1

Contract Soc Two Audit Jobs (NOW HIRING)

Direct experience driving SOC 2 Type II audit cycles end to end, including auditor coordination ... contracts. * Familiarity with privacy regulation in North America, including PIPEDA and US state ...

IT Audit & Compliance Analyst

Oaks, PA

$96K - $96K/yr

Interpret and operationalize requirements from HITRUST CSF, PCI DSS, and SOC 2 standards. * Analyze ... Audit Coordination amp; Evidence Management * Lead end-to-end audit readiness activities for ...

Obtains and reviews evidence ensuring audit conclusions are well-documented * Maintain subject knowledge expertise of AICPA SOC standards, and other relevant guidance issued regarding SOC 1 and SOC 2 ...

Senior IT Security Engineer

OR · Remote

$130K - $155K/yr

You will drive ISO 27001 certification and SOC 2 Type II attestation initiatives end-to-end - from initial gap analysis and control design through evidence collection, audit coordination, and ...

SOC Leader

Minneapolis, MN · On-site

$16.75 - $22/hr

Obtains and reviews evidence ensuring audit conclusions are well-documented * Maintain subject knowledge expertise of AICPA SOC standards, and other relevant guidance issued regarding SOC 1 and SOC 2 ...

Demonstrated experience managing delivery under formal contracts, SOC 2 Type 2 audits, statements of work, and structured governance frameworks. * Proficiency in the following project management and ...

Demonstrated experience managing delivery under formal contracts, SOC 2 Type 2 audits, statements of work, and structured governance frameworks. * Proficiency in the following project management and ...

Demonstrated experience managing delivery under formal contracts, SOC 2 Type 2 audits, statements of work, and structured governance frameworks. * Proficiency in the following project management and ...

You will drive ISO 27001 certification and SOC 2 Type II attestation initiatives end-to-end - from initial gap analysis and control design through evidence collection, audit coordination, and ...

... SOC-1 Type I and Type II audit support activities for service organization environments • ... and contract wage rates, relevant prior work experience, specific skills and competencies ...

Direct experience supporting SOC 1 and SOC 2 audits and/or ISO certifications (e.g., ISO 27001 ... 27017, 27701, 20000) * Strong understanding of control frameworks, audit methodologies, and ...

What You'll Do SOC 2 Leadership * Own control design, documentation, and evidence collection for SOC 2 Type II audit * Coordinate with Engineering and Product on control implementation and testing

Manage IT audit and assurance engagements, including SOC 1, SOC 2, SOC 3, SOC for Cybersecurity ... HITRUST, HIPAA, and other compliance assessments. 2. Collaborate with senior team members and ...

Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding ...

next page

Showing results 1-20

Contract Soc Two Audit information

See salary details

$63K

$117.7K

$172.5K

How much do contract soc two audit jobs pay per year?

As of Jun 11, 2026, the average yearly pay for contract soc two audit in the United States is $117,671.00, according to ZipRecruiter salary data. Most workers in this role earn between $96,000.00 and $141,500.00 per year, depending on experience, location, and employer.
More about Contract Soc Two Audit jobs
What cities are hiring for Contract Soc Two Audit jobs? Cities with the most Contract Soc Two Audit job openings:
What states have the most Contract Soc Two Audit jobs? States with the most job openings for Contract Soc Two Audit jobs include:
What job categories do people searching Contract Soc Two Audit jobs look for? The top searched job categories for Contract Soc Two Audit jobs are:
Infographic showing various Contract Soc Two Audit job openings in the United States as of June 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $117,671 per year, or $56.6 per hour.

Information Security Manager (GRC)

LVT

American Fork, UT • On-site

Other

Posted 20 days ago


Job description

ABOUT THIS ROLE 

LVT is actively seeking a highly motivated and detail-oriented Information Security Manager (GRC) to join our growing Information Security team. This role will report directly to the Information Security Director (GRC). This position is designed for an individual eager to delve deeply into the operational aspects of Governance, Risk, and Compliance, directly supporting LVT's steadfast commitment to security excellence and regulatory adherence as the business continues its innovative scaling.

LVT values managing risk in alignment with our customer's and stakeholder's expected levels. We design, implement,  and monitor controls that reduce real risk. The  Information Security Manager (GRC) will play an instrumental role in driving key operational GRC initiatives. The primary focus of this hands-on position will be the end-to-end management of LVT's SOC 2 audit processes, initiating third-party risk assessments, actively contributing to the policy review and approval lifecycle, and documenting and treating risks in our risk register. 

Fostering collaborative relationships and good communication is critical as you will work closely with cross-functional teams across the organization to integrate GRC standards and principles into LVT's operations. This role demands exceptional organizational skills, both strategic vision and tactical efforts, and the ability to build and mentor a team of security professionals to meet both current and future GRC challenges.

ROLE RESPONSIBILITIES

  • Manage LVT's annual SOC 2 audit and other audits as necessary.  
  • Collaborate with IT, Finance, and Legal to represent Information Security in various cross-functional processes including vendor risk, contractual terms , and customer security questions.
  • Identify inefficiencies in different GRC processes and improve them.
  • Design and manage regular internal audits of security controls.
  • Implement automated control monitoring and evidence collection.
  • Create, review, and maintain LVT's security policies.  
  • Maintain LVT's risk register to ensure accurate and timely recording of identified risks and their mitigation statuses.  
  • Build strong relationships with risk owners to drive program buy-in, accountability, and ownership.
  • Work with SalesOps to develop an approach to customer security questionnaires.
  • Mature our public-facing Security Trust Center to enhance transparency, showcase LVT's commitment to security, and streamline the sales process.
  • Identify and operationalize ways to automate tools and processes to improve LVT's compliance program efficiency and collaboration across multiple teams.
  • Establish and maintain measurable GRC program metrics to quantify effectiveness, highlight progress, and drive continuous improvement.

OUR IDEAL CANDIDATE

  • 5+ years of experience with Information Security, GRC or IT Audit roles, demonstrating a growing understanding of GRC concepts and methodologies. 
  • Experience managing a GRC function and staff.
  • Effective writing skills for tasks such as policy review and approval, developing risk treatment plans, and creating audit documentation and responses for external auditors.
  • Strong organizational skills and attention to detail for managing documentation, audit evidence, and maintaining accurate GRC records.
  • Proven track record of developing and implementing policies and procedures, assessing and prioritizing risks, and maturing security compliance programs.
  • Substantial experience with regulatory frameworks and standards, such as NIST, SOC 2, ISO 27001, and FedRAMP.
  • Experience communicating detailed security concepts, risks, and controls to both technical and non-technical stakeholders.
  • Outstanding interpersonal and leadership skills that inspire collaboration and drive alignment across teams.
  • Demonstrates an ability to lead effectively in dynamic, fast-paced environments, balancing strategic vision with tactical execution to respond to evolving security needs.
  • Experience working with GRC platforms (e.g., Drata, Vanta, ZenGRC) and project management tools (e.g., Jira, Asana) is a plus.
  • A Bachelor's degree in Information Security, Computer Science, Information Technology, Business, or a related field, or equivalent practical experience, is preferred. 
  • Relevant professional certifications such as CISSP, CompTIA Security+, CISA, or CRISC are highly desirable.