Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria. * Review evidence requests and determine whether evidence is complete, partial ...
Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria. * Review evidence requests and determine whether evidence is complete, partial ...
Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria. * Review evidence requests and determine whether evidence is complete, partial ...
Quick apply
Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria. * Review evidence requests and determine whether evidence is complete, partial ...
GRC Analyst - 100% Remote - 6+ Month Contract
Rosemont, IL · On-site
$50 - $75/hr
We're hiring two GRC Analysts for a 6+ month contract role helping our end client with an ... Perform a SOC Type 2 Audit/Assessment for their InfoSec environment with a focus on meeting ...
Quick apply
GRC Analyst - 100% Remote - 6+ Month Contract
Rosemont, IL · On-site
$50 - $75/hr
We're hiring two GRC Analysts for a 6+ month contract role helping our end client with an ... Perform a SOC Type 2 Audit/Assessment for their InfoSec environment with a focus on meeting ...
Ensure documentation is audit-ready, consistent, and aligned with SOC 2 Trust Services Criteria ... Contract Duration: 6M Work Setting: Remote (US) Some overlap with Eastern and PST time zones is ...
Ensure documentation is audit-ready, consistent, and aligned with SOC 2 Trust Services Criteria ... Contract Duration: 6M Work Setting: Remote (US) Some overlap with Eastern and PST time zones is ...
Key Responsibilities • Own assigned areas of ISO 27001 and/or SOC 2 audits as technical control owner. • Act as primary technical point of contact for auditors, leading walkthroughs and ...
Quick apply
Key Responsibilities • Own assigned areas of ISO 27001 and/or SOC 2 audits as technical control owner. • Act as primary technical point of contact for auditors, leading walkthroughs and ...
Operational Governance, AVP
Burlington, MA · On-site
$100K - $160K/yr
This role will support Regulatory, SOC 1 and SOC 2 audits, as well as client-driven audit engagements. The successful candidate will bring a strong technology audit background, with demonstrated ...
Operational Governance, AVP
Burlington, MA · On-site
$100K - $160K/yr
This role will support Regulatory, SOC 1 and SOC 2 audits, as well as client-driven audit engagements. The successful candidate will bring a strong technology audit background, with demonstrated ...
Operational Governance, AVP
Burlington, MA · On-site
$100K - $160K/yr
This role will support Regulatory, SOC 1 and SOC 2 audits, as well as client-driven audit engagements. The successful candidate will bring a strong technology audit background, with demonstrated ...
Operational Governance, AVP
Burlington, MA · On-site
$100K - $160K/yr
This role will support Regulatory, SOC 1 and SOC 2 audits, as well as client-driven audit engagements. The successful candidate will bring a strong technology audit background, with demonstrated ...
Cybersecurity Account Associate
Bozeman, MT · On-site
$15 - $20/hr
Serve as a primary point of contact for day-to-day client questions during SOC 2 audit projects, ensuring timely and professional communication. * Coordinate and track audit evidence requests ...
Cybersecurity Account Associate
Bozeman, MT · On-site
$15 - $20/hr
Serve as a primary point of contact for day-to-day client questions during SOC 2 audit projects, ensuring timely and professional communication. * Coordinate and track audit evidence requests ...
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Quick apply
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding ...
Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding ...
SOC 2 Assessor (Part time & Remote)
Sterling, VA · On-site +1
$50 - $90/hr
Remote Contract Period: February 2026 - February 2027 (with potential renewals) Overview ... Compile the results of the audit into a detailed SOC 2 Type 2 report. * Provide recommendations and ...
SOC 2 Assessor (Part time & Remote)
Sterling, VA · On-site +1
$50 - $90/hr
Remote Contract Period: February 2026 - February 2027 (with potential renewals) Overview ... Compile the results of the audit into a detailed SOC 2 Type 2 report. * Provide recommendations and ...
Lead Security Engineer
Manhattan, NY · On-site
Experience with SOC 2 audit procedure and ISO 27001 compliance. Ability to communicate network, platform, and data security issues to peers and management. Self-driven and comfortable working in a ...
Lead Security Engineer
Manhattan, NY · On-site
Experience with SOC 2 audit procedure and ISO 27001 compliance. Ability to communicate network, platform, and data security issues to peers and management. Self-driven and comfortable working in a ...
Remote Contract Period: February 2026 - February 2027 (with potential renewals) Overview ... Compile the results of the audit into a detailed SOC 2 Type 2 report. * Provide recommendations and ...
Quick apply
Remote Contract Period: February 2026 - February 2027 (with potential renewals) Overview ... Compile the results of the audit into a detailed SOC 2 Type 2 report. * Provide recommendations and ...
... II). * Experience performing walkthroughs, control testing, audit documentation, and report preparation for SOC examinations. * Strong knowledge of the AICPA Trust Services Criteria (TSC) and ...
... II). * Experience performing walkthroughs, control testing, audit documentation, and report preparation for SOC examinations. * Strong knowledge of the AICPA Trust Services Criteria (TSC) and ...
Ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort Regional Cloud/Government Certifications * Drive DESC CSP certification for UAE ...
Ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort Regional Cloud/Government Certifications * Drive DESC CSP certification for UAE ...
