Jobs › SOC 2
SOC 2 Compliance Jobs
SOC 2 is the AICPA's trust and security attestation, the standard SaaS and cloud companies use to prove their controls to customers.
SOC 2 is an attestation report, defined by the AICPA's Trust Services Criteria, that tells customers an organization's controls over security, and optionally availability, processing integrity, confidentiality, and privacy, are designed and operating effectively. A Type I report assesses design at a point in time, a Type II report assesses operating effectiveness over a period, usually three to twelve months. It is not a law, but for B2B software and cloud companies it has become the price of doing business, the report a prospect's security team asks for before signing.
Because almost every SaaS company needs one, SOC 2 readiness and audit work is one of the highest-volume entry points in GRC. The roles run from building the control environment and evidence collection to managing the audit and the auditor relationship, and they are a common on-ramp to broader security-compliance and GRC careers.
SOC 2: Frequently Asked Questions
What is SOC 2?
SOC 2 is an attestation report based on the AICPA Trust Services Criteria that demonstrates an organization's controls over security and, optionally, availability, processing integrity, confidentiality, and privacy are effective.
What is the difference between SOC 2 Type I and Type II?
Type I assesses whether controls are suitably designed at a point in time. Type II assesses whether they operated effectively over a period, typically three to twelve months.
Is SOC 2 required by law?
No. SOC 2 is voluntary, but it is effectively required by customers in B2B software and cloud, where security teams request it before purchasing.
Open SOC 2 GRC jobs (45)
Lead, Security Controls Assurance - SOX
Security Risk Management Specialist II
Enterprise Risk Manager / Hibrido - Barueri SP
Governance, Risk, and Compliance Manager - FedRAMP
Senior Compliance Manager
Governance, Risk, and Compliance Manager - Privacy
Security Compliance, GRC Engineer
Product GRC Subject Matter Expert, (V4G)
Subject Matter Expert, GTM GRC - V4G
Security & AI Governance Lead
Senior Third-Party Risk Specialist
Technical Audit Manager - CSO CTO (f/m/x)
Senior GRC Analyst
Security Compliance Specialist
GRC Pre-Sales Consultant / Solutions Engineer – EMEA
Director of Cybersecurity Governance, Risk and Compliance
Cybersecurity & AI Engineer Automation
Global Risk and Compliance Manager
IT SOX Controls Specialist
Internal Audit Manager
Senior Manager, Information Compliance, AI Governance & Privacy
Senior Privacy Counsel
Staff Program Manager, Compliance
Field CISO
GRC Engineer
Governance, Risk & Compliance Analyst
Virtual CISO & Cybersecurity Practice Lead
Head of Security & AI Governance
Director of Governance, Risk, and Compliance
Governance, Risk & Compliance (GRC) Analyst
Sr Manager, Governance, Risk, Compliance & Privacy
GRC Program Manager
Program Manager, Security GRC
Security Assurance Lead
Security Engineer, GRC
Software Engineer, Risk Management
Senior Security Compliance Specialist
Security Compliance Analyst, Privacy
Governance, Risk & Compliance (GRC) Manager
IT Enterprise Risk Analyst
GRC Pre-Sales Consultant / Solutions Engineer – DACH market, EMEA
EMEA Assurance Lead
Senior Software Engineer, Trust and Third Party Risk Management
Security Controls Assurance Lead
Senior GRC Program Manager
SOC 2 jobs: what the market looks like right now
A snapshot built from the 45 SOC 2 roles currently on this page.
What these roles pay
Of the 45 open SOC 2 roles on this page, 13 publish a salary range. Across those:
- Median advertised midpoint: $233k
- Middle half of the market: $155k to $250k
- Full advertised range: $62k to $410k
Computed from the live postings on this page, not from survey data, and recalculated every time the board refreshes. Roles without a published range are excluded.
Where the work is
- Work mode: 11 remote, 2 hybrid, 32 on-site or unstated.
- Seniority mix: senior (23), mid (16), executive (4), director (2)
- Employers hiring more than one: Vanta (5), Mistral AI (3), Anthropic (2), Decagon (2), Stripe (2), Cloudflare (2)
Skills these postings ask for
- board and committee reporting
- policy lifecycle ownership
- risk appetite and tolerance setting
- three-lines-of-defence operating models
- ISO/IEC 42001 and NIST AI RMF fluency
How to get a governance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in SOC 2 postings to be worth knowing: CGEIT, CRISC, AIGP, CISA. The certification academy covers what each one actually tests and who it is for.
Hiring for SOC 2?
We have 45 open SOC 2 roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
All GRC jobs · Job alerts