GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsSOC 2

SOC 2 Compliance Jobs

SOC 2 is the AICPA's trust and security attestation, the standard SaaS and cloud companies use to prove their controls to customers.

New SOC 2 GRC jobs, the moment they post.

One click unsubscribe.

SOC 2 is an attestation report, defined by the AICPA's Trust Services Criteria, that tells customers an organization's controls over security, and optionally availability, processing integrity, confidentiality, and privacy, are designed and operating effectively. A Type I report assesses design at a point in time, a Type II report assesses operating effectiveness over a period, usually three to twelve months. It is not a law, but for B2B software and cloud companies it has become the price of doing business, the report a prospect's security team asks for before signing.

Because almost every SaaS company needs one, SOC 2 readiness and audit work is one of the highest-volume entry points in GRC. The roles run from building the control environment and evidence collection to managing the audit and the auditor relationship, and they are a common on-ramp to broader security-compliance and GRC careers.

SOC 2: Frequently Asked Questions

What is SOC 2?

SOC 2 is an attestation report based on the AICPA Trust Services Criteria that demonstrates an organization's controls over security and, optionally, availability, processing integrity, confidentiality, and privacy are effective.

What is the difference between SOC 2 Type I and Type II?

Type I assesses whether controls are suitably designed at a point in time. Type II assesses whether they operated effectively over a period, typically three to twelve months.

Is SOC 2 required by law?

No. SOC 2 is voluntary, but it is effectively required by customers in B2B software and cloud, where security teams request it before purchasing.

Open SOC 2 GRC jobs (45)

Lead, Security Controls Assurance - SOX

Anthropic
On-site · San Francisco, CA, WA New York City · Full-time
$410k Governance CISA CISSP Sep 10, 2026

Security Risk Management Specialist II

Affirm
Remote · Canada · Remote · Full-time
$101k to $151k Featured Risk CISA CISM CRISC Sep 10, 2026

Enterprise Risk Manager / Hibrido - Barueri SP

Capco
On-site · Brazil · Full-time
Featured Risk Sep 8, 2026

Governance, Risk, and Compliance Manager - FedRAMP

Decagon
On-site · San Francisco · Full-time
$190k to $275k Featured Compliance Sep 7, 2026

Senior Compliance Manager

Backbase
On-site · Amsterdam · Full-time
Featured Compliance CISM CRISC CISSP Sep 7, 2026

Governance, Risk, and Compliance Manager - Privacy

Decagon
On-site · San Francisco · Full-time
$190k to $275k Featured Privacy Sep 7, 2026

Security Compliance, GRC Engineer

Mistral AI
On-site · Paris · Full-time
Featured Compliance CISA CISM CRISC Sep 7, 2026

Product GRC Subject Matter Expert, (V4G)

Vanta
Remote · . · Remote · Full-time
Featured Governance CISA CISM CISSP Sep 7, 2026

Subject Matter Expert, GTM GRC - V4G

Vanta
Remote · . · Remote · Full-time
Featured Governance CISA CISM CISSP Sep 7, 2026

Security & AI Governance Lead

Tribe AI
On-site · United States · Full-time
Featured AI Governance Public Trust Sep 7, 2026

Senior Third-Party Risk Specialist

Mistral AI
On-site · Paris · Full-time
Featured Risk Sep 7, 2026

Technical Audit Manager - CSO CTO (f/m/x)

Deutsche Bank
On-site · Bucharest, 6A Dimitrie Pompeiu Blvd · Full-time
Featured Audit CISA CRISC CISSP Sep 7, 2026

Senior GRC Analyst

Gusto
On-site · San Francisco, CA · Full-time
$183k Featured Governance CISA CRISC CGEIT Sep 7, 2026

Security Compliance Specialist

Mistral AI
On-site · Paris · Full-time
Featured Compliance Sep 7, 2026

GRC Pre-Sales Consultant / Solutions Engineer – EMEA

Vanta
On-site · London, UK · Full-time
Featured Governance Sep 7, 2026

Director of Cybersecurity Governance, Risk and Compliance

UT Austin
On-site · UT MAIN CAMPUS · Full-time
$170k Featured Compliance CISA CISM CRISC Sep 3, 2026

Cybersecurity & AI Engineer Automation

Mirakl
On-site · Paris, France · Full-time
Featured Cybersecurity Aug 31, 2026

Global Risk and Compliance Manager

Elixirr
On-site · London, UK · Full-time
Featured Governance Aug 31, 2026

IT SOX Controls Specialist

Stripe
On-site · SEA, SF, NYC · Full-time
Featured Governance CISA Aug 31, 2026

Internal Audit Manager

Coinbase
Remote · Luxembourg · Remote · Full-time
Featured Audit CISA Aug 30, 2026

Senior Manager, Information Compliance, AI Governance & Privacy

Simon-Kucher
Hybrid · Toronto, ON, Canada · Full-time
$140k to $170k Featured AI Governance Privacy CISM CRISC CISSP Aug 27, 2026

