Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria. * Review evidence requests and determine whether evidence is complete, partial ...
Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria. * Review evidence requests and determine whether evidence is complete, partial ...
About the roleFYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an ... Draft and review auditor responses, management explanations, control narratives, and evidence ...
Quick apply
About the roleFYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an ... Draft and review auditor responses, management explanations, control narratives, and evidence ...
Auditor, SOC2
Dallas, TX · On-site
$80K - $85K/yr
We are seeking a SOC 2 Auditor to join our growing team. This role requires strong client-facing skills and the ability to manage multiple client audits from start to finish. Essential Duties and ...
Auditor, SOC2
Dallas, TX · On-site
$80K - $85K/yr
We are seeking a SOC 2 Auditor to join our growing team. This role requires strong client-facing skills and the ability to manage multiple client audits from start to finish. Essential Duties and ...
Auditor, SOC2
Dallas, TX · Remote
We are seeking a SOC 2 Auditor to join our growing team. This role requires strong client-facing skills and the ability to manage multiple client audits from start to finish.
Quick apply
Auditor, SOC2
Dallas, TX · Remote
We are seeking a SOC 2 Auditor to join our growing team. This role requires strong client-facing skills and the ability to manage multiple client audits from start to finish.
Auditor, SOC2
Dallas, TX · Remote
$80K - $85K/yr
We are seeking a SOC 2 Auditor to join our growing team. This role requires strong client-facing skills and the ability to manage multiple client audits from start to finish.
Auditor, SOC2
Dallas, TX · Remote
$80K - $85K/yr
We are seeking a SOC 2 Auditor to join our growing team. This role requires strong client-facing skills and the ability to manage multiple client audits from start to finish.
Technical Writer - SOC 2 (Compliance | Financial Data) We're looking for an experienced Technical ... Experience working with auditors or third-party assessors * Familiarity with SaaS, cloud ...
Technical Writer - SOC 2 (Compliance | Financial Data) We're looking for an experienced Technical ... Experience working with auditors or third-party assessors * Familiarity with SaaS, cloud ...
TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...
Quick apply
TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...
SOC 2 Assessor (Part time & Remote)
$50 - $90/hr
TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...
New
SOC 2 Assessor (Part time & Remote)
$50 - $90/hr
TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...
New
SOC 2 Assessor (Part time & Remote)
Sterling, VA · On-site +1
$50 - $90/hr
TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...
SOC 2 Assessor (Part time & Remote)
Sterling, VA · On-site +1
$50 - $90/hr
TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...
IT Audit Consultant (SOC 1 / SOC 2)
$85K - $105K/yr
Lead SOC 1 and SOC 2 engagements from planning through report issuance, ensuring high-quality ... Experience mentoring or supervising junior auditors or consultants. * Excellent written and verbal ...
IT Audit Consultant (SOC 1 / SOC 2)
$85K - $105K/yr
Lead SOC 1 and SOC 2 engagements from planning through report issuance, ensuring high-quality ... Experience mentoring or supervising junior auditors or consultants. * Excellent written and verbal ...
GRC Compliance Auditor
Dallas, TX · On-site
This role owns the day-to-day execution of NMC²'s SOC 2 Type II and ISO 27001 compliance ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. It is impossible to list ...
GRC Compliance Auditor
Dallas, TX · On-site
This role owns the day-to-day execution of NMC²'s SOC 2 Type II and ISO 27001 compliance ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. It is impossible to list ...
This role owns the day-to-day execution of NMC's SOC 2 Type II and ISO 27001 compliance programmes ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. It is impossible to list ...
This role owns the day-to-day execution of NMC's SOC 2 Type II and ISO 27001 compliance programmes ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. It is impossible to list ...
Cybersecurity Account Associate
Bozeman, MT · On-site
$15 - $20/hr
Support senior auditors in performing control walkthroughs, scheduling interviews, and documenting client processes related to SOC 2 trust services criteria. * Monitor project timelines, update ...
Cybersecurity Account Associate
Bozeman, MT · On-site
$15 - $20/hr
Support senior auditors in performing control walkthroughs, scheduling interviews, and documenting client processes related to SOC 2 trust services criteria. * Monitor project timelines, update ...
Senior DevOps Security Lead
Coppell, TX · On-site
$170K - $175K/yr
Manage the SOC 2 auditor relationship and readiness milestones. * Manage AWS Cognito identity integration, backups, and disaster-recovery procedures. * Monitor platform uptime percentage (target 99 ...
Senior DevOps Security Lead
Coppell, TX · On-site
$170K - $175K/yr
Manage the SOC 2 auditor relationship and readiness milestones. * Manage AWS Cognito identity integration, backups, and disaster-recovery procedures. * Monitor platform uptime percentage (target 99 ...
Senior Security Assessor
Plano, TX · On-site
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Information Security Auditor
San Francisco, CA · On-site
$166K - $170K/yr
San Francisco, CA TITLE: Information Security Auditor DUTIES: Lead a team that provides ... Experience conducting Information Security (IS) Audits compliant with ISO 27001:2013 and SOC 2 Type ...
Information Security Auditor
San Francisco, CA · On-site
$166K - $170K/yr
San Francisco, CA TITLE: Information Security Auditor DUTIES: Lead a team that provides ... Experience conducting Information Security (IS) Audits compliant with ISO 27001:2013 and SOC 2 Type ...
