SOC 2 Compliance Engineer for Cloud & IAM

Jobtailor

California (MO)

Hybrid

USD 90,000 - 150,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks a security/compliance specialist to lead SOC 2 Type I/II audits, develop policy automation, and maintain evidence repositories. You will collaborate with IT, security, and engineering to implement compliant, scalable controls across cloud services.

The role requires hands-on experience with cloud infrastructure, IAM, and CI/CD tooling, plus strong communication skills to translate technical risk to stakeholders.

Qualifications

  • 2–5 years of experience in technical compliance, IT audit, or GRC within a SaaS or startup
  • Proven end-to-end experience supporting external SOC 2 Type I and II audits
  • Expertise auditing IT General Controls (ITGC) including Change Management, Logical Access, and System Operations
  • Strong understanding of cloud infrastructure (AWS/GCP/Azure), IAM, CI/CD pipelines, encryption standards, and vulnerability management
  • Ability to read a Terraform plan or an AWS Config rule and interpret its compliance impact
  • Experience operating Vanta or Drata
  • Experience tracking work in Jira
  • Experience with KnowBe4 or a security awareness platform
  • Exceptional written and verbal communication skills
  • Ability to explain technical controls to customers and business risks to engineers

Responsibilities

  • Draft technically precise responses to RFPs, security questionnaires, and customer portals
  • Own and update the audit-ready repository of security evidence, configurations, and policies
  • Retrieve technical evidence on AWS KMS encryption, logging pipelines, and IAM paths
  • Partner with IT, Security, Product, Engineering, and Delivery on compliance-by-design decisions
  • Write, update, and operationalize security policies and translate controls into developer tasks
  • Automate policy enforcement in CI/CD pipelines
  • Conduct compliance enablement sessions for engineering teams
  • Coordinate SOC 2 Type I and II audit cycles across entities
  • Manage audit schedules, external auditors, and remediation of findings
  • Automate evidence collection and monitor controls using Vanta and Drata
  • Manage the Jira compliance ticketing queue
  • Execute quarterly User Access Reviews, security awareness training, phishing simulations, and risk processes
  • Build and maintain compliance KPI/KRI dashboards and report audit readiness
  • Manage annual policy review and attestation cycles
  • Assist with alignment to NIST SP 800-53, NIST SP 800-171 Rev 3, FedRAMP, and CMMC 2.0
  • Draft early System Security Plans and Plans of Action & Milestones
  • Own third-party vendor reviews for cloud, HRIS, and CRM providers
  • Support security incidents by preserving evidence and drafting post-incident reports

Skills

Technical Compliance
IT Audit
GRC
IAM
Encryption Standards
Vulnerability Management
Audit Readiness
Security Policy Development
Communication

Tools

Jira
Vanta
Drata
KnowBe4
Terraform
AWS Config

Job description

Jobtailor seeks a security/compliance specialist to lead SOC 2 Type I/II audits, develop policy automation, and maintain evidence repositories. You will collaborate with IT, security, and engineering to implement compliant, scalable controls across cloud services.

The role requires hands-on experience with cloud infrastructure, IAM, and CI/CD tooling, plus strong communication skills to translate technical risk to stakeholders.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote ISO & SOC 2 Compliance Analyst
Remote ISO & SOC 2 Compliance Analyst

Actalent • North Carolina

On-site
USD 110,000 - 150,000
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead

FYI - For Your Information, Inc. • Silver Spring (MD)

Hybrid
USD 80,000 - 100,000
Opportunity to work a hybrid work schedule
Tuition/education assistance
Pet insurance
Security & Compliance Analyst — AI Governance & SOC 2
Security & Compliance Analyst — AI Governance & SOC 2

Jobtailor • Illinois

On-site
USD 90,000 - 120,000
Security Compliance Automation Lead
Security Compliance Automation Lead

ServiceNow • Mountain View (CA)

Hybrid
USD 180,000 - 240,000
Remote Compliance Leader - SOC 2, GDPR & ISO 27001 Expert
Remote Compliance Leader - SOC 2, GDPR & ISO 27001 Expert

10a Labs • United States

Remote
USD 105,000 - 125,000
Performance-based bonus
Support for conferences and certs
Fully remote (US-based)
+2
SOC 2 Type 2 Compliance Lead for SaaS/Cloud
SOC 2 Type 2 Compliance Lead for SaaS/Cloud

FYI - For Your Information, Inc. • Silver Spring (MD)

Hybrid
USD 80,000 - 100,000
Opportunity to work a hybrid work schedule
Tuition/education assistance
Pet insurance
Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

Advanced Operations Partners • United States

On-site
USD 140,000 - 190,000
SOC 2 Security & IT Compliance Lead
SOC 2 Security & IT Compliance Lead

Helloslang • New York (NY)

Hybrid
USD 140,000 - 190,000
SaaS Security & Compliance Lead (SOC 2)
SaaS Security & Compliance Lead (SOC 2)

Advanced Operations Partners • United States

On-site
USD 140,000 - 190,000
Security Compliance Engineer | SOC 2, CMMC & GRC
Security Compliance Engineer | SOC 2, CMMC & GRC

Socket.dev • New York (NY)

Hybrid
USD 120,000 - 185,000