1

Soc1 Jobs (NOW HIRING)

Own and improve SOC1-related controls for Identity Provider and IGA processes, including audit evidence, control documentation, access reviews, and remediation tracking. * Remain hands-on in building ...

Senior Security Engineer

San Francisco, CA · On-site

$134K - $185K/yr

... SOC2, SOC1, PCI and HITRUST to ensure that we remain compliant and informed. • Regularly audit our platforms and tech stack for vulnerabilities, ensuring that vulnerabilities are identified and ...

SOC Audit Senior

Hunt Valley, MD · On-site

$85K - $100K/yr

Provide clients with cybersecurity readiness assessments, internal control advisory, and SOC1 and SOC2 examination services. * Review IT security, cybersecurity, and other compliance programs to ...

Senior Accountant/ Auditor

Lansing, MI · On-site

$75K - $94K/yr

Lead audit fieldwork and liaison with external audit firms and regulators, including PCAOB and SOC1/SOC2 engagements. * Prepare tax provision analyses (ASC 740) and collaborate with tax advisors for ...

Provide clients with cybersecurity readiness assessments, internal control advisory, and SOC1 and SOC2 examination services. * Review IT security, cybersecurity, and other compliance programs to ...

Senior Security Engineer

$117K - $160K/yr

Understand, oversee, and drive the rituals associated with HIPAA, SOC2, SOC1, PCI and HITRUST to ensure that we remain compliant and informed. • Vulnerability Management: Regularly audit our ...

Showing results 41-60

Soc1 information

What is the difference between Soc1 vs Soc2?

AspectSoc1Soc2
FocusFinancial reporting controlsSecurity, availability, processing integrity, confidentiality, privacy
CertificationsSSAE 18/SOC 1SSAE 18/SOC 2
Work EnvironmentAuditing financial controls in service organizationsAssessing controls related to security and data privacy
Industry UsageFinance, accounting, auditingIT, cloud services, data centers

Soc1 reports focus on controls relevant to financial reporting, while Soc2 reports evaluate controls related to security and data privacy. Organizations choose between them based on their clients' needs and industry standards.

What is a Soc1 job description?

A SOC 1 (System and Organization Controls 1) job involves auditing and assessing internal controls over financial reporting for organizations. Professionals in this role typically perform risk assessments, testing control effectiveness, and preparing reports to ensure compliance with industry standards such as SSAE 18. Strong knowledge of IT systems, auditing standards, and certifications like CPA or CISA are often required.

Is SOC1 analyst still in demand?

SOC1 analysts are in demand due to the increasing need for organizations to ensure compliance with financial reporting controls and security standards. They typically require knowledge of audit processes, control frameworks, and security tools, making their skills valuable in finance, audit, and cybersecurity environments. The demand is expected to grow as regulatory requirements and cybersecurity threats continue to rise.
More about Soc1 jobs
What cities are hiring for Soc1 jobs? Cities with the most Soc1 job openings:
What states have the most Soc1 jobs? States with the most job openings for Soc1 jobs include:
Infographic showing various Soc1 job openings in the United States as of August 2026, with employment types broken down into 97% Full Time, and 3% Contract. Highlights an 60% Physical, 27% Hybrid, and 13% Remote job distribution.

