Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria. * Review evidence requests and determine whether evidence is complete, partial ...
Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria. * Review evidence requests and determine whether evidence is complete, partial ...
About the roleFYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an ... Draft and review auditor responses, management explanations, control narratives, and evidence ...
Quick apply
About the roleFYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an ... Draft and review auditor responses, management explanations, control narratives, and evidence ...
TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...
Quick apply
TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...
SOC 2 Assessor (Part time & Remote)
Sterling, VA · On-site +1
$50 - $90/hr
TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...
SOC 2 Assessor (Part time & Remote)
Sterling, VA · On-site +1
$50 - $90/hr
TestPros is looking for Expert level SOC 2 Auditors with experience performing SOC 2 Type 2 Assessments. Position Type: Consultant (Project-Based) Location: Remote Start: Future projects late 2026 or ...
Compliance / Audit Specialist - Secret clearance minimum with Security Clearance
Arlington, VA · On-site
$80/hr
... audits (SOC 2, FedRAMP, FISMA). * Deep expertise in SOC 1 audit lifecycle management, including scoping, control mapping, walkthroughs, evidence collection, and auditor coordination. * Strong ...
Compliance / Audit Specialist - Secret clearance minimum with Security Clearance
Arlington, VA · On-site
$80/hr
... audits (SOC 2, FedRAMP, FISMA). * Deep expertise in SOC 1 audit lifecycle management, including scoping, control mapping, walkthroughs, evidence collection, and auditor coordination. * Strong ...
... audits (SOC 2, FedRAMP, FISMA). * Deep expertise in SOC 1 audit lifecycle management, including scoping, control mapping, walkthroughs, evidence collection, and auditor coordination. * Strong ...
... audits (SOC 2, FedRAMP, FISMA). * Deep expertise in SOC 1 audit lifecycle management, including scoping, control mapping, walkthroughs, evidence collection, and auditor coordination. * Strong ...
Risk Senior Manager
Columbia, MD · On-site +1
Build and manage an opportunity pipeline across SOC (1/2/3), readiness, ISO 27001 ISMS ... Experience coordinating with external auditors and working in regulated industries (SaaS, fintech ...
Risk Senior Manager
Columbia, MD · On-site +1
Build and manage an opportunity pipeline across SOC (1/2/3), readiness, ISO 27001 ISMS ... Experience coordinating with external auditors and working in regulated industries (SaaS, fintech ...
Risk Senior Manager
Columbia, MD · On-site
Build and manage an opportunity pipeline across SOC (1/2/3), readiness, ISO 27001 ISMS ... Experience coordinating with external auditors and working in regulated industries (SaaS, fintech ...
Risk Senior Manager
Columbia, MD · On-site
Build and manage an opportunity pipeline across SOC (1/2/3), readiness, ISO 27001 ISMS ... Experience coordinating with external auditors and working in regulated industries (SaaS, fintech ...
Build and manage an opportunity pipeline across SOC (1/2/3), readiness, ISO 27001 ISMS ... Experience coordinating with external auditors and working in regulated industries (SaaS, fintech ...
Build and manage an opportunity pipeline across SOC (1/2/3), readiness, ISO 27001 ISMS ... Experience coordinating with external auditors and working in regulated industries (SaaS, fintech ...
Build and manage an opportunity pipeline across SOC (1/2/3), readiness, ISO 27001 ISMS ... Experience coordinating with external auditors and working in regulated industries (SaaS, fintech ...
Build and manage an opportunity pipeline across SOC (1/2/3), readiness, ISO 27001 ISMS ... Experience coordinating with external auditors and working in regulated industries (SaaS, fintech ...
IT Supervisory Senior Auditor (US - Alexandria, VA, Columbus, OH, Indianapolis, IN) What to expect ... Experience performing SOC 1 or SOC 2 audits (strongly preferred) * Familiarity with FISCAM and/or ...
Quick apply
IT Supervisory Senior Auditor (US - Alexandria, VA, Columbus, OH, Indianapolis, IN) What to expect ... Experience performing SOC 1 or SOC 2 audits (strongly preferred) * Familiarity with FISCAM and/or ...
IT Supervisory Senior Auditor (Federal Audit)
Alexandria, VA · On-site
$107K/yr
IT Supervisory Senior Auditor (US - Alexandria, VA, Columbus, OH, Indianapolis, IN) What to expect ... Experience performing SOC 1 or SOC 2 audits (strongly preferred) * Familiarity with FISCAM and/or ...
