Base Career helps you apply smarter for this job.
FYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an active SOC 2 Type 2 program across Security, Availability, Processing Integrity, Confidentiality, and Privacy.
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control operation support, auditor communication support, recurring compliance cadence, and SaaS/cloud control maturity.
The right candidate has supported real SOC 2 Type 2 audits and can work with engineering, IT, security, HR, operations, leadership, and auditors.
Essential responsibilities and duties
• Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria.
• Review evidence requests and determine whether evidence is complete, partial, missing, stale, unclear, or misaligned to the control being tested.
• Draft and review auditor responses, management explanations, control narratives, and evidence summaries.
• Support control operations for access reviews, vendor risk management, risk assessment, policy review, security awareness, incident response, change management, and security steering activities.
• Review evidence for IAM, MFA, logging, monitoring, encryption, vulnerability management, secure SDLC, code review, release approvals, CI/CD security, SAST, DAST, SCA, backups, availability, confidentiality, processing integrity, and privacy controls.
• Coordinate with control owners to obtain timestamped, complete, and audit-ready artifacts.
• Help maintain the recurring compliance calendar for monthly, quarterly, and annual SOC 2 control activities.
• Support policy and documentation management, version control, approvals, and annual review cadence.
• Identify control design gaps, operating effectiveness gaps, evidence issues, and audit risks.
• Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.
FYI - For Your Information, Inc. is an SBA certified, Woman-Owned Small Business and GSA schedule holder that is a premier provider of Human Capital, Training, and Information Technology services.
We have won awards for being a Great Place to Work and continue to make ground-breaking advancements.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, USA
, USA
, USA
Silver Spring, USA
, USA
Baltimore, USA
, USA
, USA
For four years in a row, we have been on Inc.
Magazine's 5000 list and were recently named one of Inc.'s 2024 Mid-Atlantic Fastest Growing companies.
FYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an active SOC 2 Type 2 program across Security, Availability, Processing Integrity, Confidentiality, and Privacy.
This role will own the SOC 2 domain in a fractional capacity, including evidence review, control operation support, auditor communication support, recurring compliance cadence, and SaaS/cloud control maturity.
The right candidate has supported real SOC 2 Type 2 audits and can work with engineering, IT, security, HR, operations, leadership, and auditors.
Essential responsibilities and duties
Nice to have
Expected deliverables
Operating style required
This role requires a senior operator who can own the SOC 2 lane in a fractional capacity.
The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager.
This is not a casual side task.
Responsiveness, ownership, and clean written work product are required.
FYI's Benefits/Incentives: What is in it for you?
Woman-owned private contractor providing federal agencies with human capital management, information technology, training, and workforce-planning services.
Visit company websiteJobs and hiring trendsFull-time
Senior Level
Hybrid
Apply faster on company sites with our extension.