Systems Administrator - Tier II
Englewood, CO · On-site
$75K - $100K/yr
In a SOC 2 environment, access records are audit evidence. Endpoint & Device Management · Image, configure, and manage workstations across the organization using Microsoft Intune and Autopilot. Own ...
Quick apply
Systems Administrator - Tier II
Englewood, CO · On-site
$75K - $100K/yr
In a SOC 2 environment, access records are audit evidence. Endpoint & Device Management · Image, configure, and manage workstations across the organization using Microsoft Intune and Autopilot. Own ...
Ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort Regional Cloud/Government Certifications * Drive DESC CSP certification for UAE ...
New
Quick apply
Ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort Regional Cloud/Government Certifications * Drive DESC CSP certification for UAE ...
New
Ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort Regional Cloud/Government Certifications * Drive DESC CSP certification for UAE ...
Ensure alignment between SOC 2 controls and overlapping ISO 27001/FedRAMP requirements to avoid duplicated audit effort Regional Cloud/Government Certifications * Drive DESC CSP certification for UAE ...
Contract Soc Two Audit information
See salary details
$63K - $73K
7% of jobs
$73K - $82.9K
4% of jobs
$82.9K - $92.9K
4% of jobs
$96.8K is the 25th percentile. Wages below this are outliers.
$92.9K - $102.8K
23% of jobs
The median wage is $112.3K / yr.
$102.8K - $112.8K
12% of jobs
$112.8K - $122.7K
12% of jobs
$122.7K - $132.7K
9% of jobs
$136.3K is the 75th percentile. Wages above this are outliers.
$132.7K - $142.6K
9% of jobs
$142.6K - $152.6K
9% of jobs
$152.6K - $162.5K
6% of jobs
$162.5K - $172.5K
3% of jobs
$63K
$117.7K
$172.5K
How much do contract soc two audit jobs pay per year?

SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
Silver Spring, MD • On-site
Full-time
Retirement
Posted 10 days ago
Job description
About the role
FYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an active SOC 2 Type 2 program across Security, Availability, Processing Integrity, Confidentiality, and Privacy. This role will own the SOC 2 domain in a fractional capacity, including evidence review, control operation support, auditor communication support, recurring compliance cadence, and SaaS/cloud control maturity. The right candidate has supported real SOC 2 Type 2 audits and can work with engineering, IT, security, HR, operations, leadership, and auditors.
Essential responsibilities and duties
- Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria.
- Review evidence requests and determine whether evidence is complete, partial, missing, stale, unclear, or misaligned to the control being tested.
- Draft and review auditor responses, management explanations, control narratives, and evidence summaries.
- Support control operations for access reviews, vendor risk management, risk assessment, policy review, security awareness, incident response, change management, and security steering activities.
- Review evidence for IAM, MFA, logging, monitoring, encryption, vulnerability management, secure SDLC, code review, release approvals, CI/CD security, SAST, DAST, SCA, backups, availability, confidentiality, processing integrity, and privacy controls.
- Coordinate with control owners to obtain timestamped, complete, and audit-ready artifacts.
- Help maintain the recurring compliance calendar for monthly, quarterly, and annual SOC 2 control activities.
- Support policy and documentation management, version control, approvals, and annual review cadence.
- Identify control design gaps, operating effectiveness gaps, evidence issues, and audit risks.
- Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.
Required qualifications
- 8+ years of cybersecurity, GRC, IT audit, compliance, SaaS security, cloud security, security consulting, or related experience.
- GRC platform experience (Drata preferred, others include Vanta or SecureFrame)
- Direct hands-on experience supporting SOC 2 Type 2 audits.
- Experience with SaaS or cloud-hosted application environments.
- Experience reviewing evidence for control design and operating effectiveness.
- Ability to translate audit requirements into operational tasks for engineering, IT, security, HR, legal, operations, and leadership stakeholders.
- Strong written communication skills and ability to produce auditor-ready explanations.
- Ability to drive control owners and follow-ups without constant prompting.
- Ability to work through ambiguity and produce clean, organized, audit-ready documentation.
Nice to have
- Prior SOC 2 auditor, CPA-firm, or audit-support experience.
- Experience with all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- CISA, CISSP, CISM, Security+, CPA, ISO 27001 Lead Auditor, or equivalent certification.
- Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, CI/CD tooling, SAST, DAST, SCA, vulnerability management, or cloud security tools.
- PCI DSS familiarity, especially where SOC 2 controls overlap with PCI requirements.
Expected deliverables
- SOC 2 Five-TSC evidence and gap tracker inputs.
- Control evidence sufficiency reviews.
- Auditor response drafts and management-response drafts.
- Control narrative and control-description updates.
- Recurring compliance calendar inputs for access reviews, vendor reviews, risk assessments, policy reviews, steering meetings, and evidence refresh cycles.
- Policy, procedure, and documentation review notes.
- SOC 2 blocker, risk, and next-action summaries.
Operating style required
This role requires a senior operator who can own the SOC 2 lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.
FYI's Benefits/Incentives: What is in it for you?
- Opportunity to work a hybrid work schedule
- A knowledgeable, high-achieving, diverse, experienced, and fun team.
- The chance to be part of a rapidly growing company and the next success story.
- A competitive base salary with a loaded benefits package plus 401K.
- Tuition/education assistance, personal computer allowance, pet insurance.
About FYI For Your Information
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Beltsville, MD, US
Year founded
1987