1

Soc Auditor Jobs (NOW HIRING)

IT Audit Consultant (SOC 1 / SOC 2)

$85K - $105K/yr

  • Medical

  • Retirement

  • PTO

Lead SOC 1 and SOC 2 engagements from planning through report issuance, ensuring high-quality ... Experience mentoring or supervising junior auditors or consultants. * Excellent written and verbal ...

Evaluate SOC report scope, control design, testing results, and auditor opinions. * Collect and analyze supporting evidence from control owners. * Assess control exceptions, coordinate corrective ...

Internal Auditor II

Bloomington, MN · On-site

$70 - $95/hr

Evaluate SOC report scope, control design, testing results, and auditor opinions. * Collect and analyze supporting evidence from control owners. * Assess control exceptions, coordinate corrective ...

Evaluate SOC report scope, control design, testing results, and auditor opinions. * Collect and analyze supporting evidence from control owners. * Assess control exceptions, coordinate corrective ...

Internal Auditor II

Bloomington, MN · On-site

$65K - $97K/yr

Evaluate SOC report scope, control design, testing results, and auditor opinions. * Collect and analyze supporting evidence from control owners. * Assess control exceptions, coordinate corrective ...

GRC Compliance Auditor

Dallas, TX · On-site

$120 - $160/hr

This role owns the day-to-day execution of NMC²'s SOC 2 Type II and ISO 27001 compliance ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. #J-18808-Ljbffr

New

$120 - $160/hr

This role owns the day-to-day execution of NMC²'s SOC 2 Type II and ISO 27001 compliance ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. #J-18808-Ljbffr

New

IT Auditor

Austin, TX · On-site

$90 - $130/hr

Familiarity with HIPAA, HITRUST, or SOC 2 frameworks. * Experience auditing cloud-based healthcare systems. * Exposure to cybersecurity or DevSecOps environments. * Certifications such as CISA, CISSP ...

New

GRC Compliance Auditor

Dallas, TX · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

This role owns the day-to-day execution of NMC²'s SOC 2 Type II and ISO 27001 compliance ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. It is impossible to list ...

Manager - SOC Reporting

Chicago, IL · On-site

$143K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

As Manager of SOC Reporting, you'll lead JLL's Service Organization Control (SOC) audit programs ... Serving as the strategic liaison between external auditors and internal stakeholders by ...

GRC Compliance Auditor

Dallas, TX · On-site

$90 - $140/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

This role owns the day-to-day execution of NMC2's SOC 2 Type II and ISO 27001 compliance programmes ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC.*It is impossible to list ...

GRC Compliance Auditor

Dallas, TX

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

This role owns the day-to-day execution of NMC's SOC 2 Type II and ISO 27001 compliance programmes ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. It is impossible to list ...

Senior GRC Analyst I, SOC 1 & SOC 2

California, MO · On-site

$66.40 - $101/hr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Senior GRC Analyst I, SOC 1 & SOC 2 Department: Governance, Risk & Compliance Employment Type ... Chris Roe Compensation: $66,400 - $101,000 / year The Senior GRC Auditor I is responsible for ...

SOC Leader

Bloomington, MN · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Perform SOC examinations and understand audit guidelines ... Understand information technology controls, concepts and auditing, or be able to lead and mentor ...

SOC Leader

Bloomington, MN · On-site +1

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Perform SOC examinations and understand audit guidelines ... Understand information technology controls, concepts and auditing, or be able to lead and mentor ...

next page

Showing results 1-20

Soc Auditor information

See salary details

$38.5K

$92.8K

$151K

How much do soc auditor jobs pay per year?

As of Aug 19, 2026, the average yearly pay for soc auditor in the United States is $92,797.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,000.00 and $112,000.00 per year, depending on experience, location, and employer.

What is a SOC auditor?

SOC Auditors are professionals who evaluate an organization’s systems and controls, typically focusing on security, availability, processing integrity, confidentiality, and privacy. Their primary role is to conduct audits based on the System and Organization Controls (SOC) framework, such as SOC 1, SOC 2, or SOC 3 reports. SOC Auditors assess whether a company’s internal controls are effective and compliant with industry standards, providing assurance to clients and stakeholders about the organization’s risk management and data protection practices.

What are the key skills and qualifications needed to thrive as a SOC auditor, and why are they important?

To thrive as a SOC Auditor, you need a solid understanding of auditing principles, risk assessment, and information security frameworks, often supported by a degree in accounting, information systems, or a related field and relevant certifications like CISA or CPA. Familiarity with audit management software, GRC tools, and systems such as SSAE 18 is typically required. Strong analytical thinking, attention to detail, and effective communication skills help SOC Auditors excel in assessing controls and reporting findings. These competencies are crucial for ensuring organizations meet compliance requirements, manage risks, and maintain stakeholder trust.

What are some common challenges SOC auditors face when working with clients during the audit process?

SOC Auditors often encounter challenges such as coordinating with clients to obtain timely and complete evidence, clarifying complex control environments, and ensuring that all relevant stakeholders understand the scope and requirements of the audit. Communication skills are crucial, as auditors must balance maintaining independence with providing clear guidance. Additionally, adapting to different client industries and varying levels of preparedness can make each engagement unique, requiring flexibility and strong organizational skills.

