You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a ... Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the ...
You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a ... Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the ...
GRC Analyst
$134K - $202K/yr
... SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company ... You will report to the Head of GRC and will be located ((remote, onsite, hybrid)). Think you may ...
GRC Analyst
$134K - $202K/yr
... SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company ... You will report to the Head of GRC and will be located ((remote, onsite, hybrid)). Think you may ...
This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles ... Familiarity with major security and privacy frameworks including ISO, NIST, SOC 2, and HIPAA
Quick apply
This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles ... Familiarity with major security and privacy frameworks including ISO, NIST, SOC 2, and HIPAA
Perform security assessments, audits, and gap analysis * Support DevSecOps and infrastructure-as ... Align cloud operations with compliance frameworks (HIPAA, SOC 2, etc.) Must Have Skills: * Hands-on ...
Quick apply
Perform security assessments, audits, and gap analysis * Support DevSecOps and infrastructure-as ... Align cloud operations with compliance frameworks (HIPAA, SOC 2, etc.) Must Have Skills: * Hands-on ...
About AssetWatch AssetWatch is a remote-first industrial condition monitoring company that helps ... Support the annual SOC 2 Type 2 audit cycle, including auditor requests, evidence collection, and ...
About AssetWatch AssetWatch is a remote-first industrial condition monitoring company that helps ... Support the annual SOC 2 Type 2 audit cycle, including auditor requests, evidence collection, and ...
Senior SOC Analyst
$90K - $119K/yr
Support Tier 2 SOC Operations: Responds to escalated alerts, security tickets, and service requests ... Remote Background Check Requirements All candidates for employment will be subject to pre ...
Senior SOC Analyst
$90K - $119K/yr
Support Tier 2 SOC Operations: Responds to escalated alerts, security tickets, and service requests ... Remote Background Check Requirements All candidates for employment will be subject to pre ...
Senior GRC Analyst
San Francisco, CA · On-site +1
$183K - $205K/yr
Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including ... A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity.
Senior GRC Analyst
San Francisco, CA · On-site +1
$183K - $205K/yr
Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including ... A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity.
Remote Role Responsibilities ... Review simulated vendor SOC 2 reports , security questionnaires, and pen-test evidence against a ...
Quick apply
Remote Role Responsibilities ... Review simulated vendor SOC 2 reports , security questionnaires, and pen-test evidence against a ...
SOC Analyst
Washington, DC · Remote
$50 - $55/hr
Hybrid 2 Days Onsite/3 Days Remote in Washington, DC Our client seeks a SOC Analyst to support continuous monitoring, detection, analysis, and response to cybersecurity events across hybrid cloud and ...
Quick apply
SOC Analyst
Washington, DC · Remote
$50 - $55/hr
Hybrid 2 Days Onsite/3 Days Remote in Washington, DC Our client seeks a SOC Analyst to support continuous monitoring, detection, analysis, and response to cybersecurity events across hybrid cloud and ...
SOC Manager
Washington, DC · On-site +1
This role directs Tier 1, Tier 2, and Tier 3 analysts across a 24x7x365 coverage model, sets the ... Remote work requires a high level of trust in our employees, and we strictly adhere to the details ...
SOC Manager
Washington, DC · On-site +1
This role directs Tier 1, Tier 2, and Tier 3 analysts across a 24x7x365 coverage model, sets the ... Remote work requires a high level of trust in our employees, and we strictly adhere to the details ...
SOC Manager
Washington, DC · On-site +1
This role directs Tier 1, Tier 2, and Tier 3 analysts across a 24x7x365 coverage model, sets the ... Remote work requires a high level of trust in our employees, and we strictly adhere to the details ...
SOC Manager
Washington, DC · On-site +1
This role directs Tier 1, Tier 2, and Tier 3 analysts across a 24x7x365 coverage model, sets the ... Remote work requires a high level of trust in our employees, and we strictly adhere to the details ...
