SOC 2 Readiness & Audit Analyst
Posted 09/23/2026
What you will do
Support Program Execution: Assist in the daily operations and execution of the SOC 2 compliance program, helping gather artifacts and document control designs.
Continuous Control Testing: Perform periodic testing of operating effectiveness across key security controls to maintain ongoing audit readiness throughout the year.
Assist with Gap Assessments: Conduct preliminary readiness reviews and gap assessments ahead of audit windows, working with control owners to track remediation tasks to completion.
Evidence & Artifact Collection: Coordinate with cross-functional teams to gather, validate, and organize evidence samples for internal reviews and external audit requests.
Audit Liaison Support: Assist with managing external auditor requests, including maintaining the Prepared-By-Client (PBC) request list, scheduling walkthroughs, and tracking sample requests.
Control Matrix Maintenance: Help update and maintain the control mapping matrix across applicable Trust Services Criteria (TSC) and internal security frameworks.
Third-Party Risk Support: Assist in reviewing third-party vendor SOC reports (subservice organizations), identifying complementary user entity controls (CUECs), and logging potential risks.
What we are looking for
- Two to four years minimum at analyst level. Bachelor's with equivalency accepted.
- Understanding of the five Trust Services Criteria — Security as the mandatory common criteria, plus Availability, Processing Integrity, Confidentiality, and Privacy.
- Ability to articulate Type I versus Type II precisely.
- Multi-framework exposure and GRC platform experience.
- Auditor-facing written and verbal communication.
Nice to have
- CISA or CPA Certification: Preferred signature credentials for GRC and audit alignment.
- Continuous Risk Assessments: Hands-on experience executing ongoing, real-time control monitoring.
- Subservice Provider Scrutiny: Experience evaluating third-party vendor risks and complementary user entity controls (CUECs).
- Large Control Environments: Ability to manage, test, and maintain extensive control sets (150+ controls).