2

Remote Soc 2 Analyst Jobs (NOW HIRING)

You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a ... Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the ...

GRC Analyst

$134K - $202K/yr

... SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company ... You will report to the Head of GRC and will be located ((remote, onsite, hybrid)). Think you may ...

About AssetWatch AssetWatch is a remote-first industrial condition monitoring company that helps ... Support the annual SOC 2 Type 2 audit cycle, including auditor requests, evidence collection, and ...

Senior SOC Analyst

$90K - $119K/yr

Support Tier 2 SOC Operations: Responds to escalated alerts, security tickets, and service requests ... Remote Background Check Requirements All candidates for employment will be subject to pre ...

Senior GRC Analyst

San Francisco, CA · On-site +1

$183K - $205K/yr

Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including ... A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity.

SOC Analyst

Washington, DC · Remote

$50 - $55/hr

Hybrid 2 Days Onsite/3 Days Remote in Washington, DC Our client seeks a SOC Analyst to support continuous monitoring, detection, analysis, and response to cybersecurity events across hybrid cloud and ...

This role directs Tier 1, Tier 2, and Tier 3 analysts across a 24x7x365 coverage model, sets the ... Remote work requires a high level of trust in our employees, and we strictly adhere to the details ...

This role directs Tier 1, Tier 2, and Tier 3 analysts across a 24x7x365 coverage model, sets the ... Remote work requires a high level of trust in our employees, and we strictly adhere to the details ...

... and SOC 2 Type II control frameworks. o Work with stakeholders across the business to collect ... Desired Characteristics: · Strong problem-solving and analytical skills · Attention to detail and ...

Experienced or Senior GRC Analyst

Fort Worth, TX · On-site +1

$84K - $111K/yr

This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles ... Create and refine policies, standards, and procedures aligned with top frameworks including SOC 2, ...

GRC Analysts I

Saint Petersburg, FL · Remote

$88K - $89K/yr

Remote Working Hours: U.S. Eastern Time (ET) business hours Employment Type: Full-Time Level: Entry ... SOC 2, and ISO 27001. Our team works across Governance, Risk & Compliance (GRC), managed ...

GRC Analysts I

Saint Petersburg, FL · On-site +1

$90K - $90K/yr

Remote Working Hours: U.S. Eastern Time (ET) business hours Employment Type: Full-Time Level: Entry ... SOC 2, and ISO 27001. Our team works across Governance, Risk & Compliance (GRC), managed ...

GRC Analysts I

Saint Petersburg, FL · On-site +1

$90K - $90K/yr

Remote Working Hours: U.S. Eastern Time (ET) business hours Employment Type: Full-Time Level: Entry ... SOC 2, and ISO 27001. Our team works across Governance, Risk & Compliance (GRC), managed ...

... analyses, and compliance validation. Ensure consistency in methodology across frameworks such as: NIST 800-53 / NIST CSF SOC 2 ISO 27001 HIPAA PCI DSS FedRAMP / public sector frameworks Validate the ...

Security Analyst (SOC)

Hawthorne, CA · On-site +1

$110K - $130K/yr

OR 2+ years of professional experience in information security in lieu of a degree. * Experience ... This role requires you to be onsite in Hawthorne, CA; remote or hybrid work will not be considered.

Showing results 41-60

Remote Soc 2 Analyst information

See salary details

$32K

$84.2K

$133.5K

How much do remote soc 2 analyst jobs pay per year?

As of Sep 4, 2026, the average yearly pay for remote soc 2 analyst in the United States is $84,207.00, according to ZipRecruiter salary data. Most workers in this role earn between $65,000.00 and $98,500.00 per year, depending on experience, location, and employer.

What is a Remote SOC 2 Analyst?

A Remote SOC 2 Analyst is a cybersecurity professional who works remotely to help organizations achieve and maintain SOC 2 compliance. SOC 2 (Service Organization Control 2) is a set of standards designed to ensure service providers securely manage data to protect the privacy and interests of their clients. The analyst assesses an organization's security controls, policies, and procedures, identifies gaps, and recommends improvements. They also assist with preparing for SOC 2 audits, managing documentation, and ensuring that security practices align with SOC 2 requirements, all while working from a remote location.

