2

Remote Soc 2 Analyst Jobs in California (NOW HIRING)

Senior GRC Analyst

San Francisco, CA · On-site +1

$183K - $205K/yr

Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including ... A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity.

Security Analyst (SOC)

Hawthorne, CA · On-site +1

$110K - $130K/yr

OR 2+ years of professional experience in information security in lieu of a degree. * Experience ... This role requires you to be onsite in Hawthorne, CA; remote or hybrid work will not be considered.

Experience supporting SOC 2 Type 2 audits in a cloud-based or high-growth technology environment ... Visit our PinFlex page to learn more about our working model. #LI-REMOTE At Pinterest we believe ...

New

GRC Analyst

San Francisco, CA · On-site +1

$134K - $202K/yr

... SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company ... You will report to the Head of GRC and will be located ((remote, onsite, hybrid)). Think you may ...

Compliance Engineer

San Francisco, CA · On-site +1

$6.0K - $7.5K/mo

Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO ... Remote * Compensation: $6000-$7500 USD/Month , based on experience * Hours: Must be open to working ...

New

next page

Showing results 1-20

Remote Soc 2 Analyst information

What is a Remote SOC 2 Analyst?

A Remote SOC 2 Analyst is a cybersecurity professional who works remotely to help organizations achieve and maintain SOC 2 compliance. SOC 2 (Service Organization Control 2) is a set of standards designed to ensure service providers securely manage data to protect the privacy and interests of their clients. The analyst assesses an organization's security controls, policies, and procedures, identifies gaps, and recommends improvements. They also assist with preparing for SOC 2 audits, managing documentation, and ensuring that security practices align with SOC 2 requirements, all while working from a remote location.

What are the key skills and qualifications needed to thrive as a Remote SOC 2 Analyst?

To excel as a Remote SOC 2 Analyst, you need a solid understanding of information security, risk assessment, and compliance frameworks, typically supported by a degree in information security or related fields. Familiarity with tools like GRC platforms, audit management systems, and certifications such as CISA or CISSP are often required. Strong analytical thinking, attention to detail, and effective communication are vital soft skills for interpreting controls and collaborating with clients remotely. These skills ensure accurate assessments, maintain regulatory compliance, and enable efficient communication in a distributed work environment.

What are some common challenges faced by Remote SOC 2 Analysts when working with distributed teams?

Remote SOC 2 Analysts often face challenges related to communication and collaboration, particularly when coordinating with IT, security, and compliance teams across different locations and time zones. Ensuring consistent documentation and maintaining up-to-date evidence for audits can require proactive organization and regular virtual check-ins. Leveraging collaboration tools and establishing clear processes helps streamline workflows and ensures everyone stays aligned on compliance tasks, despite the physical distance.

What is the difference between Remote Soc 2 Analyst vs Remote Security Auditor?

AspectRemote Soc 2 AnalystRemote Security Auditor
CertificationsSOC 2, CISSP, CISACISA, CISSP, ISO 27001 Lead Auditor
Work EnvironmentRemote, client-facing, compliance-focusedRemote or onsite, audit and assessment-based
Industry UsageTech, finance, healthcareVarious industries, including finance and healthcare

Remote Soc 2 Analysts primarily focus on preparing organizations for SOC 2 compliance, ensuring controls meet standards. Remote Security Auditors conduct comprehensive evaluations of security controls across various frameworks. While both roles require similar certifications and often work remotely, Soc 2 Analysts specialize in SOC 2 reports, whereas Security Auditors have a broader scope including multiple standards.

Is a remote SOC 2 analyst still in demand?

Remote SOC 2 analysts are in strong demand due to increasing cybersecurity regulations and the need for organizations to demonstrate compliance. Skills in security frameworks, audit processes, and familiarity with tools like GRC platforms enhance job prospects in this field.

What are the most commonly searched types of Soc 2 Analyst jobs in California?

