Skip to Content
All roles

SOC 2 Readiness & Audit Analyst

Charlotte, NC Remote Full-time

Posted 09/23/2026

As a SOC 2 Readiness & Audit Analyst, you will serve as a key execution lead for our information security compliance programs. You will be responsible for driving continuous audit readiness by evaluating control design, testing operating effectiveness, and collecting audit evidence across applicable AICPA Trust Services Criteria. In this role, you will work directly with internal teams to remediate control gaps ahead of observation windows, maintain control matrices within GRC platforms (such as Vanta, Drata, or AuditBoard), and support external auditor requests during Type I and Type II audits. This position is ideal for a detail-oriented compliance professional looking to manage end-to-end evidence workflows, assess third-party vendor risks, and maintain robust security governance.
Apply for this role →

 What you will do

  • Support Program Execution: Assist in the daily operations and execution of the SOC 2 compliance program, helping gather artifacts and document control designs.

  • Continuous Control Testing: Perform periodic testing of operating effectiveness across key security controls to maintain ongoing audit readiness throughout the year.

  • Assist with Gap Assessments: Conduct preliminary readiness reviews and gap assessments ahead of audit windows, working with control owners to track remediation tasks to completion.

  • Evidence & Artifact Collection: Coordinate with cross-functional teams to gather, validate, and organize evidence samples for internal reviews and external audit requests.

  • Audit Liaison Support: Assist with managing external auditor requests, including maintaining the Prepared-By-Client (PBC) request list, scheduling walkthroughs, and tracking sample requests.

  • Control Matrix Maintenance: Help update and maintain the control mapping matrix across applicable Trust Services Criteria (TSC) and internal security frameworks.

  • Third-Party Risk Support: Assist in reviewing third-party vendor SOC reports (subservice organizations), identifying complementary user entity controls (CUECs), and logging potential risks.

What we are looking for

  • Two to four years minimum at analyst level. Bachelor's with equivalency accepted.
  • Understanding of the five Trust Services Criteria — Security as the mandatory common criteria, plus Availability, Processing Integrity, Confidentiality, and Privacy.
  • Ability to articulate Type I versus Type II precisely.
  • Multi-framework exposure and GRC platform experience.
  • Auditor-facing written and verbal communication.

Nice to have

  • CISA or CPA Certification: Preferred signature credentials for GRC and audit alignment.
  • Continuous Risk Assessments: Hands-on experience executing ongoing, real-time control monitoring.
  • Subservice Provider Scrutiny: Experience evaluating third-party vendor risks and complementary user entity controls (CUECs).
  • Large Control Environments: Ability to manage, test, and maintain extensive control sets (150+ controls).

Skills and expertise

SOC 2 Trust Services Criteria (AICPA) SOC 1 ISO 27001 PCI DSS NIST 800-53 HIPAA Vanta Drata Secureframe AuditBoard

Ready to apply?

Apply for this role →