1

Soc 2 Jobs (NOW HIRING)

You'll be the go-to person for everything from onboarding new hires to managing our SaaS tool stack and supporting our path to SOC 2 compliance. What You'll Own Identity & Access Management

We hold an active ISO 27001 certification and SOC 2 Type II attestation, and security and compliance are central to how we operate and how our customers trust us. This role reports to the Information ...

Lead the company's SOC 2 Type II and HIPAA compliance initiatives from planning through certification. * Develop, draft, and maintain security, IT, and privacy policies aligned with SOC 2, HIPAA ...

Lead the company's SOC 2 Type II and HIPAA compliance initiatives from planning through certification. * Develop, draft, and maintain security, IT, and privacy policies aligned with SOC 2, HIPAA ...

Lead SOC 2 Type II program development * Support FedRAMP readiness and alignment * Risk Management * Assess security risks across systems, services, projects, vendors, and control gaps * Develop and ...

Lead the company's SOC 2 Type II and HIPAA compliance initiatives from planning through certification. * Develop, draft, and maintain security, IT, and privacy policies aligned with SOC 2, HIPAA ...

ISO 27001, SOC 2, PCI-DSS, GDPR, SOX.- Coordinate internal/external audits, documentation, evidence. [devsdata.com], [cybersm.com] Incident Response & Reporting: - Develop incident response plans ...

Lead the company's SOC 2 Type II and HIPAA compliance initiatives from planning through certification. * Develop, draft, and maintain security, IT, and privacy policies aligned with SOC 2, HIPAA ...

Lead the company's SOC 2 Type II and HIPAA compliance initiatives from planning through certification. * Develop, draft, and maintain security, IT, and privacy policies aligned with SOC 2, HIPAA ...

Lead SOC 2 Type II program development * Support FedRAMP readiness and alignment * Risk Management * Assess security risks across systems, services, projects, vendors, and control gaps * Develop and ...

Lead the company's SOC 2 Type II and HIPAA compliance initiatives from planning through certification. * Develop, draft, and maintain security, IT, and privacy policies aligned with SOC 2, HIPAA ...

Lead the company's SOC 2 Type II and HIPAA compliance initiatives from planning through certification. * Develop, draft, and maintain security, IT, and privacy policies aligned with SOC 2, HIPAA ...

Owning and running the company's SOC 2 program and broader security compliance initiatives * Developing and improving security policies, controls, and governance frameworks (SOC 2, ISO 27001, NIST)

Lead the company's SOC 2 Type II and HIPAA compliance initiatives from planning through certification. * Develop, draft, and maintain security, IT, and privacy policies aligned with SOC 2, HIPAA ...

next page

Showing results 1-20

Soc 2 information

See salary details

$11

$48

$80

How much do soc 2 jobs pay per hour?

As of Jun 16, 2026, the average hourly pay for soc 2 in the United States is $48.10, according to ZipRecruiter salary data. Most workers in this role earn between $38.22 and $58.89 per hour, depending on experience, location, and employer.

What are some typical daily responsibilities for a SOC 2 Analyst?

A SOC 2 Analyst is responsible for monitoring security alerts, analyzing potential threats, and coordinating the response to security incidents on a daily basis. They investigate suspicious activity, conduct detailed log analysis, and escalate complex cases to senior team members when necessary. Additionally, SOC 2 Analysts help fine-tune detection systems and may participate in threat hunting exercises to proactively identify vulnerabilities. The role often involves collaborating closely with IT, network, and compliance teams to ensure organizational security standards are maintained.

What jobs make 10,000 a month without a degree?

High-paying jobs that can reach $10,000 a month without a degree include roles such as sales managers, real estate brokers, commercial pilots, and skilled trades like electricians or plumbers. Success in these fields often depends on experience, certifications, or licensing, rather than formal education, and they may require strong interpersonal skills or technical expertise.

How hard is it to get a SOC 2?

Securing a SOC 2 certification involves preparing for an audit by implementing and documenting controls related to security, availability, processing integrity, confidentiality, and privacy. The process can take several months depending on the organization's size and readiness, and requires thorough understanding of compliance standards and internal controls. Professionals often need experience with risk management, security frameworks, and audit procedures to successfully obtain SOC 2.