Soc Two Auditor information
See salary details
$38.5K - $48.7K
3% of jobs
$48.7K - $59K
11% of jobs
$59K - $69.2K
8% of jobs
$72.5K is the 25th percentile. Wages below this are outliers.
$69.2K - $79.4K
11% of jobs
The median wage is $88.3K / yr.
$79.4K - $89.6K
20% of jobs
$89.6K - $99.9K
13% of jobs
$108K is the 75th percentile. Wages above this are outliers.
$99.9K - $110.1K
12% of jobs
$110.1K - $120.3K
11% of jobs
$120.3K - $130.5K
9% of jobs
$130.5K - $140.8K
3% of jobs
$140.8K - $151K
0% of jobs
$38.5K
$92.8K
$151K
How much do soc two auditor jobs pay per year?
What is the difference between Soc Two Auditor vs Soc Two Consultant?
| Aspect | Soc Two Auditor | Soc Two Consultant |
|---|---|---|
| Certifications | Typically holds CPA, CISA, or similar certifications | Often has similar certifications but focuses on advisory roles |
| Work Environment | Performs audits within organizations, often in finance or IT departments | Provides advisory services, assessments, and recommendations to clients |
| Employer & Industry Usage | Employed by organizations or audit firms to conduct SOC 2 audits | Works for consulting firms or independently to advise on SOC 2 compliance |
While both roles focus on SOC 2 compliance, a Soc Two Auditor conducts formal audits to assess compliance, whereas a Soc Two Consultant provides guidance and recommendations to help organizations prepare for audits.

SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
Silver Spring, MD • On-site
Full-time
Retirement
Re-posted 21 days ago
Job description
About the role
FYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an active SOC 2 Type 2 program across Security, Availability, Processing Integrity, Confidentiality, and Privacy. This role will own the SOC 2 domain in a fractional capacity, including evidence review, control operation support, auditor communication support, recurring compliance cadence, and SaaS/cloud control maturity. The right candidate has supported real SOC 2 Type 2 audits and can work with engineering, IT, security, HR, operations, leadership, and auditors.
Essential responsibilities and duties
- Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria.
- Review evidence requests and determine whether evidence is complete, partial, missing, stale, unclear, or misaligned to the control being tested.
- Draft and review auditor responses, management explanations, control narratives, and evidence summaries.
- Support control operations for access reviews, vendor risk management, risk assessment, policy review, security awareness, incident response, change management, and security steering activities.
- Review evidence for IAM, MFA, logging, monitoring, encryption, vulnerability management, secure SDLC, code review, release approvals, CI/CD security, SAST, DAST, SCA, backups, availability, confidentiality, processing integrity, and privacy controls.
- Coordinate with control owners to obtain timestamped, complete, and audit-ready artifacts.
- Help maintain the recurring compliance calendar for monthly, quarterly, and annual SOC 2 control activities.
- Support policy and documentation management, version control, approvals, and annual review cadence.
- Identify control design gaps, operating effectiveness gaps, evidence issues, and audit risks.
- Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.
Required qualifications
- 8+ years of cybersecurity, GRC, IT audit, compliance, SaaS security, cloud security, security consulting, or related experience.
- GRC platform experience (Drata preferred, others include Vanta or SecureFrame)
- Direct hands-on experience supporting SOC 2 Type 2 audits.
- Experience with SaaS or cloud-hosted application environments.
- Experience reviewing evidence for control design and operating effectiveness.
- Ability to translate audit requirements into operational tasks for engineering, IT, security, HR, legal, operations, and leadership stakeholders.
- Strong written communication skills and ability to produce auditor-ready explanations.
- Ability to drive control owners and follow-ups without constant prompting.
- Ability to work through ambiguity and produce clean, organized, audit-ready documentation.
Nice to have
- Prior SOC 2 auditor, CPA-firm, or audit-support experience.
- Experience with all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- CISA, CISSP, CISM, Security+, CPA, ISO 27001 Lead Auditor, or equivalent certification.
- Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, CI/CD tooling, SAST, DAST, SCA, vulnerability management, or cloud security tools.
- PCI DSS familiarity, especially where SOC 2 controls overlap with PCI requirements.
Expected deliverables
- SOC 2 Five-TSC evidence and gap tracker inputs.
- Control evidence sufficiency reviews.
- Auditor response drafts and management-response drafts.
- Control narrative and control-description updates.
- Recurring compliance calendar inputs for access reviews, vendor reviews, risk assessments, policy reviews, steering meetings, and evidence refresh cycles.
- Policy, procedure, and documentation review notes.
- SOC 2 blocker, risk, and next-action summaries.
Operating style required
This role requires a senior operator who can own the SOC 2 lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.
FYI's Benefits/Incentives: What is in it for you?
- Opportunity to work a hybrid work schedule
- A knowledgeable, high-achieving, diverse, experienced, and fun team.
- The chance to be part of a rapidly growing company and the next success story.
- A competitive base salary with a loaded benefits package plus 401K.
- Tuition/education assistance, personal computer allowance, pet insurance.
About FYI For Your Information
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Beltsville, MD, US
Year founded
1987