2

Remote Soc 2 Analyst Jobs in California (NOW HIRING)

Remote Role Responsibilities * Review simulated vendor SOC 2 reports , security questionnaires, and pen-test evidence against a buyer's security standard. * Catch scope mismatches and lapsed bridge ...

Remote Role Responsibilities * Review simulated vendor SOC 2 reports , security questionnaires, and pen-test evidence against a buyer's security standard. * Catch scope mismatches and lapsed bridge ...

Security Analyst (SOC)

Hawthorne, CA ยท On-site +1

$110K - $130K/yr

OR 2+ years of professional experience in information security in lieu of a degree. * Experience ... This role requires you to be onsite in Hawthorne, CA; remote or hybrid work will not be considered.

GRC Analyst

San Francisco, CA ยท On-site +1

$134K - $202K/yr

... SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company ... You will report to the Head of GRC and will be located ((remote, onsite, hybrid)). Think you may ...

Network Security Engineer

San Francisco, CA ยท On-site +1

$123K - $168K/yr

Configure and maintain firewalls, VPNs, network segmentation, NAC, and secure remote access ... Support compliance initiatives (SOC 2, ISO 27001, NIST, etc.). * Develop security policies ...

BDR Hunter US

Palo Alto, CA ยท On-site +1

$70K - $80K/yr

... analysis, and security questionnaire response - helping security, compliance, and risk teams get and stay audit-ready across frameworks like SOC 2, ISO 27001, HIPAA, HITRUST, NIST, PCI DSS, SOX, and ...

Senior Product Manager, Enterprise

Emeryville, CA ยท Remote

$146K - $193K/yr

SOC 2 a plus). * Experience with dashboards, reporting, or analytics products. * Track record ... Experience with telehealth or remote patient monitoring solutions. * Experience with integration ...

Implementation Engineer

San Francisco, CA ยท On-site +1

$130K - $150K/yr

The platform is secured to a bank-grade standard, and we have received our SOC 2 Type 2 attestation ... This role is a remote position, and you will be working in the West Coast time zone. Travel is not ...

Client Support Engineer

San Francisco, CA ยท On-site +1

$130K - $150K/yr

The platform is secured to a bank-grade standard, and we have received our SOC 2 Type 2 attestation ... This role is a remote position, and you will be working in the West Coast time zone. Travel is not ...

Senior Product Manager, Enterprise

Emeryville, CA ยท Remote

$146K - $193K/yr

SOC 2 a plus). * Experience with dashboards, reporting, or analytics products. * Track record ... Experience with telehealth or remote patient monitoring solutions. * Experience with integration ...

Fabric SOC Architect

Santa Clara, CA ยท Remote

$100K - $500K/yr

This role is remote, based out of The United States. We welcome candidates at various experience ... Analytical and data-driven, with a talent for turning workloads into architectural insights.

Senior Security Engineer

Mountain View, CA ยท On-site +1

$170K - $215K/yr

... analytics to empower individuals to better understand and manage their credit. Our recently ... Implement and maintain the technical controls supporting our PCI DSS and SOC 2 / ISO 27001 ...

Principal Data Architect

Irvine, CA ยท Remote

$126K - $214K/yr

Working knowledge of FinTech-relevant regulatory and compliance considerations (e.g., GLBA, SOC 2, ... analytics or embedded reporting. * Experience supporting loan origination, deposit account opening ...

next page

Showing results 1-20

Remote Soc 2 Analyst information

What is a Remote SOC 2 Analyst?

A Remote SOC 2 Analyst is a cybersecurity professional who works remotely to help organizations achieve and maintain SOC 2 compliance. SOC 2 (Service Organization Control 2) is a set of standards designed to ensure service providers securely manage data to protect the privacy and interests of their clients. The analyst assesses an organization's security controls, policies, and procedures, identifies gaps, and recommends improvements. They also assist with preparing for SOC 2 audits, managing documentation, and ensuring that security practices align with SOC 2 requirements, all while working from a remote location.

What are the key skills and qualifications needed to thrive as a Remote SOC 2 Analyst?

To excel as a Remote SOC 2 Analyst, you need a solid understanding of information security, risk assessment, and compliance frameworks, typically supported by a degree in information security or related fields. Familiarity with tools like GRC platforms, audit management systems, and certifications such as CISA or CISSP are often required. Strong analytical thinking, attention to detail, and effective communication are vital soft skills for interpreting controls and collaborating with clients remotely. These skills ensure accurate assessments, maintain regulatory compliance, and enable efficient communication in a distributed work environment.

What are some common challenges faced by Remote SOC 2 Analysts when working with distributed teams?

Remote SOC 2 Analysts often face challenges related to communication and collaboration, particularly when coordinating with IT, security, and compliance teams across different locations and time zones. Ensuring consistent documentation and maintaining up-to-date evidence for audits can require proactive organization and regular virtual check-ins. Leveraging collaboration tools and establishing clear processes helps streamline workflows and ensures everyone stays aligned on compliance tasks, despite the physical distance.

What is the difference between Remote Soc 2 Analyst vs Remote Security Auditor?

AspectRemote Soc 2 AnalystRemote Security Auditor
CertificationsSOC 2, CISSP, CISACISA, CISSP, ISO 27001 Lead Auditor
Work EnvironmentRemote, client-facing, compliance-focusedRemote or onsite, audit and assessment-based
Industry UsageTech, finance, healthcareVarious industries, including finance and healthcare

Remote Soc 2 Analysts primarily focus on preparing organizations for SOC 2 compliance, ensuring controls meet standards. Remote Security Auditors conduct comprehensive evaluations of security controls across various frameworks. While both roles require similar certifications and often work remotely, Soc 2 Analysts specialize in SOC 2 reports, whereas Security Auditors have a broader scope including multiple standards.

Is a remote SOC 2 analyst still in demand?

Remote SOC 2 analysts are in strong demand due to increasing cybersecurity regulations and the need for organizations to demonstrate compliance. Skills in security frameworks, audit processes, and familiarity with tools like GRC platforms enhance job prospects in this field.

What are the most commonly searched types of Soc 2 Analyst jobs in California?

The most popular types of Soc 2 Analyst jobs in California are:

What cities in California are hiring for Remote Soc 2 Analyst jobs?

Cities in California with the most Remote Soc 2 Analyst job openings:

Infographic showing various Remote Soc 2 Analyst job openings in California as of August 2026, with employment types broken down into 65% Full Time, 9% Temporary, and 26% Contract. Highlights an 100% Remote job distribution.

Security Review Expert - SOC 2

San Francisco, CA โ€ข Remote

$90 - $110/hr

Full-time

Posted 18 days ago


Job description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: Security Expert
Type: Contract
Compensation: $90–$110/hour
Location: Remote

Role Responsibilities

  • Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard.
  • Catch scope mismatches and lapsed bridge letters that a surface-level review would miss.
  • Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal.
  • Assess data-handling and sub-processor risk for vendors touching sensitive data.
  • Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

  • 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM).
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence.
  • Strong written communication skills; comfortable producing structured, rubric-style feedback.

Preferred

  • Relevant security certification, such as CISSP or CISA.
  • Prior task-writing, rubric-authoring, or AI-training data experience.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

  • For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
  • For any help or support, reach out to: support@mercor.com

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.