IT Supervisory Senior Auditor (Federal Audit)
Alexandria, VA · On-site
$107K/yr
IT Supervisory Senior Auditor (US - Alexandria, VA, Columbus, OH, Indianapolis, IN) What to expect ... Experience performing SOC 1 or SOC 2 audits (strongly preferred) * Familiarity with FISCAM and/or ...
IT Supervisory Senior Auditor (Federal Audit)
Alexandria, VA · On-site
$107K/yr
Description IT Supervisory Senior Auditor (US - Alexandria, VA, Columbus, OH, Indianapolis, IN ... Experience performing SOC 1 or SOC 2 audits (strongly preferred) * Familiarity with FISCAM and/or ...
IT Supervisory Senior Auditor (Federal Audit)
Alexandria, VA · On-site
$107K/yr
Description IT Supervisory Senior Auditor (US - Alexandria, VA, Columbus, OH, Indianapolis, IN ... Experience performing SOC 1 or SOC 2 audits (strongly preferred) * Familiarity with FISCAM and/or ...
Information Security Compliance Coordinator
Washington, DC · Remote
$60K - $75K/yr
Support ISO, SOC 2, and CMMC compliance activities under the direction of the Director of ... Tracking auditor requests * Organizing documentation for review * Maintain compliance artifacts ...
Information Security Compliance Coordinator
Washington, DC · Remote
$60K - $75K/yr
Support ISO, SOC 2, and CMMC compliance activities under the direction of the Director of ... Tracking auditor requests * Organizing documentation for review * Maintain compliance artifacts ...
Information Security Compliance Coordinator
Washington, DC · Remote
$60K - $75K/yr
Support ISO, SOC 2, and CMMC compliance activities under the direction of the Director of ... Tracking auditor requests * Organizing documentation for review * Maintain compliance artifacts ...
Quick apply
Information Security Compliance Coordinator
Washington, DC · Remote
$60K - $75K/yr
Support ISO, SOC 2, and CMMC compliance activities under the direction of the Director of ... Tracking auditor requests * Organizing documentation for review * Maintain compliance artifacts ...
Coordinate the annual SOC 2 audit and HIPAA assessments: assemble and organize requested evidence. * Serve as the primary point of contact and manage day-to-day communications with external auditors.
Coordinate the annual SOC 2 audit and HIPAA assessments: assemble and organize requested evidence. * Serve as the primary point of contact and manage day-to-day communications with external auditors.
Support ISO, SOC 2, and CMMC compliance activities under the direction of the Director of ... Tracking auditor requests * Organizing documentation for review * Maintain compliance artifacts ...
Quick apply
Support ISO, SOC 2, and CMMC compliance activities under the direction of the Director of ... Tracking auditor requests * Organizing documentation for review * Maintain compliance artifacts ...
GRC Engineer
Vienna, VA · On-site
$140K - $170K/yr
Own our SOC 2 audit end-to-end, including the transition from point-in-time to a rolling 12-month window * Serve as the primary liaison with our external auditors * Maintain the evidence repository ...
GRC Engineer
Vienna, VA · On-site
$140K - $170K/yr
Own our SOC 2 audit end-to-end, including the transition from point-in-time to a rolling 12-month window * Serve as the primary liaison with our external auditors * Maintain the evidence repository ...
Information Security Compliance Coordinator
Washington, DC · On-site
$55K - $65K/yr
Support ISO, SOC 2, and CMMC compliance activities under the direction of the Director of ... Tracking auditor requests * Organizing documentation for review * Maintain compliance artifacts ...
Information Security Compliance Coordinator
Washington, DC · On-site
$55K - $65K/yr
Support ISO, SOC 2, and CMMC compliance activities under the direction of the Director of ... Tracking auditor requests * Organizing documentation for review * Maintain compliance artifacts ...
Sr Information Security Engineer
Herndon, VA · On-site
$109K - $148K/yr
Experience supporting audits and assessments such as SOC 2, ISO 27001, etc. * Strong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership ...
Sr Information Security Engineer
Herndon, VA · On-site
$109K - $148K/yr
Experience supporting audits and assessments such as SOC 2, ISO 27001, etc. * Strong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership ...
Soc Two Auditor information
See Silver Spring, MD salary details
$39.8K - $50.4K
3% of jobs
$50.4K - $60.9K
11% of jobs
$60.9K - $71.5K
8% of jobs
$75K is the 25th percentile. Wages below this are outliers.
$71.5K - $82.1K
11% of jobs
The median wage is $91.3K / yr.
$82.1K - $92.7K
20% of jobs
$92.7K - $103.2K
13% of jobs
$111.6K is the 75th percentile. Wages above this are outliers.