Senior Compliance Analyst
Irving, TX · Remote
$60 - $70/hr
... and SOC 2 Type II control frameworks. o Work with stakeholders across the business to collect ... Desired Characteristics: · Strong problem-solving and analytical skills · Attention to detail and ...
Quick apply
Senior Compliance Analyst
Irving, TX · Remote
$60 - $70/hr
... and SOC 2 Type II control frameworks. o Work with stakeholders across the business to collect ... Desired Characteristics: · Strong problem-solving and analytical skills · Attention to detail and ...
Experienced or Senior GRC Analyst
Fort Worth, TX · On-site +1
$84K - $111K/yr
This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles ... Create and refine policies, standards, and procedures aligned with top frameworks including SOC 2, ...
Experienced or Senior GRC Analyst
Fort Worth, TX · On-site +1
$84K - $111K/yr
This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles ... Create and refine policies, standards, and procedures aligned with top frameworks including SOC 2, ...
Experienced or Senior GRC Analyst
Fort Worth, TX · On-site +1
$84K - $111K/yr
This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles ... Create and refine policies, standards, and procedures aligned with top frameworks including SOC 2, ...
Experienced or Senior GRC Analyst
Fort Worth, TX · On-site +1
$84K - $111K/yr
This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles ... Create and refine policies, standards, and procedures aligned with top frameworks including SOC 2, ...
GRC Analysts I
Saint Petersburg, FL · Remote
$88K - $89K/yr
Remote Working Hours: U.S. Eastern Time (ET) business hours Employment Type: Full-Time Level: Entry ... SOC 2, and ISO 27001. Our team works across Governance, Risk & Compliance (GRC), managed ...
Quick apply
GRC Analysts I
Saint Petersburg, FL · Remote
$88K - $89K/yr
Remote Working Hours: U.S. Eastern Time (ET) business hours Employment Type: Full-Time Level: Entry ... SOC 2, and ISO 27001. Our team works across Governance, Risk & Compliance (GRC), managed ...
GRC Analysts I
Saint Petersburg, FL · On-site +1
$90K - $90K/yr
Remote Working Hours: U.S. Eastern Time (ET) business hours Employment Type: Full-Time Level: Entry ... SOC 2, and ISO 27001. Our team works across Governance, Risk & Compliance (GRC), managed ...
GRC Analysts I
Saint Petersburg, FL · On-site +1
$90K - $90K/yr
Remote Working Hours: U.S. Eastern Time (ET) business hours Employment Type: Full-Time Level: Entry ... SOC 2, and ISO 27001. Our team works across Governance, Risk & Compliance (GRC), managed ...
GRC Analysts I
Saint Petersburg, FL · On-site +1
$90K - $90K/yr
Remote Working Hours: U.S. Eastern Time (ET) business hours Employment Type: Full-Time Level: Entry ... SOC 2, and ISO 27001. Our team works across Governance, Risk & Compliance (GRC), managed ...
GRC Analysts I
Saint Petersburg, FL · On-site +1
$90K - $90K/yr
Remote Working Hours: U.S. Eastern Time (ET) business hours Employment Type: Full-Time Level: Entry ... SOC 2, and ISO 27001. Our team works across Governance, Risk & Compliance (GRC), managed ...
... analyses, and compliance validation. Ensure consistency in methodology across frameworks such as: NIST 800-53 / NIST CSF SOC 2 ISO 27001 HIPAA PCI DSS FedRAMP / public sector frameworks Validate the ...
... analyses, and compliance validation. Ensure consistency in methodology across frameworks such as: NIST 800-53 / NIST CSF SOC 2 ISO 27001 HIPAA PCI DSS FedRAMP / public sector frameworks Validate the ...
Security Analyst (SOC)
Hawthorne, CA · On-site +1
$110K - $130K/yr
OR 2+ years of professional experience in information security in lieu of a degree. * Experience ... This role requires you to be onsite in Hawthorne, CA; remote or hybrid work will not be considered.
Security Analyst (SOC)
Hawthorne, CA · On-site +1
$110K - $130K/yr
OR 2+ years of professional experience in information security in lieu of a degree. * Experience ... This role requires you to be onsite in Hawthorne, CA; remote or hybrid work will not be considered.