Senior Privacy Counsel

Abnormal Security
Remote · Remote · Full-time
Featured Privacy CIPP Aug 22, 2026

Staff Program Manager, Compliance

Zscaler
On-site · Mohali, IND · Full-time
Featured Compliance CISA CISM CISSP Aug 22, 2026

Field CISO

Drata
Remote · Remote · Full-time
$210k to $350k Featured Governance CISM CRISC CISSP Aug 22, 2026

GRC Engineer

Cloudflare
On-site · Hybrid · Full-time
Featured Governance Aug 22, 2026

Governance, Risk & Compliance Analyst

Perplexity
On-site · San Francisco · Full-time
Featured Compliance Aug 22, 2026

Virtual CISO & Cybersecurity Practice Lead

Interdependence
Remote · Remote · Full-time
$200k to $300k Featured Cybersecurity CISM CRISC CISSP Aug 20, 2026

Head of Security & AI Governance

Flip
On-site · Los Angeles · Full-time
Featured Cybersecurity AI Governance Aug 20, 2026

Director of Governance, Risk, and Compliance

EliseAI
On-site · New York City · Full-time
$200k to $275k Featured Compliance Aug 17, 2026

Governance, Risk & Compliance (GRC) Analyst

Alignerr
Remote · Remote · Contract
$30 to $55/hr Featured Compliance Aug 15, 2026

Sr Manager, Governance, Risk, Compliance & Privacy

Data Analysis Inc
Plano, TX · Full-time
Featured Governance CISA CISM CRISC Aug 13, 2026

GRC Program Manager

Palantir Technologies
On-site · New York, NY · Full-time
$90k to $160k Featured Governance Clearance required Aug 11, 2026

Program Manager, Security GRC

Stripe
Remote · Remote · Full-time
Featured Governance Aug 11, 2026

Security Assurance Lead

Scale AI
On-site · Washington, DC · Full-time
Featured Governance Top Secret CISA CISM CISSP Aug 11, 2026

Security Engineer, GRC

Plaid
On-site · San Francisco · Full-time
Featured Governance Aug 11, 2026

Software Engineer, Risk Management

Hyperproof
Remote · Remote · Full-time
Featured Risk Aug 11, 2026

Senior Security Compliance Specialist

Cloudflare
On-site · Distributed · Full-time
Featured Compliance Aug 11, 2026

Security Compliance Analyst, Privacy

LangChain
On-site · San Francisco, CA · Full-time
Featured Privacy Aug 10, 2026

Governance, Risk & Compliance (GRC) Manager

Northwood Space
On-site · El Segundo, CA · Full-time
Featured Compliance Aug 10, 2026

IT Enterprise Risk Analyst

Holland & Knight
Hybrid · Miami, FL · Full-time
Featured Risk Jul 31, 2026

GRC Pre-Sales Consultant / Solutions Engineer – DACH market, EMEA

Vanta
On-site · London, UK · Full-time
Featured Governance Jun 28, 2026

EMEA Assurance Lead

Scale AI
On-site · Doha, Qatar · Full-time
Featured Governance Clearable CISA CISM CISSP Jun 28, 2026

Senior Software Engineer, Trust and Third Party Risk Management

Vanta
Remote · . · Remote · Full-time
Featured Risk Jun 26, 2026

Security Controls Assurance Lead

Anthropic
On-site · San Francisco, CA, NY Washington · Full-time
$270k Featured Governance Jun 20, 2026

Senior GRC Program Manager

Ripple
On-site · Luxembourg · Full-time
Featured Governance CISA CISSP Jun 20, 2026

SOC 2 jobs: what the market looks like right now

A snapshot built from the 45 SOC 2 roles currently on this page.

What these roles pay

Of the 45 open SOC 2 roles on this page, 13 publish a salary range. Across those:

  • Median advertised midpoint: $233k
  • Middle half of the market: $155k to $250k
  • Full advertised range: $62k to $410k

Computed from the live postings on this page, not from survey data, and recalculated every time the board refreshes. Roles without a published range are excluded.

Where the work is

  • Work mode: 11 remote, 2 hybrid, 32 on-site or unstated.
  • Seniority mix: senior (23), mid (16), executive (4), director (2)
  • Employers hiring more than one: Vanta (5), Mistral AI (3), Anthropic (2), Decagon (2), Stripe (2), Cloudflare (2)

Skills these postings ask for

  • board and committee reporting
  • policy lifecycle ownership
  • risk appetite and tolerance setting
  • three-lines-of-defence operating models
  • ISO/IEC 42001 and NIST AI RMF fluency

How to get a governance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.

Certifications that come up most

None of these are universally required, but they appear often enough in SOC 2 postings to be worth knowing: CGEIT, CRISC, AIGP, CISA. The certification academy covers what each one actually tests and who it is for.

Hiring for SOC 2?

We have 45 open SOC 2 roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

New SOC 2 GRC jobs, the moment they post.

One click unsubscribe.