What is a SOC 2 job?

A SOC 2 job typically refers to roles related to SOC 2 compliance, which ensures that a company’s systems meet security, availability, processing integrity, confidentiality, and privacy standards. Professionals in these roles work on implementing, maintaining, and auditing SOC 2 controls to protect customer data. Common positions include compliance analysts, security auditors, and IT risk managers. These jobs require knowledge of cybersecurity frameworks, risk management, and regulatory compliance.

Can I make $200 a year in cyber security?

A SOC 2 professional typically earns significantly more than $200 annually, as cybersecurity roles generally offer competitive salaries that depend on experience, certifications, and location. Entry-level positions may start around $50,000 per year, with experienced professionals earning higher, making earning only $200 per year highly unlikely. Skills in security frameworks, auditing, and compliance are essential for higher-paying roles in this field.

What jobs in the US pay $300,000 a year?

High-paying jobs that can reach or exceed $300,000 annually include senior roles such as Chief Information Security Officer (CISO), experienced software engineers, investment bankers, and specialized physicians. These positions often require advanced skills, extensive experience, and relevant certifications, and may involve leadership responsibilities or working in high-stakes environments.

What are the key skills and qualifications needed to thrive in the Soc 2 position, and why are they important?

To thrive as a SOC 2 (Security Operations Center Tier 2 Analyst), you need a strong foundation in cybersecurity principles, threat analysis, and incident response, typically backed by a degree in IT or cybersecurity and relevant experience. Familiarity with SIEM tools, intrusion detection/prevention systems, and certifications like CompTIA Security+, CEH, or CISSP is highly valued. Strong analytical thinking, attention to detail, and the ability to communicate technical information clearly are key soft skills for this role. These skills are crucial for accurately detecting, investigating, and escalating security incidents to protect organizational assets.

More about Soc 2 jobs
What cities are hiring for Soc 2 jobs? Cities with the most Soc 2 job openings:
What are the most commonly searched types of Soc 2 jobs? The most popular types of Soc 2 jobs are:
What states have the most Soc 2 jobs? States with the most job openings for Soc 2 jobs include:
Infographic showing various Soc 2 job openings in the United States as of June 2026, with employment types broken down into 75% Full Time, and 25% Temporary. Highlights an 50% In-person, and 50% Remote job distribution, with an average salary of $100,051 per year, or $48.1 per hour.

IT & Security Operations Manager

Clearstory

Walnut Creek, CA • On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 13 days ago

Be an early applicant


Job description

Clearstory is looking for an IT & Security Operations Manager to manage and improve the day-to-day operations of our IT, security compliance, and corporate systems infrastructure.

We've built a solid foundation - SOC 2 compliance tooling in Vanta, structured onboarding and offboarding workflows, a vendor security review process, and a cross-functional data governance program. What we need is a dedicated owner to manage these programs day-to-day, project manage key deliverables, maintain what's already working, and identify opportunities to improve and scale as we grow.

If you thrive as the go-to person for IT, compliance coordination, and keeping an organization running smoothly, this role is for you.

Responsibilities

IT Administration

  • Manage day-to-day identity and access management - Google Workspace admin, Slack admin, AI platform administration, shared inbox management
  • Run employee onboarding provisioning - Day 1 account creation, checklist management, Vanta security onboarding, welcome communications, completion tracking
  • Run employee offboarding - access revocation, system owner coordination, equipment return, deprovisioning verification within SLA
  • Serve as the internal IT point of contact - password resets, hardware troubleshooting, software support, connectivity issues
  • Manage the asset lifecycle - laptop procurement, serial number tracking, equipment reassignment, peripherals ordering
  • Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
  • Execute quarterly and annual access reviews, verifying active users against the employee roster, documenting findings, and remediating stale access
  • Manage Vanta day-to-day - dashboards, weekly compliance summaries, Trust Center access requests, failed test remediation
  • Monitor and drive employee security compliance - agent installs, 1Password provisioning, MFA enforcement, security awareness training
  • Take first pass on inbound customer security questionnaires and maintain an answer library to streamline future responses
  • Track and execute data governance action items from biweekly cross-functional meetings - tool policy enforcement, vendor risk monitoring, etc.