This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our ... analysis, with appropriate human oversight. * Participate in incident management as the GRC/risk ...
Quick apply
This role is critical to maintaining our SOC 1, SOC 2, and PCI certifications and to raising our ... analysis, with appropriate human oversight. * Participate in incident management as the GRC/risk ...
Remote Soc 2 Analyst information
See salary details
$32K - $41.2K
2% of jobs
$41.2K - $50.5K
7% of jobs
$50.5K - $59.7K
9% of jobs
$64.5K is the 25th percentile. Wages below this are outliers.
$59.7K - $68.9K
12% of jobs
$68.9K - $78.1K
17% of jobs
The median wage is $79.7K / yr.
$78.1K - $87.4K
16% of jobs
$94.8K is the 75th percentile. Wages above this are outliers.
$87.4K - $96.6K
15% of jobs
$96.6K - $105.8K
5% of jobs
$105.8K - $115K
9% of jobs
$115K - $124.3K
4% of jobs
$124.3K - $133.5K
3% of jobs
$32K
$84.2K
$133.5K
How much do remote soc 2 analyst jobs pay per year?
What is a Remote SOC 2 Analyst?
What are the key skills and qualifications needed to thrive as a Remote SOC 2 Analyst?
What are some common challenges faced by Remote SOC 2 Analysts when working with distributed teams?
What is the difference between Remote Soc 2 Analyst vs Remote Security Auditor?
| Aspect | Remote Soc 2 Analyst | Remote Security Auditor |
|---|---|---|
| Certifications | SOC 2, CISSP, CISA | CISA, CISSP, ISO 27001 Lead Auditor |
| Work Environment | Remote, client-facing, compliance-focused | Remote or onsite, audit and assessment-based |
| Industry Usage | Tech, finance, healthcare | Various industries, including finance and healthcare |
Remote Soc 2 Analysts primarily focus on preparing organizations for SOC 2 compliance, ensuring controls meet standards. Remote Security Auditors conduct comprehensive evaluations of security controls across various frameworks. While both roles require similar certifications and often work remotely, Soc 2 Analysts specialize in SOC 2 reports, whereas Security Auditors have a broader scope including multiple standards.
Is a remote SOC 2 analyst still in demand?
What cities are hiring for Remote Soc 2 Analyst jobs?
Cities with the most Remote Soc 2 Analyst job openings:
What are the most commonly searched types of Soc 2 Analyst jobs?
The most popular types of Soc 2 Analyst jobs are:
What states have the most Remote Soc 2 Analyst jobs?
States with the most job openings for Remote Soc 2 Analyst jobs include:
What job categories do people searching Remote Soc 2 Analyst jobs look for?
The top searched job categories for Remote Soc 2 Analyst jobs are:

Full-time
Posted 23 days ago
Job description
OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.
We are a small team that punches above its weight. Every person here has direct impact on the product and our users.
About the Role
Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.
You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl - they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.
If you've ever finished a vendor review and thought this should take a third as long and catch twice as much - and wanted to be the one to fix it - keep reading.
What You'll Do
- Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling - and get vendors live without becoming the bottleneck.
- Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.
- Turn findings into decisions - residual risk and compensating controls, not a spreadsheet of yellow cells.
- Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
- Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.
- Build continuous monitoring for critical vendors and run annual reviews on a real cadence.
- Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.
What We're Looking For
- 4+ years in third-party/vendor security risk or security assessment - real assessment reps, not just program administration.
- Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.
- Technical literacy - cloud architecture, access models, encryption, data flows - enough to know when a vendor's answer doesn't hold up.
- Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.
- A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.
- Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.
Nice to Have
- Experience assessing AI/ML vendors or inference infrastructure
- ISO 42001 or NIST AI RMF
- Scripting and automation to eliminate your own toil
- GRC platform administration (Drata, Vanta, or similar)
- Time at an early-stage startup where you built the function rather than joined it
- CISSP, CISA, CRISC, or CTPRP.
If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.