SOC 2 Assessor in United States at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a SOC 2 Assessor based in the United States.
This is a specialized security compliance consulting role focused on evaluating, testing, and validating the effectiveness of internal controls under SOC 2 Type II frameworks. You will work with organizations across cloud and enterprise environments to assess their security, availability, confidentiality, processing integrity, and privacy controls in alignment with AICPA Trust Services Criteria. The role is highly analytical and detail-driven, requiring deep expertise in audit methodologies, risk assessment, and evidence-based evaluation. You will operate in a remote, project-based environment where independence, precision, and strong documentation skills are critical. A key part of your impact will be producing formal audit reports, identifying control gaps, and recommending remediation strategies that strengthen clients’ security posture. You will also stay current on evolving threat landscapes to ensure assessments reflect real-world risks. This is an ideal role for an experienced compliance professional who thrives in structured, high-stakes audit environments.
In this role, you will lead SOC 2 Type II assessments and ensure rigorous evaluation of client security controls in accordance with industry standards:
- Test and evaluate the operating effectiveness of internal controls aligned with AICPA Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy).
- Conduct gap analyses and readiness assessments to identify weaknesses in existing control environments.
- Collect, validate, and organize audit evidence to support findings and ensure compliance accuracy.
- Compile and deliver comprehensive SOC 2 Type II audit reports with clear findings and documented conclusions.
- Provide actionable remediation guidance and best practice recommendations to improve client security posture.
- Monitor and incorporate threat intelligence insights to ensure assessments reflect current risk landscapes.
- Develop and review key performance indicators related to implemented security and control measures.
- Collaborate with client stakeholders to clarify findings and support audit readiness and remediation efforts.
- Ensure consistency, accuracy, and completeness across all audit documentation and deliverables.
The ideal candidate is an experienced security and compliance professional with strong SOC 2 audit expertise and deep understanding of enterprise security frameworks:
- 5+ years of experience in IT security, compliance, or audit roles, including recent SOC 2 Type II assessment experience.
- Strong understanding of AICPA Trust Services Criteria and SOC 2 reporting requirements.
- Experience conducting security risk assessments, control testing, and gap analyses.
- Knowledge of cloud security environments and enterprise IT infrastructures.
- Familiarity with security governance, policies, and compliance frameworks.
- Experience in incident management, threat analysis, and security monitoring practices.
- Strong analytical and documentation skills with high attention to detail.
- Ability to independently manage audit engagements in a remote, project-based environment.
- Excellent communication skills for reporting findings and advising stakeholders.
- Bachelor’s degree in Computer Science or related field preferred, or equivalent experience and certifications.
- Relevant industry certifications or equivalent practical experience strongly valued.
- Competitive hourly compensation: $50–$90/hr (contract-based, 1099 or C2C)
- Remote, flexible project-based work arrangement
- Opportunity to work on high-impact SOC 2 assessments across diverse industries
- Exposure to enterprise and federal-aligned security compliance environments
- Independent consulting-style engagement with autonomy over execution
- Opportunity to strengthen expertise in security governance and audit methodologies
- Potential contract renewals based on performance and project needs
- Work aligned with evolving cybersecurity and threat intelligence practices