SOC 2 Cyber Program Lead

First Citizens Bank

Raleigh (NC)

Remote

USD 113,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
Comprehensive benefits program

Job summary

A leading financial institution in Raleigh, NC is seeking a SOC 2 Program Lead. The role involves managing the SOC 2 compliance program, overseeing readiness activities, and partnering with stakeholders to ensure sustained compliance. Candidates should have extensive experience in risk management and possess relevant certifications. This full-time position offers a competitive salary range of $113,000 to $190,000 depending on experience.

Qualifications

  • 6 years of experience in Financial Services or Risk Management.
  • Strong knowledge of SOC 2 Trust Services Criteria.
  • Excellent communication skills with the ability to influence stakeholders.

Responsibilities

  • Lead SOC 2 readiness and compliance program.
  • Execute assessments and readiness activities.
  • Produce reports and dashboards on SOC 2 readiness.

Skills

Executing SOC 2 audits
Risk assessments
Communication skills
Stakeholder partnership

Education

Bachelor's Degree
High School Diploma or GED

Tools

SOC 2 Trust Services Criteria
NIST frameworks
CISSP, CISA, CISM

Job description

Overview

Remote eligible. This position provides cybersecurity risk management and expert support at the highest level of cybersecurity governance and oversight, with primary responsibility for leading and managing the company’s Systems and Organization Controls (SOC) 2 program. The role coordinates across business and technology stakeholders to ensure SOC 2 requirements are understood, implemented, and sustained. Serves as a SOC 2 leader, contributes to broader cyber risk oversight, recommending and monitoring enhancements to processes and procedures, performing analysis, and reporting in support of strategic objectives.

Responsibilities
  • SOC 2 Program Leadership - Leads and manages the bank’s SOC 2 readiness and compliance program. Coordinates program activities across business and technology teams, ensuring controls are properly implemented, documented, and maintained in alignment with SOC 2 Trust Services Criteria (TSC). Oversees evidence collection, audit preparedness, and continuous improvement of the SOC 2 program. Serves as the primary liaison with auditors during readiness and examination activities.
  • SOC 2 Readiness - Executes assessments and readiness activities to evaluate compliance with SOC 2 requirements. Performs gap analyses, documents control coverage, and monitors remediation efforts. Collects and validates evidence, ensures accuracy and completeness, and prepares the organization for external audits by driving readiness efforts.
  • Stakeholder Partnership - Partners with control owners, governance teams, and other stakeholders to align on responsibilities, close identified gaps, and monitor remediation progress. Provides guidance and education on SOC 2 requirements, roles, and expectations, ensuring stakeholders understand their role in sustaining compliance.
  • Risk Identification and Monitoring - Identifies and monitors risks related to SOC 2 control requirements and broader cybersecurity domains. Escalates potential areas of concern, facilitates root cause analysis, and tracks corrective actions to resolution. Maintains awareness of changes in SOC 2 requirements, industry trends, and regulatory expectations, translating them into actionable insights for the bank.
  • Reporting - Produces reports and dashboards on SOC 2 readiness, testing results, control maturity, and remediation progress. Conveys root cause analysis, patterns, and trends to leadership. Provides transparency into risk exposure, compliance status, and effectiveness of mitigation measures, with emphasis on SOC 2 Trust Services Criteria coverage.
Qualifications

Bachelor's Degree and 6 years of experience in Financial Services, Risk Management, Operational Risk Management, Compliance, Audit, Finance or Accounting OR High School Diploma or GED and 10 years of experience in Financial Services, Risk Management, Operational Risk Management, Compliance, Audit, Finance or Accounting

  • Direct experience executing or leading SOC 2 audits and programs, including readiness assessments, gap analysis, evidence collection, and audit preparedness
  • Strong knowledge of SOC 2 Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) and demonstrated ability to apply them in a large, complex organization
  • Experience partnering with stakeholders across business and technology to monitor risks, close compliance gaps, and sustain ongoing SOC 2 readiness
  • In-depth practical knowledge of internal controls, risk assessments, and operational and cybersecurity processes, with experience implementing regulatory and compliance frameworks
  • Broad knowledge and understanding of cybersecurity risks and controls, including IT infrastructure, cloud computing, mobile technologies, and cybersecurity technologies
  • Excellent written and oral communication skills, with ability to influence stakeholders and communicate effectively at multiple levels
  • CISSP, CISA, CISM, CRISC, CIA, or equivalent certification
Preferred Qualifications
  • 7-10 years of experience in risk management or compliance, including leadership of SOC 2, ISO, PCI, or similar frameworks
  • 3+ years of experience at a Large Financial Institution or similarly regulated environment
  • Familiarity with NIST frameworks (e.g., CSF, SP 800-53) and their application in strengthening cybersecurity programs
  • Extensive knowledge and subject matter expertise in managing cybersecurity compliance in financial services, including applicable regulations (SOC 2, NIST, CSA, FFIEC, OCC, FRB, state law, and other regulatory guidance)
  • Strong project management and continuous improvement skills

This job posting is expected to remain active for 45 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.

The base pay for this position is generally between $113,000 and $190,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at jobs.firstcitizens.com/benefits.

Job metadata
  • Seniority level: Not Applicable
  • Employment type: Full-time
  • Job function: Consulting, Information Technology, and Sales
  • Industries: Banking and Financial Services

Referrals increase your chances of interviewing at First Citizens Bank by 2x

Get notified about new Program Lead jobs in Raleigh, NC.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Manager
Cybersecurity Manager

Simmons Bank • Town of Texas (WI)

On-site
USD 120,000 - 160,000
SVP - Cyber Security Ops Center & Assurance
SVP - Cyber Security Ops Center & Assurance

State Employees' Credit Union • Raleigh (NC)

Hybrid
USD 180,000 - 280,000
Chief Information Security Officer
Chief Information Security Officer

The Security Executive Council • Houston (TX), Northern (KY)

Hybrid
USD 180,000 - 280,000
SVP - Cyber Security Ops Center & Assurance
SVP - Cyber Security Ops Center & Assurance

SECU • United States

Hybrid
USD 150,000 - 200,000
Chief Cybersecurity Risk Officer
Chief Cybersecurity Risk Officer

Truist • Atlanta (GA)

On-site
USD 300,000 - 400,000
Medical, dental, vision benefits
401k plan and retirement benefits
Paid time off and holidays
Senior Technology Risk Analyst - Monitoring and Testing
Senior Technology Risk Analyst - Monitoring and Testing

Citizens Bank • United States

Hybrid
USD 90,000 - 120,000
Chief Information Security Officer
Chief Information Security Officer

Origin Bank • Tyler (TX)

On-site
USD 180,000 - 290,000
Chief Information Security Officer
Chief Information Security Officer

Origin Bank • Monroe (LA)

On-site
USD 180,000 - 260,000
Chief Information Security Officer
Chief Information Security Officer

Origin Bank • Houston (TX)

On-site
USD 180,000 - 260,000
Chief Information Security Officer
Chief Information Security Officer

Origin Bank • Longview (TX)

On-site
USD 180,000 - 240,000