1

Soc 2 Auditor Jobs (NOW HIRING)

Auditor, SOC2

Dallas, TX · Remote

$80K - $85K/yr

We are seeking a SOC 2 Auditor to join our growing team. This role requires strong client-facing skills and the ability to manage multiple client audits from start to finish. Essential Duties and ...

Auditor, SOC2

Dallas, TX · Remote

$80K - $85K/yr

We are seeking a SOC 2 Auditor to join our growing team. This role requires strong client-facing skills and the ability to manage multiple client audits from start to finish.

Auditor, SOC2

Dallas, TX · On-site

$80K - $85K/yr

We are seeking a SOC 2 Auditor to join our growing team. This role requires strong client-facing skills and the ability to manage multiple client audits from start to finish. Essential Duties and ...

TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...

Lead and perform SOC 1 and SOC 2 examinations for clients from planning through report issuance ... Experience mentoring or supervising junior auditors or consultants. * Excellent written and verbal ...

$80 - $100/hr

Own the day-to-day relationship with our SOC 2 auditor and any compliance automation platform (e.g., Vanta,Drata,Secureframe) * Collect, organize, andsubmitevidence requested by the auditor across ...

GRC Compliance Auditor

Dallas, TX · On-site

$125 - $150/hr

This role owns the day-to-day execution of NMC²'s SOC 2 Type II and ISO 27001 compliance ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. #J-18808-Ljbffr

$125 - $150/hr

This role owns the day-to-day execution of NMC²'s SOC 2 Type II and ISO 27001 compliance ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. #J-18808-Ljbffr

GRC Compliance Auditor

Dallas, TX · On-site

$100 - $125/hr

This role owns the day-to-day execution of NMC2's SOC 2 Type II and ISO 27001 compliance programmes ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC.*It is impossible to list ...

This role owns the day-to-day execution of NMC's SOC 2 Type II and ISO 27001 compliance programmes ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. It is impossible to list ...

Support audits covering SOX, SOC 2, ISO 27001, PCI and other emerging audit requirements. * Manage audit schedules, scope definition and logistics with external auditors. * Act as a primary liaison ...

next page

Showing results 1-20

Soc 2 Auditor information

See salary details

$38.5K

$92.8K

$151K

How much do soc 2 auditor jobs pay per year?

As of Sep 9, 2026, the average yearly pay for soc 2 auditor in the United States is $92,797.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,000.00 and $112,000.00 per year, depending on experience, location, and employer.

What is a SOC 2 auditor?

SOC 2 auditors are independent professionals or firms who evaluate and report on a service organization's controls relevant to security, availability, processing integrity, confidentiality, and privacy. They conduct audits according to the American Institute of Certified Public Accountants (AICPA) standards and issue SOC 2 reports that help organizations demonstrate their commitment to protecting customer data. SOC 2 auditors assess whether a company's systems and processes meet the trust service criteria and identify areas for improvement. Their reports are often required by clients or regulators to ensure compliance and risk management.

What are the key skills and qualifications needed to thrive as a SOC 2 auditor?

To thrive as a SOC 2 Auditor, you need a solid understanding of IT risk management, information security principles, and accounting or audit practices, often supported by a relevant degree or certifications like CPA, CISA, or CISSP. Familiarity with audit management tools, compliance frameworks, and systems such as GRC platforms is essential. Strong analytical skills, attention to detail, and clear communication help auditors interpret complex data and interact with clients effectively. These skills and qualifications are crucial for ensuring organizations meet compliance standards and maintain trust with stakeholders.

What are some common challenges faced by SOC 2 auditors during client assessments?

SOC 2 Auditors often encounter challenges such as interpreting complex or ambiguous control environments, managing tight project timelines, and ensuring that clients fully understand the requirements for compliance. Additionally, auditors may need to navigate varying levels of documentation maturity across organizations, which can require extra time for evidence gathering and clarification. Effective communication and adaptability are essential, as auditors frequently collaborate with diverse client teams and must balance objectivity with supportive guidance throughout the assessment process.

What is the difference between Soc 2 Auditor vs Security Analyst?

AspectSoc 2 AuditorSecurity Analyst
CertificationsCPA, CISA, or SOC-specific certificationsCISSP, CISA, Security+
Work EnvironmentAudit firms, consulting companies, client sitesIn-house security teams, IT departments
Industry UsageAuditing organizations, compliance firmsTech companies, financial institutions

While both roles focus on security and compliance, a Soc 2 Auditor primarily conducts audits to assess controls for SOC 2 reports, ensuring organizations meet trust service criteria. A Security Analyst monitors and implements security measures within an organization to prevent breaches. The Soc 2 Auditor evaluates controls externally, whereas the Security Analyst works internally to maintain security posture.

