What You'll Do:
SOC & External Audit Engagement Management:
- Serve as a primary point of contact for external audit firms conducting enterprise SOC 1 and SOC 2 audit engagements, managing the engagement lifecycle from annual renewal and kickoff through final report issuance
- Manage ad-hoc SOC 1 and SOC 2 audit engagements for newly acquired products not yet in scope of the enterprise SOC reports
- Coordinate document requests, evidence collection timelines, and walkthrough scheduling with internal control owners across the organization
- Evaluate audit artifacts for completeness and accuracy before submission to external auditors
- Communicate preliminary audit findings to management and assist in drafting management responses
IT Internal Audit Coordination:
- Serve as the primary liaison with the external IT internal audit firm, managing document requests, walkthrough scheduling, and audit status reporting for audits aligned with FFIEC IT Handbook standards
- Perform walkthroughs with product teams and internal control owners to assess the IT internal control environment and recommend IT internal controls based on SOC and IT internal audit requirements
- Proactively identify control gaps and recommend remediation strategies to control owners
Risk Finding Management & Control Monitoring:
- Own the full lifecycle of the IT risk finding register, from opening findings through remediation closure, including escalation of overdue findings to management
- Document and process risk acceptance based on control owner feedback
- Perform ongoing monitoring of specific IT internal controls to ensure SOC and IT internal audit readiness throughout the year
- Perform periodic IT internal control testing to validate control design and operating effectiveness
- Conduct periodic risk finding reviews to verify findings were closed appropriately with supporting remediation evidence
Risk Assessments & Policy Coordination:
- Lead annual updates to IT risk assessments, including the FFIEC Cybersecurity Assessment Tool (CAT), NIST CSF control mappings, and CIS Controls risk assessments
- Lead the annual business impact analysis update, evaluating likelihood and impact of potential disruptions to the technology environment
- Coordinate the annual policy update cycle with policy owners, including documenting changes, presenting to the IT Steering Committee, and coordinating management and Board approval
- Perform additional IT risk and assurance duties as assigned to support the team's evolving needs
What You'll Need:
- Bachelor's degree in Information Systems, Accounting, Computer Science, or related discipline; equivalent professional experience may be substituted in lieu of a degree
- 3-6 years of experience in IT audit, IT risk, or IT compliance, such as advisory services at a CPA or consulting firm, IT internal audit at a financial institution, or GRC at a technology company
- Hands-on experience managing or significantly contributing to SOC 1/SOC 2 audit engagements, including evidence collection and walkthrough coordination
- Working knowledge of IT general controls and their application to SOC trust services criteria and/or FFIEC IT Handbook examination standards
- Demonstrated experience performing IT internal control testing and evaluating control effectiveness
- Experience maintaining risk finding registers and managing risk remediation lifecycles
- Familiarity with IT risk assessment frameworks such as FFIEC CAT, NIST CSF, or CIS Controls
- Strong written and verbal communication skills with the ability to interact effectively with external auditors, internal control owners, and management
- Strong organizational skills and the ability to independently manage multiple audit and assurance workstreams in a remote-first environment
- Must be available for quarterly on-site team engagements in Raleigh, NC and periodic on-site visits during external audit fieldwork
Preferred:
- CISA (Certified Information Systems Auditor) or CRISC (Certified in Risk and Information Systems Control)
- Experience in the financial services, banking, or fintech industry
- Experience with FFIEC regulatory examinations or bank/credit union technology audit programs
- Experience with SaaS/cloud environments (AWS, Azure) and understanding of shared responsibility models
- Experience coordinating with outsourced or co-sourced internal audit functions
What You'll Get:
- Market competitive total rewards package
- To be part of the Heart & SOUL of a winning company with an inspiring mission
- The opportunity to Make Big Things Happen
- Competitive salary along with full health benefits with an HSA option
- Flexible PTO and bank holidays
- 401(k) plan and company match
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, age, genetic trait, sexual orientation, national origin, disability status, or any other characteristic protected by law. Abrigo is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at [email protected] with the subject line accommodation.
About Abrigo
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
51 - 200 Employees
Headquarters location
Austin, TX, US
Year founded
2000