Full-time

Posted 14 days ago


Job description

Job Overview
We are seeking a senior Identity Management and Identity Governance & Administration (IGA) Architect to define and execute the firm's long-term identity strategy, governance model, target-state architecture, and technology roadmap.
This individual will serve as the firm's identity subject matter expert, partnering with technology, cybersecurity, risk, compliance, audit, and business stakeholders to modernize the organization's identity capabilities and establish identity as a foundational security control across the enterprise.
This role will assess the current Identity Provider and IGA landscape, including existing solutions, use cases, legacy systems, access governance processes, entitlement models, and application integrations. The candidate will identify what is working well, where gaps and risks exist, and define a clear path toward a modern, secure, scalable next-generation Identity Provider and IGA framework.
This is a highly visible role requiring both strategic leadership and hands-on execution. The successful candidate will architect and help build the next-generation identity platform, manage the transition from legacy systems, strengthen SOC1-related identity controls, and partner closely with IT, security, cloud, application, infrastructure, risk, compliance, and audit stakeholders.
Responsibilities
  • Define and lead the firm's Identity and Access Management strategy, target-state architecture, operating model, and multi-year roadmap across identity governance, access management, privileged access, and non-human identities.
  • Evaluate, select, and implement identity technologies and platforms, leading architecture reviews, technology assessments, proof-of-concepts, and vendor selection initiatives to support evolving business, security, and regulatory requirements.
  • Establish enterprise identity standards, governance frameworks, and success metrics, while partnering with technology and business leaders to drive adoption, manage risk, and continuously mature the firm's identity capabilities.
  • Own and lead the firm's Identity Management, Identity Provider, and Identity Governance & Administration strategy and roadmap.
  • Assess current identity solutions, IGA processes, access models, legacy integrations, and control gaps across the firm.
  • Architect the next-generation identity and IGA framework covering human identities, non-human identities, privileged accounts, service accounts, workload identities, API identities, and AI agentic workload identities.
  • Define and implement governance standards for joiner/mover/leaver processes, access requests, approvals, provisioning, deprovisioning, entitlement management, access reviews, and role models.
  • Design modern authentication, authorization, federation, and delegation patterns using technologies such as OpenID Connect, OAuth 2.0, SAML, Kerberos, LDAP, Microsoft Entra ID, AWS IAM, Active Directory, and Secret Management platforms.
  • Establish governance and lifecycle controls for non-human identities, including ownership, risk classification, access review, secret rotation, and least-privilege enforcement.
  • Design identity patterns for On-Behalf-Of workflows, delegated permissions, service-to-service access, application impersonation, and AI/agent-based access scenarios.
  • Lead the smooth migration of legacy applications and systems to the next-generation Identity Provider and IGA architecture.
  • Partner with IT stakeholders to understand current challenges and define practical, secure, and scalable identity solutions.
  • Own and improve SOC1-related controls for Identity Provider and IGA processes, including audit evidence, control documentation, access reviews, and remediation tracking.
  • Remain hands-on in building and implementing identity solutions, integrations, workflows, standards, and proof-of-concepts.

Requirements
  • Demonstrated experience defining enterprise Identity and Access Management strategies, architectures, operating models in complex environments.
  • Experience evaluating, selecting, and implementing identity technologies, including leading platform assessments, proof-of-concepts, vendor evaluations, and architecture review processes.
  • Proven ability to influence and partner with senior technology, cybersecurity, risk, compliance, and business stakeholders to drive identity transformation initiatives and align identity capabilities with organizational objectives.
  • Proven experience leading or supporting identity and IGA transformation programs in a large enterprise environment.
  • Strong hands-on knowledge of IGA capabilities, including access request, approval workflows, provisioning, deprovisioning, joiner/mover/leaver processes, entitlement management, access certification, role-based access control, and application onboarding.
  • Experience with major IGA platforms such as SailPoint, Saviynt, Omada, One Identity, Microsoft Entra ID Governance, or equivalent solutions.
  • Deep technical knowledge of Microsoft Entra ID, on-premises Active Directory, AWS IAM, Kerberos, LDAP, federation, and hybrid identity environments.
  • Strong understanding of OpenID Connect, OAuth 2.0, SAML, delegated authorization, On-Behalf-Of flows, and service-to-service authentication.
  • Experience with non-human identity management, including service accounts, workload identities, machine identities, API identities, secret management, ownership models, and lifecycle controls.
  • Experience with AI agentic workload identity, permission delegation, and autonomous or automated access patterns is strongly preferred.
  • Strong understanding of SOC1 controls, audit readiness, access governance, privileged access controls, and identity-related risk management.
  • Prior experience in a similar identity architecture, IGA, or security leadership role in another enterprise firm.

The base salary range for this position is $128,000 - $297,000 per year.
Arrowstreet Capital operates a robust talent acquisition program, and we also seek to compensate and reward our employees competitively within our industry and in line with our merit-based culture. Our approach to total compensation includes base salaries and annual discretionary bonuses, as well as a robust benefits package. The determination of a successful candidate's base salary placement within the listed range will vary based on the candidate's relevant experience and qualifications (which may also include relevant certifications, credentials and other education), the job responsibilities and scope, the commensurate resulting level of the position and other relevant factors. The listed range is also an estimate, and additional information regarding base salary and other elements of total compensation offered by Arrowstreet Capital to successful applicants will be communicated during the recruitment process.
Arrowstreet Capital is a Boston-based systematic investment firm that manages global equity portfolios for institutional investors around the world.
All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, ancestry, genetic information, age, pregnancy, medical condition, disability, veteran or military status, marital status or any other characteristic protected by federal, state, or local law.
Arrowstreet Capital is committed to working with and providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you need a reasonable accommodation for any part of the employment process due to a disability, contact us to discuss the nature of your request and contact information.