2

Remote Soc 2 Analyst Jobs in California (NOW HIRING)

Remote Role Responsibilities * Review simulated vendor SOC 2 reports , security questionnaires, and pen-test evidence against a buyer's security standard. * Catch scope mismatches and lapsed bridge ...

Remote Role Responsibilities * Review simulated vendor SOC 2 reports , security questionnaires, and pen-test evidence against a buyer's security standard. * Catch scope mismatches and lapsed bridge ...

$111K - $137K/yr

... remote-first company ... Collect up-to-date audit evidence and own SOC 2 IT controls. * SaaS Administration: Own the day-to ...

Security Analyst (SOC)

Hawthorne, CA ยท On-site +1

$110K - $130K/yr

OR 2+ years of professional experience in information security in lieu of a degree. * Experience ... This role requires you to be onsite in Hawthorne, CA; remote or hybrid work will not be considered.

Network Security Engineer

San Francisco, CA ยท On-site +1

$123K - $168K/yr

Configure and maintain firewalls, VPNs, network segmentation, NAC, and secure remote access ... Support compliance initiatives (SOC 2, ISO 27001, NIST, etc.). * Develop security policies ...

Senior GRC Lead

San Francisco, CA ยท On-site +1

$134K - $185K/yr

You'll leverage your deep understanding of SOC 2, PCI DSS, ISO 27001, AI governance frameworks, and ... As a perk, we also have up to four weeks per year of fully remote work! Responsibilities * Manage ...

Senior Product Manager, Enterprise

Emeryville, CA ยท Remote

$146K - $193K/yr

SOC 2 a plus). * Experience with dashboards, reporting, or analytics products. * Track record ... Experience with telehealth or remote patient monitoring solutions. * Experience with integration ...

next page

Showing results 1-20

Remote Soc 2 Analyst information

What is a Remote SOC 2 Analyst?

A Remote SOC 2 Analyst is a cybersecurity professional who works remotely to help organizations achieve and maintain SOC 2 compliance. SOC 2 (Service Organization Control 2) is a set of standards designed to ensure service providers securely manage data to protect the privacy and interests of their clients. The analyst assesses an organization's security controls, policies, and procedures, identifies gaps, and recommends improvements. They also assist with preparing for SOC 2 audits, managing documentation, and ensuring that security practices align with SOC 2 requirements, all while working from a remote location.

What are the key skills and qualifications needed to thrive as a Remote SOC 2 Analyst?

To excel as a Remote SOC 2 Analyst, you need a solid understanding of information security, risk assessment, and compliance frameworks, typically supported by a degree in information security or related fields. Familiarity with tools like GRC platforms, audit management systems, and certifications such as CISA or CISSP are often required. Strong analytical thinking, attention to detail, and effective communication are vital soft skills for interpreting controls and collaborating with clients remotely. These skills ensure accurate assessments, maintain regulatory compliance, and enable efficient communication in a distributed work environment.

What are some common challenges faced by Remote SOC 2 Analysts when working with distributed teams?

Remote SOC 2 Analysts often face challenges related to communication and collaboration, particularly when coordinating with IT, security, and compliance teams across different locations and time zones. Ensuring consistent documentation and maintaining up-to-date evidence for audits can require proactive organization and regular virtual check-ins. Leveraging collaboration tools and establishing clear processes helps streamline workflows and ensures everyone stays aligned on compliance tasks, despite the physical distance.

What is the difference between Remote Soc 2 Analyst vs Remote Security Auditor?

AspectRemote Soc 2 AnalystRemote Security Auditor
CertificationsSOC 2, CISSP, CISACISA, CISSP, ISO 27001 Lead Auditor
Work EnvironmentRemote, client-facing, compliance-focusedRemote or onsite, audit and assessment-based
Industry UsageTech, finance, healthcareVarious industries, including finance and healthcare

Remote Soc 2 Analysts primarily focus on preparing organizations for SOC 2 compliance, ensuring controls meet standards. Remote Security Auditors conduct comprehensive evaluations of security controls across various frameworks. While both roles require similar certifications and often work remotely, Soc 2 Analysts specialize in SOC 2 reports, whereas Security Auditors have a broader scope including multiple standards.

Is a remote SOC 2 analyst still in demand?

Remote SOC 2 analysts are in strong demand due to increasing cybersecurity regulations and the need for organizations to demonstrate compliance. Skills in security frameworks, audit processes, and familiarity with tools like GRC platforms enhance job prospects in this field.

What are the most commonly searched types of Soc 2 Analyst jobs in California?

The most popular types of Soc 2 Analyst jobs in California are:

What cities in California are hiring for Remote Soc 2 Analyst jobs?

Cities in California with the most Remote Soc 2 Analyst job openings:

Infographic showing various Remote Soc 2 Analyst job openings in California as of August 2026, with employment types broken down into 65% Full Time, 9% Temporary, and 26% Contract. Highlights an 100% Remote job distribution.

Security Review Expert - SOC 2

Mercor

San Francisco, CA โ€ข Remote

$90 - $110/hr

Full-time

Posted 13 days ago


Job description

About the job

Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.

Position: Security Expert
Type: Contract
Compensation: $90–$110/hour
Location: Remote

Role Responsibilities

  • Review simulated vendor SOC 2 reports, security questionnaires, and pen-test evidence against a buyer's security standard.
  • Catch scope mismatches and lapsed bridge letters that a surface-level review would miss.
  • Author step-level rubrics and golden responses capturing how an experienced security reviewer would judge a request or renewal.
  • Assess data-handling and sub-processor risk for vendors touching sensitive data.
  • Work independently and asynchronously to meet deadlines while improving AI model performance.

Qualifications

Must-Have

  • 8+ years of professional experience in security review, vendor risk management, or third-party risk (TPRM).
  • Hands-on experience evaluating SOC 2 reports, security questionnaires, and compliance evidence.
  • Strong written communication skills; comfortable producing structured, rubric-style feedback.

Preferred

  • Relevant security certification, such as CISSP or CISA.
  • Prior task-writing, rubric-authoring, or AI-training data experience.

Application Process (Takes 20–30 mins to complete)

  • Upload resume
  • AI interview based on your resume
  • Submit form

Resources & Support

  • For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome
  • For any help or support, reach out to: support@mercor.com

PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.