Security & Compliance

  • Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
  • Execute quarterly and annual access reviews, verifying active users against the employee roster, documenting findings, and remediating stale access
  • Manage Vanta day-to-day - dashboards, weekly compliance summaries, Trust Center access requests, failed test remediation
  • Monitor and drive employee security compliance - agent installs, 1Password provisioning, MFA enforcement, security awareness training
  • Take first pass on inbound customer security questionnaires and maintain an answer library to streamline future responses
  • Track and execute data governance action items from biweekly cross-functional meetings - tool policy enforcement, vendor risk monitoring, etc.

Business Operations

  • Maintain and improve a centralized SaaS inventory - tools, seat counts, renewal dates, and costs. Keep a renewal calendar with advance notice to budget owners
  • Manage new software requests - intake, triage, security review routing, approval tracking, provisioning
  • Prepare vendor security assessments - collect SOC 2 reports, DPAs, and documentation for CTO review and approval
  • Support office IT and facilities - conference room AV, key fob provisioning, building management coordination
  • Document key processes - onboarding/offboarding runbooks, SOC 2 evidence collection guides, vendor review steps, AI usage best practices
  • Identify and implement automation opportunities - workflows for onboarding triggers, access request routing, renewal reminders, and offboarding checklists
The Opportunity

This is an opportunity to be the dedicated owner of IT and security operations at a growing SaaS company.

You will:

  • Take ownership of established compliance, IT, and security programs and keep them running smoothly
  • Project manage SOC 2 audit readiness as the company expands its customer base
  • Identify gaps and inefficiencies in existing workflows and fix them
  • Help create scalable processes that support the company through its next stage of growth
  • Work cross-functionally with Engineering, Finance, and GTM teams

Success in this role means Clearstory's IT, security compliance, and corporate systems run reliably and keep getting better over time.

The Company You'll Join

Clearstory is a SaaS platform modernizing how construction companies communicate, approve, and track change orders and related cost workflows. We replace paper, spreadsheets, and email with simple, trusted financial workflows that help contractors get paid accurately and on time.

We are a Series B, 100% SaaS company with strong product-market fit, growing six-figure deals, and a large, underserved TAM. Our customers love us, our retention is strong, and we are building for long-term impact.

Requirements

  • 4-7 years of experience in IT operations, security operations, or SaaS business operations
  • Hands-on SOC 2 evidence collection and audit coordination experience (not just awareness - you've done the work)
  • Google Workspace administration experience (security settings, groups)
  • Experience with compliance platforms like Vanta, Drata, or similar
  • SaaS vendor management experience - renewals, license optimization, procurement intake
  • Comfort with automation tools to streamline established workflows
  • The ability to work directly with a CTO on security operations without needing hand-holding on fundamentals
  • A builder's mindset - you'd rather create a process than follow a broken one, and you document what you build

Strong plus if you have:

  • Experience completing customer security questionnaires
  • Office or facilities coordination at a startup
  • MDM deployment experience
About You

You're a hands-on operator who gets things done without being asked. You see a problem, fix it, and move on - whether that's a password reset at 9am or prepping access review documentation at 2pm. Task size doesn't faze you because you know the small stuff and the big stuff both matter at a company this size.

You're organized and reliable. When you're asked to coordinate an offboarding or chase down a vendor's SOC 2 report, it gets done on time and nothing slips. You're comfortable working across teams - Engineering, Finance, GTM - and you can translate security and IT requirements into plain language for people who don't live in that world.

You understand that IT and security operations at a growing company isn't glamorous - but you also know it's foundational. You've seen what happens when access deprovisioning slips or when SOC 2 evidence collection becomes a fire drill. You're the person who keeps things running so that doesn't happen.

This is not a security engineering or CISO-track role - the CTO owns security architecture and policy. This is not a pure helpdesk role either - IT support is part of the job, but compliance coordination and process maintenance are the core.

Benefits

  • Competitive salary and meaningful equity ownership
  • Comprehensive health, dental, and vision coverage
  • 401(k) plan to support your long-term financial goals
  • Flexible PTO and company holidays
  • Remote-friendly work environment with flexibility and autonomy
  • Opportunity to work alongside a high-caliber, mission-driven team
  • Career growth and leadership opportunities as the company scales