Jobs › SOC 2
SOC 2 Compliance Jobs
SOC 2 is the AICPA's trust and security attestation, the standard SaaS and cloud companies use to prove their controls to customers.
SOC 2 is an attestation report, defined by the AICPA's Trust Services Criteria, that tells customers an organization's controls over security, and optionally availability, processing integrity, confidentiality, and privacy, are designed and operating effectively. A Type I report assesses design at a point in time, a Type II report assesses operating effectiveness over a period, usually three to twelve months. It is not a law, but for B2B software and cloud companies it has become the price of doing business, the report a prospect's security team asks for before signing.
Because almost every SaaS company needs one, SOC 2 readiness and audit work is one of the highest-volume entry points in GRC. The roles run from building the control environment and evidence collection to managing the audit and the auditor relationship, and they are a common on-ramp to broader security-compliance and GRC careers.
SOC 2: Frequently Asked Questions
What is SOC 2?
SOC 2 is an attestation report based on the AICPA Trust Services Criteria that demonstrates an organization's controls over security and, optionally, availability, processing integrity, confidentiality, and privacy are effective.
What is the difference between SOC 2 Type I and Type II?
Type I assesses whether controls are suitably designed at a point in time. Type II assesses whether they operated effectively over a period, typically three to twelve months.
Is SOC 2 required by law?
No. SOC 2 is voluntary, but it is effectively required by customers in B2B software and cloud, where security teams request it before purchasing.
Open SOC 2 GRC roles (33)
GRC and AI Governance - Senior Manager
Governance, Risk & Compliance (GRC) Manager
Senior GRC Engineer
Manager, GRC Subject Matter Experts, Product
Senior GRC Specialist
Senior AI GRC Engineer
Senior GRC Lead
Senior Compliance Advisor
Security GRC Manager: Customer Trust Enablement
Senior Director of Governance, Risk and Compliance
Director of Governance, Risk, and Compliance (GRC)
Senior Fullstack Engineer, Vendor Risk Management - UK
Compliance Program Assistant Manager
Senior Compliance Engineer
Governance Risk and Compliance
Engineering Manager, GRC Platform
Staff+ Software Engineer, GRC Platform
Internal Audit IT Associate Manager
Internal Audit IT Manager
Senior IT Auditor
GRC Specialist
Staff+ Security Engineer, Risk Engineering
Senior Fullstack Engineer, Vendor Risk Management
Insider Risk Analyst - SkillBridge Intern
Senior Engineering Manager, Privacy & Data Security
Group Product Manager, GRC Workflows
Senior Manager, Audit Partnerships
HR Compliance, Risk & Policy Lead
Senior HR Compliance Manager
Senior Fullstack Software Engineer, Privacy & Data Security
GRC Engineer
Staff Analyst, Customer Audit
Director of Security, GRC
All GRC jobs · Job alerts