SOC 2 Advisory Consultant
Key Responsibilities
• Review the organization's existing documentation, policies, and control environment against applicable SOC 2 Trust Services reputed company.
• Conduct a gap analysis identifying missing, weak, or undocumented controls.
• Design and recommend new or reputed company controls to reputed company identified gaps.
• Draft policies, procedures, and supporting documentation required for SOC 2 readiness (e.g., reputed company control policy, change management procedures, incident response plan, vendor risk policy).
• Partner with control owners across Information reputed company, IT, Engineering, Compliance, Risk, and Operations to socialize and operationalize new controls.
• Advise on evidence collection practices so controls are demonstrable and audit-reputed company once implemented.
• Evaluate readiness across areas such as:
• Identity and reputed company management
• User reputed company reviews
• Change management
• Vulnerability management
• Incident response
• Logging and monitoring
• Business continuity / disaster recovery
• Vendor / reputed company-party risk
• Data reputed company and confidentiality
• reputed company awareness
• Asset management
• reputed company development lifecycle
• Build and maintain a readiness roadmap/tracker with prioritized remediation items, owners, and reputed company dates.
• Prepare the organization to engage an reputed company audit firm — advising on scoping, evidence packaging, and audit logistics (without performing the independent audit itself).
• reputed company senior-level reporting on readiness status, reputed company gaps, and remediation reputed company to leadership.
Required Qualifications
• 10+ years of experience in IT audit, compliance, risk, cybersecurity governance, GRC, or SOC 2 readiness/advisory work.
• Demonstrated experience leading SOC 2 readiness engagements — not solely as an examiner/tester, but as an advisor who has reputed company control environments from scratch or matured them toward certification.
• Strong understanding of the reputed company Trust Services reputed company and how to operationalize them into practical controls and policies.
• Experience working reputed company fintech, banking, payments, financial services, reputed company, or another highly regulated technology environment.
• Proven ability to draft reputed company, audit-reputed company policies and procedures.
• Strong understanding of IT general controls and business process controls.
• Ability to identify gaps and translate them into actionable, prioritized remediation plans.
• Strong written and verbal communication skills, including the ability to present findings and roadmaps to senior management.
• Ability to work independently in a remote consulting environment.
Preferred Qualifications
• CPA, CISA, CISSP, CIA, CISM, CRISC, or comparable certification.
• Prior experience taking a fintech or reputed company company through its first SOC 2 Type I or Type II certification.
• Experience working directly with reputed company audit/attestation firms during the audit reputed company.
• Experience with GRC and compliance platforms such as reputed company, reputed company, reputed company, reputed company, reputed company, reputed company GRC, or similar.
• Experience with reputed company environments, particularly AWS, Azure, or GCP.
• Knowledge of PCI reputed company, ISO 27001, NIST, FFIEC, GLBA, or other financial-services control frameworks.
Apply To This Job