The most popular types of Soc 2 Analyst jobs in California are:

What job categories do people searching Remote Soc 2 Analyst jobs in California look for?

The top searched job categories for Remote Soc 2 Analyst jobs in California are:

What cities in California are hiring for Remote Soc 2 Analyst jobs?

Cities in California with the most Remote Soc 2 Analyst job openings:

Infographic showing various Remote Soc 2 Analyst job openings in California as of August 2026, with employment types broken down into 87% Full Time, 9% Part Time, and 4% Contract. Highlights an 81% Physical, 8% Hybrid, and 11% Remote job distribution.

Security GRC Analyst

Pinterest

San Francisco, CA • On-site, Remote

Full-time

Posted 3 days ago

New


Job description

Pinterest's Security team (Pinfosec) is seeking an IC14 Security Engineer -  Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively.

Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest's security control environment. The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessments.

What you'll do:

  • Administer and maintain the security risk register, including tracking identified risks, updates, remediation activities, owners, and reporting outputs.
  • Partner with stakeholders across Security and the business to identify, document, assess, and monitor security risks.
  • Draft, review, update, and manage the lifecycle of security policies, standards, and supporting procedures.
  • Support the planning, coordination, evidence collection, and follow-up activities for Pinterest's annual SOC 2 Type 2 audit.
  • Track and report on security awareness training metrics, completion rates, exceptions, and follow-up actions.
  • Execute security control testing activities aligned to CIS Controls and document testing outcomes, findings, and remediation recommendations.
  • Conduct and support risk assessments in partnership with internal Security colleagues and relevant business stakeholders.
  • Help monitor control effectiveness and identify opportunities to improve process maturity, consistency, and evidence quality.
  • Prepare dashboards, reports, and presentations for leadership on risk, compliance, audit, and awareness program status.
  • Support remediation tracking for control gaps, audit findings, and risk treatment actions.
  • Contribute to the continuous improvement of Pinterest's GRC framework, documentation, and operating rhythms.
  • Maintain strong working relationships with internal partners to promote a practical, business-aligned approach to security governance and compliance.

What we are looking for:

  • 4+ years experience in security governance, risk, compliance, audit, or security assurance roles.
  • Working knowledge of core security and compliance frameworks such as SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar.
  • Experience supporting audits, assessments, or control testing programs in a technology or SaaS environment.
  • Ability to write clear, practical, and actionable security policies, standards, and process documentation.
  • Experience maintaining risk registers and supporting formal risk assessment processes.
  • Strong organizational skills with the ability to manage multiple workstreams and deadlines with attention to detail.
  • Comfort working cross-functionally and gathering information or evidence from technical and non-technical stakeholders.
  • Strong written and verbal communication skills, including the ability to summarize risk and compliance issues clearly.
  • A pragmatic, collaborative mindset and a desire to help teams meet security requirements in a scalable way.
  • Bachelor's degree in a relevant field such as Computer Information systems or Cybersecurity, or equivalent experience.

Preferred qualifications: 

  • Experience supporting SOC 2 Type 2 audits in a cloud-based or high-growth technology environment.
  • Familiarity with security awareness program administration and reporting.
  • Experience performing or coordinating control testing mapped to recognized frameworks such as CIS Controls.
  • Knowledge of common enterprise security domains, including identity and access management, logging and monitoring, vulnerability management, endpoint security, and third-party risk.
  • Relevant certifications such as Security+, CISA, CRISC, CISSP, or similar are a plus.

In-Office Requirement Statement:

  • We let the type of work you do guide the collaboration style. That means we're not always working in an office, but we continue to gather for key moments of collaboration and connection.
  • This role will need to be in the office for in-person collaboration 1-2 times/quarter and therefore can be situated anywhere in the country. 

Relocation Statement:

  • This position is not eligible for relocation assistance. Visit our PinFlex page to learn more about our working model.


#LI-REMOTE