What is the difference between Soc Auditor vs Security Analyst?

AspectSoc AuditorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISACompTIA Security+, CISSP
Work EnvironmentAudit firms, consulting companies, in-house audit teamsIT departments, cybersecurity firms, corporate security teams
Industry UsageUsed mainly in compliance and audit contextsUsed in threat detection and security management

While both roles focus on security, a Soc Auditor primarily conducts audits to ensure compliance with security standards, whereas a Security Analyst monitors and responds to security threats. The Soc Auditor's role is more about assessment and compliance, while the Security Analyst actively manages security incidents.

How to become a SOC auditor?

To become a SOC auditor, individuals typically need a background in accounting, information security, or IT auditing, along with relevant certifications such as CPA, CISA, or CISSP. Gaining experience in cybersecurity, internal controls, and audit procedures is essential, and many employers prefer candidates with knowledge of SOC reporting standards and audit tools. Continuous professional development and understanding of compliance frameworks are also important for this role.
More about Soc Auditor jobs

What cities are hiring for Soc Auditor jobs?

Cities with the most Soc Auditor job openings:

What states have the most Soc Auditor jobs?

States with the most job openings for Soc Auditor jobs include:

Infographic showing various Soc Auditor job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 8% Part Time, 2% Contract, and 1% Nights. Highlights an 88% Physical, 5% Hybrid, and 7% Remote job distribution, with an average salary of $92,797 per year, or $44.6 per hour.

SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead

FYI - For Your Information, Inc.

Silver Spring, MD • On-site

$80 - $100/hr

Other

Retirement

Re-posted 2 days ago


Job description

About the Role

FYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an active SOC 2 Type 2 program across Security, Availability, Processing Integrity, Confidentiality, and Privacy. This role will own the SOC 2 domain in a fractional capacity, including evidence review, control operation support, auditor communication support, recurring compliance cadence, and SaaS/cloud control maturity. The right candidate has supported real SOC 2 Type 2 audits and can work with engineering, IT, security, HR, operations, leadership, and auditors.

Essential Responsibilities and Duties
  • Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria.
  • Review evidence requests and determine whether evidence is complete, partial, missing, stale, unclear, or misaligned to the control being tested.
  • Draft and review auditor responses, management explanations, control narratives, and evidence summaries.
  • Support control operations for access reviews, vendor risk management, risk assessment, policy review, security awareness, incident response, change management, and security steering activities.
  • Review evidence for IAM, MFA, logging, monitoring, encryption, vulnerability management, secure SDLC, code review, release approvals, CI/CD security, SAST, DAST, SCA, backups, availability, confidentiality, processing integrity, and privacy controls.
  • Coordinate with control owners to obtain timestamped, complete, and audit-ready artifacts.
  • Help maintain the recurring compliance calendar for monthly, quarterly, and annual SOC 2 control activities.
  • Support policy and documentation management, version control, approvals, and annual review cadence.
  • Identify control design gaps, operating effectiveness gaps, evidence issues, and audit risks.
  • Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.
Required Qualifications
  • 8+ years of cybersecurity, GRC, IT audit, compliance, SaaS security, cloud security, security consulting, or related experience.
  • GRC platform experience (Drata preferred, others include Vanta or SecureFrame)
  • Direct hands‑on experience supporting SOC 2 Type 2 audits.
  • Experience with SaaS or cloud‑hosted application environments.
  • Experience reviewing evidence for control design and operating effectiveness.
  • Ability to translate audit requirements into operational tasks for engineering, IT, security, HR, legal, operations, and leadership stakeholders.
  • Strong written communication skills and ability to produce auditor‑ready explanations.
  • Ability to drive control owners and follow‑ups without constant prompting.
  • Ability to work through ambiguity and produce clean, organized, audit‑ready documentation.
Nice to Have
  • Prior SOC 2 auditor, CPA‑firm, or audit‑support experience.
  • Experience with all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
  • CISA, CISSP, CISM, Security+, CPA, ISO 27001 Lead Auditor, or equivalent certification.
  • Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, CI/CD tooling, SAST, DAST, SCA, vulnerability management, or cloud security tools.
  • PCI DSS familiarity, especially where SOC 2 controls overlap with PCI requirements.
Expected Deliverables
  • SOC 2 Five‑TSC evidence and gap tracker inputs.
  • Control evidence sufficiency reviews.
  • Auditor response drafts and management‑response drafts.
  • Control narrative and control‑description updates.
  • Recurring compliance calendar inputs for access reviews, vendor reviews, risk assessments, policy reviews, steering meetings, and evidence refresh cycles.
  • Policy, procedure, and documentation review notes.
  • SOC 2 blocker, risk, and next‑action summaries.
Operating Style Required

This role requires a senior operator who can own the SOC 2 lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.

Benefits
  • Opportunity to work a hybrid work schedule
  • A knowledgeable, high‑achieving, diverse, experienced, and fun team.
  • The chance to be part of a rapidly growing company and the next success story.
  • A competitive base salary with a loaded benefits package plus 401K.
  • Tuition/education assistance, personal computer allowance, pet insurance.
#J-18808-Ljbffr