SOC Analyst

Embedded Shishya

United States

Remote

USD 90,000 - 120,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Remote work
Hardware provided
Internet allowance
Education allowances
Bonuses
Growth opportunities
Flexible schedule
Work-life balance

Job summary

SyncEzy is a remote-savvy company seeking a hands-on Information Security & Compliance Analyst (GRC) to own day-to-day compliance operations and keep controls audit-ready across SOC 2, ISO 27001 and Cyber Essentials.

The role collaborates with Engineering, DevOps and IT, requiring 2–4 years in GRC, strong documentation skills, and the ability to translate requirements into practical actions for a SaaS environment.

Qualifications

  • 2–4 years of experience in GRC or information security compliance.
  • Practical exposure to SOC 2 or ISO 27001; familiarity with Cyber Essentials preferred.
  • Experience collecting, reviewing and organizing audit evidence and coordinating with control owners.
  • Strong documentation and policy-writing skills with attention to consistency and audibility.
  • Understanding of cloud environments, IAM, endpoint security, vulnerability management, logging, backups and change management.
  • Ability to read technical evidence and work with both technical and non-technical stakeholders.

Responsibilities

  • Maintain year-round readiness for SOC 2, ISO 27001 and Cyber Essentials.
  • Own routine compliance administration, evidence collection and control monitoring.
  • Translate compliance requirements into practical actions for Engineering, DevOps and IT teams.
  • Identify gaps, track remediation to closure and maintain clear documentation.

Skills

GRC
Information security
Audit evidence
Policy writing
Cloud security
IAM / Access management
Vulnerability management

Tools

Vanta
Drata
Sprinto

Job description

This is a remote position.

SyncEzy is a growing Integration Company in the B2B SAAS space, with a strong focus on the Construction, Trades, and Service Industries. We are fiercely independent & bootstrapped, NOT VC Funded. This is A TRUE Remote /work-from-home position. We have staff dispersed across 4 countries and 15 cities. We pride ourselves on running a flat organization, with a friendly, easy-going culture.

We are looking for a hands-on Information Security & Compliance Analyst (GRC)to take ownership of the day-to-day activities required to maintain our security and compliance posture. The role will support and coordinate compliance activities across SOC 2, ISO 27001 and Cyber Essentials, and will work closely with Engineering, DevOps, IT and management to keep controls operating effectively and evidence audit-ready throughout the year.

This is an execution-focused role.The successful candidate should be comfortable moving between policy work, evidence collection, endpoint/software compliance, risk tracking, access reviews and audit coordination. The Senior Engineering Manager will remain the management and escalation point, while the analyst becomes the primary owner of routine compliance operations and follow-up.

Primary Objectives
  • Maintain year-round readiness for SOC 2, ISO 27001 and Cyber Essentials rather than treating compliance as a once-a-year audit exercise.
  • Own routine compliance administration, evidence collection, control monitoring and follow-up so engineering leadership can remain focused on product delivery and technical management.
  • Translate compliance requirements into practical actions for Engineering, DevOps and IT teams without creating unnecessary operational overhead.
  • Identify gaps early, track remediation to closure and maintain clear documentation showing that controls are designed and operating effectively.
Requirements
Required Qualifications & Skills
  • 2–4 years of relevant experience in GRC, information security compliance, security assurance, IT audit or a closely related role.
  • Practical exposure to at least one major security/compliance framework such as SOC 2 or ISO 27001; familiarity with Cyber Essentials is strongly preferred.
  • Experience collecting, reviewing and organizing audit evidence and working with technical control owners.
  • Strong documentation and policy-writing skills with attention to consistency and audibility.
  • Working understanding of cloud environments, identity and access management, endpoint security, vulnerability management, logging, backups and change management.
  • Ability to read technical evidence and ask the right questions without needing to be a software engineer or DevOps engineer.
  • Strong ownership, follow-up and organizational skills; comfortable tracking multiple recurring compliance activities simultaneously.
  • Clear written and verbal communication skills and the ability to work with both technical and non-technical stakeholders.
Preferred / Good-to-Have
  • Experience with compliance automation or GRC platforms such as Vanta, Drata, Sprinto or equivalent tools.
  • Experience working in a SaaS, software-development or cloud-first organization.
  • Familiarity with MDM / endpoint-management tooling and software inventory reviews.
  • Exposure to AWS, Azure or other public-cloud security controls.
  • Experience supporting customer security questionnaires or vendor-risk assessments.
  • Relevant certifications such as ISO 27001 Internal Auditor / Lead Implementer, Security+, CISA, CRISC or similar are useful but not mandatory.
Benefits

Benefits - A TRUE Remote / Work from Home position. We are a Global Remote company, and have been remote working long before it was made popular by COVID. We have staff dispersed across 4 countries and 15 cities. We pride ourselves on running a flat organization, with a friendly and going culture.

  • Competitive Salary + All the belowSalary range:7-9 lacs
  • Allowance for Internet / Phone costs
  • Company Hardware provided after completing probation.
  • Continuous development and education allowances.
  • Flexible Remote work from anywhere (As long as you have good internet and communication)
  • Excellent growth opportunities, growth into leadership for the right candidate
  • Generous policies around leave / social and training allowances
  • End of year Bonuses based on company + Individual performance.
  • Zero Commute, Work while you work, play while you play. Perfect Work / Life balance.
  • Remote job opportunities and other benefits to be discussed during the interviewFlexible, family friendly & fun work environment
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote SOC & Compliance Analyst (GRC)
Remote SOC & Compliance Analyst (GRC)

Embedded Shishya • United States

On-site
USD 90,000 - 120,000
Remote work
Hardware provided
Internet allowance
+5
Information Security Lead
Information Security Lead

United States Digital Space LLC • United States

Remote
USD 140,000 - 200,000
Remote work
Equity package
Development budget
+5
GRC Analyst - Public Sector
GRC Analyst - Public Sector

Apply • Washington, Northern (KY)

Hybrid
USD 110,000 - 140,000
Director, Governance, Risk & Compliance
Director, Governance, Risk & Compliance

Anomali • Redwood City (CA)

Hybrid
USD 180,000 - 230,000
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead

FYI - For Your Information, Inc. • Silver Spring (MD)

Hybrid
USD 80,000 - 100,000
Opportunity to work a hybrid work schedule
Tuition/education assistance
Pet insurance
Security Compliance Analyst
Security Compliance Analyst

Harbinger Motors • Garden Grove (CA)

On-site
USD 110,000 - 160,000
Stock options
Flexible PTO
Health coverage
+2
Staff Security Engineer (Compliance) - Moveworks
Staff Security Engineer (Compliance) - Moveworks

ServiceNow • Mountain View (CA)

Hybrid
USD 180,000 - 240,000
GSOC Analyst - Swing Shift - 6 month opportunity
GSOC Analyst - Swing Shift - 6 month opportunity

Control Risks • San Jose (CA)

On-site
USD 38,000 - 40,000
Medical Benefits
401(K) Retirement
Hybrid work arrangements
+2
Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2