How do I become a SOC 2 auditor?

To become a SOC 2 auditor, professionals typically need a background in information security, IT auditing, or accounting, along with relevant certifications such as CPA, CISA, or CISSP. Gaining experience in cybersecurity, internal controls, and audit procedures is essential, and many auditors pursue specialized training in SOC 2 frameworks offered by accredited organizations.

How much does a SOC 2 auditor make?

A SOC 2 auditor's salary typically ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Senior auditors or those with specialized skills can earn higher salaries, especially in larger organizations or regions with a high cost of living.

What are popular job titles related to Soc 2 Auditor jobs?

For Soc 2 Auditor jobs, the most frequently searched job titles are:

Infographic showing various Soc 2 Auditor job openings in the United States as of September 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $92,797 per year, or $44.6 per hour.

SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead

Silver Spring, MD • On-site

FYI - For Your Information, Inc.
IT Services • 51 - 200 employees

$80 - $100/hr

Other

Retirement

Re-posted 23 days ago


Job description

About the Role

FYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an active SOC 2 Type 2 program across Security, Availability, Processing Integrity, Confidentiality, and Privacy. This role will own the SOC 2 domain in a fractional capacity, including evidence review, control operation support, auditor communication support, recurring compliance cadence, and SaaS/cloud control maturity. The right candidate has supported real SOC 2 Type 2 audits and can work with engineering, IT, security, HR, operations, leadership, and auditors.

Essential Responsibilities and Duties
  • Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria.
  • Review evidence requests and determine whether evidence is complete, partial, missing, stale, unclear, or misaligned to the control being tested.
  • Draft and review auditor responses, management explanations, control narratives, and evidence summaries.
  • Support control operations for access reviews, vendor risk management, risk assessment, policy review, security awareness, incident response, change management, and security steering activities.
  • Review evidence for IAM, MFA, logging, monitoring, encryption, vulnerability management, secure SDLC, code review, release approvals, CI/CD security, SAST, DAST, SCA, backups, availability, confidentiality, processing integrity, and privacy controls.
  • Coordinate with control owners to obtain timestamped, complete, and audit-ready artifacts.
  • Help maintain the recurring compliance calendar for monthly, quarterly, and annual SOC 2 control activities.
  • Support policy and documentation management, version control, approvals, and annual review cadence.
  • Identify control design gaps, operating effectiveness gaps, evidence issues, and audit risks.
  • Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.
Required Qualifications
  • 8+ years of cybersecurity, GRC, IT audit, compliance, SaaS security, cloud security, security consulting, or related experience.
  • GRC platform experience (Drata preferred, others include Vanta or SecureFrame)
  • Direct hands‑on experience supporting SOC 2 Type 2 audits.
  • Experience with SaaS or cloud‑hosted application environments.
  • Experience reviewing evidence for control design and operating effectiveness.
  • Ability to translate audit requirements into operational tasks for engineering, IT, security, HR, legal, operations, and leadership stakeholders.
  • Strong written communication skills and ability to produce auditor‑ready explanations.
  • Ability to drive control owners and follow‑ups without constant prompting.
  • Ability to work through ambiguity and produce clean, organized, audit‑ready documentation.
Nice to Have
  • Prior SOC 2 auditor, CPA‑firm, or audit‑support experience.
  • Experience with all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
  • CISA, CISSP, CISM, Security+, CPA, ISO 27001 Lead Auditor, or equivalent certification.
  • Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, CI/CD tooling, SAST, DAST, SCA, vulnerability management, or cloud security tools.
  • PCI DSS familiarity, especially where SOC 2 controls overlap with PCI requirements.
Expected Deliverables
  • SOC 2 Five‑TSC evidence and gap tracker inputs.
  • Control evidence sufficiency reviews.
  • Auditor response drafts and management‑response drafts.
  • Control narrative and control‑description updates.
  • Recurring compliance calendar inputs for access reviews, vendor reviews, risk assessments, policy reviews, steering meetings, and evidence refresh cycles.
  • Policy, procedure, and documentation review notes.
  • SOC 2 blocker, risk, and next‑action summaries.
Operating Style Required

This role requires a senior operator who can own the SOC 2 lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.

Benefits
  • Opportunity to work a hybrid work schedule
  • A knowledgeable, high‑achieving, diverse, experienced, and fun team.
  • The chance to be part of a rapidly growing company and the next success story.
  • A competitive base salary with a loaded benefits package plus 401K.
  • Tuition/education assistance, personal computer allowance, pet insurance.
#J-18808-Ljbffr