Senior SOC 2 Staff Auditor
About the Company
A leading security and compliance firm, trusted by over 1200 organizations worldwide, specializes in audit and compliance solutions for standards such as SOC 1, SOC 2, ISO 27001, PCI DSS, and HIPAA. As a licensed CPA firm, PCI Qualified Security Assessor (QSA), and ISO 27001 Certification Body, the firm is dedicated to simplifying IT compliance through innovative technologies and an agile approach.
Location
Remote - Philippines
Start date
ASAP
Type
Full-time Long Term Contract
Description
In this role, you will:
- Execute day-to-day activities of IT audit engagements, including SOC 1, SOC 2, and HIPAA assessments, under management direction.
- Evaluate the design and effectiveness of technology controls.
- Identify and communicate IT audit findings to management.
- Assist in identifying performance improvement opportunities for assigned clients.
- Communicate effectively with clients and team members.
- Lead client meetings and foster relationships through proactive communication.
- Provide weekly status reports to management.
- Proactively communicate any potential issues to management.
Requirements
- Excellent oral and written communication skills.
- Ability to work independently and collaboratively.
- High degree of motivation.
- Fluent in English, confidently communicate with clients daily.
- Bachelor’s degree in accounting, business, cyber security, or management information systems.
- At least 5 years of experience performing IT audit engagements at a Big 4 or other audit/consulting firm.
Top 5 Technical Skills Required
- IT Audit Execution – Proficiency in performing SOC 1, SOC 2, and HIPAA audits, including assessing control design and effectiveness.
- Risk Assessment – Ability to identify and evaluate IT risks and control weaknesses in complex environments.
- Compliance Frameworks – Knowledge of standards such as SOC 1/2, ISO 27001, PCI DSS, and HIPAA.
- GRC Tools – Experience with governance, risk, and compliance platforms to streamline audit processes.
- Technical Communication – Skill in documenting and presenting audit findings clearly to technical and non-technical stakeholders.
Nice-to-Have Technical Skills
- Compliance Automation Tools – Familiarity with tools like Vanta, Drata, or Secureframe for automating compliance workflows.
- Cloud Security – Understanding of cloud environments (e.g., AWS, Azure) and related security controls.
- Cybersecurity Frameworks – Knowledge of additional frameworks like NIST CSF or GDPR.
Why Join?
This role provides an opportunity to work with a global leader in security and compliance, utilizing cutting-edge technologies in a fully remote, collaborative environment. You will grow professionally and make a significant impact on clients’ compliance postures.
Please note if you are successful, the first weeks training will be at 9pm (client is based in USA) for 8 hours, then will resume normal working hours.
Shift is from 21:00 to 05:00 America/New_York time.