1

Soc Two Compliance Jobs (NOW HIRING)

You'll be the go-to person for everything from onboarding new hires to managing our SaaS tool stack and supporting our path to SOC 2 compliance. What You'll Own Identity & Access Management

You'll be the go-to person for everything from onboarding new hires to managing our SaaS tool stack and supporting our path to SOC 2 compliance. What You'll Own Identity & Access Management

Qualifications and Skills: * 5+ years of directly related experience in IT security compliance, including recent experience with SOC 2 * Cloud computing security * Security governance and policy

New

Qualifications and Skills: * 5+ years of directly related experience in IT security compliance, including recent experience with SOC 2 * Cloud computing security * Security governance and policy

Maintain and evolve SOC 2 Type II compliance, including evidence gathering, documentation, and audit coordination. Ensure compliance with HIPAA and other healthcare data protection standards.

Showing results 21-40

Soc Two Compliance information

See salary details

$31.5K

$98.9K

$207.5K

How much do soc two compliance jobs pay per year?

As of Aug 6, 2026, the average yearly pay for soc two compliance in the United States is $98,949.00, according to ZipRecruiter salary data. Most workers in this role earn between $61,500.00 and $115,000.00 per year, depending on experience, location, and employer.

What is the work of Soc Two Compliance?

SOC 2 Compliance involves ensuring that a company's systems and processes meet the standards set by the Service Organization Control 2 framework, which focuses on security, availability, processing integrity, confidentiality, and privacy. Professionals in this role typically perform audits, implement controls, and maintain documentation to demonstrate compliance with these criteria, often using tools like audit software and security protocols.

What is the difference between Soc Two Compliance vs Security Analyst?

AspectSoc Two ComplianceSecurity Analyst
Required CredentialsCertifications like SOC 2, CPA, or CISACertifications like CISSP, CISA, or Security+
Work EnvironmentAuditing, compliance assessments, consultingMonitoring, threat analysis, incident response
Employer & Industry UsageUsed by organizations seeking SOC 2 reports, auditors, consultantsUsed by security teams within organizations, cybersecurity firms

Soc Two Compliance professionals focus on ensuring organizations meet SOC 2 standards through audits and compliance assessments. Security Analysts primarily monitor and protect IT systems from security threats. While both roles involve security, Soc Two Compliance emphasizes compliance and reporting, whereas Security Analysts focus on threat detection and incident response.

More about Soc Two Compliance jobs
What cities are hiring for Soc Two Compliance jobs? Cities with the most Soc Two Compliance job openings:
What states have the most Soc Two Compliance jobs? States with the most job openings for Soc Two Compliance jobs include:
Infographic showing various Soc Two Compliance job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 11% Part Time, and 5% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $98,949 per year, or $47.6 per hour.

Director, IT, Security & Compliance

PurpleLab Inc

Wayne, PA • On-site

$165K - $185K/yr

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

Description:

The Director, Information Technology & Security/Compliance is responsible for the day-to-day management of the company's IT operations and security/compliance programs. This includes overseeing the relationship with the company's managed IT service provider, ensuring the security and reliability of IT systems, and leading the company's compliance efforts under frameworks including HIPAA, SOC 2, and HiTrust. This role reports to the VP, Information Technology and serves as the primary operational lead for IT infrastructure and regulatory compliance.


This position is required to be on-site in Wayne, PA at least 3 day a week.


  • Manage the day-to-day relationship with the company's managed IT service provider, serving as the primary point of contact for service delivery, escalations, and performance management.
  • Oversee IT operations including cloud operations, endpoint management, and identity and access management.
  • Lead a group of dev ops and system reliability engineers for cloud operations.
  • Lead and maintain the company's HiTrust certification program, including gap assessments, remediation tracking, and audit coordination.
  • Own and manage the SOC 2 compliance program, including evidence collection, control monitoring, and coordination with external auditors.
  • Develop, implement, and maintain IT security policies, procedures, and controls in alignment with applicable regulatory and contractual requirements.
  • Conduct and coordinate risk assessments, such as penetration testing; develop and track remediation plans for identified vulnerabilities and gaps.
  • Manage incident response activities including identification, containment, investigation, and documentation of security events.
  • Maintain and test disaster recovery (DR) and business continuity plans.
  • Ensure ongoing HIPAA compliance across systems, processes, and third-party relationships.
  • Manage IT vendor relationships and contracts, including software licensing, cloud services, and security tooling.
  • Prepare and maintain compliance documentation.
  • Perform other duties as assigned to support business needs and company objectives.
Requirements:
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity or a related field is required.
  • 5+ years of experience in IT operations, security, or compliance roles, with at least 2 years in a management or leadership capacity.
  • Demonstrated experience managing a HiTrust certification program (HITRUST CSF).
  • Demonstrated experience managing a SOC 2 audit and compliance program.
  • Experience managing a third-party managed IT services or helpdesk provider.
  • Strong working knowledge of HIPAA Security and Privacy Rules.
  • Experience conducting risk assessments and implementing security controls.
  • Experience with incident response and disaster recovery planning.
  • Strong understanding of cloud computing security and infrastructure (AWS, Azure, or GCP).
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills; ability to translate technical risk into business terms.
  • Experience in healthcare, life sciences, or health data industries strongly preferred.
  • Relevant certifications (CISSP, CISM, CRISC, HITRUST CCSFP, or equivalent) a plus.