$103.2K - $113.8K
12% of jobs
$113.8K - $124.4K
11% of jobs
$124.4K - $135K
9% of jobs
$135K - $145.5K
3% of jobs
$145.5K - $156.1K
0% of jobs
$39.8K
$95.9K
$156.1K
How much do soc two auditor jobs pay per year?
What is the difference between Soc Two Auditor vs Soc Two Consultant?
| Aspect | Soc Two Auditor | Soc Two Consultant |
|---|---|---|
| Certifications | Typically holds CPA, CISA, or similar certifications | Often has similar certifications but focuses on advisory roles |
| Work Environment | Performs audits within organizations, often in finance or IT departments | Provides advisory services, assessments, and recommendations to clients |
| Employer & Industry Usage | Employed by organizations or audit firms to conduct SOC 2 audits | Works for consulting firms or independently to advise on SOC 2 compliance |
While both roles focus on SOC 2 compliance, a Soc Two Auditor conducts formal audits to assess compliance, whereas a Soc Two Consultant provides guidance and recommendations to help organizations prepare for audits.
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
Silver Spring, MD • On-site
Full-time
Retirement
Re-posted 25 days ago
Job description
About the role
FYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an active SOC 2 Type 2 program across Security, Availability, Processing Integrity, Confidentiality, and Privacy. This role will own the SOC 2 domain in a fractional capacity, including evidence review, control operation support, auditor communication support, recurring compliance cadence, and SaaS/cloud control maturity. The right candidate has supported real SOC 2 Type 2 audits and can work with engineering, IT, security, HR, operations, leadership, and auditors.
Essential responsibilities and duties
- Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria.
- Review evidence requests and determine whether evidence is complete, partial, missing, stale, unclear, or misaligned to the control being tested.
- Draft and review auditor responses, management explanations, control narratives, and evidence summaries.
- Support control operations for access reviews, vendor risk management, risk assessment, policy review, security awareness, incident response, change management, and security steering activities.
- Review evidence for IAM, MFA, logging, monitoring, encryption, vulnerability management, secure SDLC, code review, release approvals, CI/CD security, SAST, DAST, SCA, backups, availability, confidentiality, processing integrity, and privacy controls.
- Coordinate with control owners to obtain timestamped, complete, and audit-ready artifacts.
- Help maintain the recurring compliance calendar for monthly, quarterly, and annual SOC 2 control activities.
- Support policy and documentation management, version control, approvals, and annual review cadence.
- Identify control design gaps, operating effectiveness gaps, evidence issues, and audit risks.
- Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.
Required qualifications
- 8+ years of cybersecurity, GRC, IT audit, compliance, SaaS security, cloud security, security consulting, or related experience.
- GRC platform experience (Drata preferred, others include Vanta or SecureFrame)
- Direct hands-on experience supporting SOC 2 Type 2 audits.
- Experience with SaaS or cloud-hosted application environments.
- Experience reviewing evidence for control design and operating effectiveness.
- Ability to translate audit requirements into operational tasks for engineering, IT, security, HR, legal, operations, and leadership stakeholders.
- Strong written communication skills and ability to produce auditor-ready explanations.
- Ability to drive control owners and follow-ups without constant prompting.
- Ability to work through ambiguity and produce clean, organized, audit-ready documentation.
Nice to have
- Prior SOC 2 auditor, CPA-firm, or audit-support experience.
- Experience with all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- CISA, CISSP, CISM, Security+, CPA, ISO 27001 Lead Auditor, or equivalent certification.
- Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, CI/CD tooling, SAST, DAST, SCA, vulnerability management, or cloud security tools.
- PCI DSS familiarity, especially where SOC 2 controls overlap with PCI requirements.
Expected deliverables
- SOC 2 Five-TSC evidence and gap tracker inputs.
- Control evidence sufficiency reviews.
- Auditor response drafts and management-response drafts.
- Control narrative and control-description updates.
- Recurring compliance calendar inputs for access reviews, vendor reviews, risk assessments, policy reviews, steering meetings, and evidence refresh cycles.
- Policy, procedure, and documentation review notes.
- SOC 2 blocker, risk, and next-action summaries.
Operating style required
This role requires a senior operator who can own the SOC 2 lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.
FYI's Benefits/Incentives: What is in it for you?
- Opportunity to work a hybrid work schedule
- A knowledgeable, high-achieving, diverse, experienced, and fun team.
- The chance to be part of a rapidly growing company and the next success story.
- A competitive base salary with a loaded benefits package plus 401K.
- Tuition/education assistance, personal computer allowance, pet insurance.
About FYI For Your Information
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Beltsville, MD, US
Year founded
1987