What are the key skills and qualifications needed to thrive as a Remote SOC 2 Analyst?

To excel as a Remote SOC 2 Analyst, you need a solid understanding of information security, risk assessment, and compliance frameworks, typically supported by a degree in information security or related fields. Familiarity with tools like GRC platforms, audit management systems, and certifications such as CISA or CISSP are often required. Strong analytical thinking, attention to detail, and effective communication are vital soft skills for interpreting controls and collaborating with clients remotely. These skills ensure accurate assessments, maintain regulatory compliance, and enable efficient communication in a distributed work environment.

What are some common challenges faced by Remote SOC 2 Analysts when working with distributed teams?

Remote SOC 2 Analysts often face challenges related to communication and collaboration, particularly when coordinating with IT, security, and compliance teams across different locations and time zones. Ensuring consistent documentation and maintaining up-to-date evidence for audits can require proactive organization and regular virtual check-ins. Leveraging collaboration tools and establishing clear processes helps streamline workflows and ensures everyone stays aligned on compliance tasks, despite the physical distance.

What is the difference between Remote Soc 2 Analyst vs Remote Security Auditor?

AspectRemote Soc 2 AnalystRemote Security Auditor
CertificationsSOC 2, CISSP, CISACISA, CISSP, ISO 27001 Lead Auditor
Work EnvironmentRemote, client-facing, compliance-focusedRemote or onsite, audit and assessment-based
Industry UsageTech, finance, healthcareVarious industries, including finance and healthcare

Remote Soc 2 Analysts primarily focus on preparing organizations for SOC 2 compliance, ensuring controls meet standards. Remote Security Auditors conduct comprehensive evaluations of security controls across various frameworks. While both roles require similar certifications and often work remotely, Soc 2 Analysts specialize in SOC 2 reports, whereas Security Auditors have a broader scope including multiple standards.

Is a remote SOC 2 analyst still in demand?

Remote SOC 2 analysts are in strong demand due to increasing cybersecurity regulations and the need for organizations to demonstrate compliance. Skills in security frameworks, audit processes, and familiarity with tools like GRC platforms enhance job prospects in this field.
More about Remote Soc 2 Analyst jobs

What cities are hiring for Remote Soc 2 Analyst jobs?

Cities with the most Remote Soc 2 Analyst job openings:

What are the most commonly searched types of Soc 2 Analyst jobs?

The most popular types of Soc 2 Analyst jobs are:

What states have the most Remote Soc 2 Analyst jobs?

States with the most job openings for Remote Soc 2 Analyst jobs include:

Infographic showing various Remote Soc 2 Analyst job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 6% Part Time, and 5% Contract. Highlights an 82% Physical, 7% Hybrid, and 11% Remote job distribution, with an average salary of $84,207 per year, or $40.5 per hour.

Full-time

Posted 23 days ago


Job description

About OpenRouter
OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.
We are a small team that punches above its weight. Every person here has direct impact on the product and our users.
About the Role
Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.
You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl - they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.
If you've ever finished a vendor review and thought this should take a third as long and catch twice as much - and wanted to be the one to fix it - keep reading.
What You'll Do
  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling - and get vendors live without becoming the bottleneck.
  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.
  • Turn findings into decisions - residual risk and compensating controls, not a spreadsheet of yellow cells.
  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.
  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.
  • Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.

What We're Looking For
  • 4+ years in third-party/vendor security risk or security assessment - real assessment reps, not just program administration.
  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.
  • Technical literacy - cloud architecture, access models, encryption, data flows - enough to know when a vendor's answer doesn't hold up.
  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.
  • A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.
  • Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.

Nice to Have
  • Experience assessing AI/ML vendors or inference infrastructure
  • ISO 42001 or NIST AI RMF
  • Scripting and automation to eliminate your own toil
  • GRC platform administration (Drata, Vanta, or similar)
  • Time at an early-stage startup where you built the function rather than joined it
  • CISSP, CISA, CRISC, or CTPRP.

If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.