Seeking an experienced Senior GRC/SOC 2 Consultant to support a SOC 2 Type II readiness and certification initiative. The ideal candidate has hands-on experience guiding organizations through SOC 2 Type II, including control assessment, remediation, evidence collection, and audit coordination, with practical experience using Vanta or a similar GRC automation platform. This is a 6–8 week contract engagement focused on accelerating audit readiness and supporting the organization through the SOC 2 process.
Key Responsibilities
- Lead SOC 2 Type II readiness, including control reviews, gap identification, and remediation planning.
- Partner with Security, IT, Engineering, Operations, and Compliance teams to address SOC 2 requirements.
- Develop and improve required security policies, procedures, and control documentation.
- Manage audit evidence collection, validation, and organization.
- Configure and optimize Vanta for compliance monitoring, evidence automation, and audit readiness.
- Review controls across access management, change management, vulnerability management, incident response, risk management, and vendor management.
- Coordinate with external SOC auditors, respond to audit requests, and assist with identified deficiencies.
- Ensure controls, evidence, and documentation are audit-ready within the required timeline.
Required Qualifications
- 5+ years of experience in GRC, SOC audits, cybersecurity compliance, or security assurance.
- Demonstrated experience helping organizations successfully complete SOC 2 Type II.
- Strong understanding of the AICPA Trust Services Criteria.
- Hands-on experience with Vanta or comparable GRC/compliance automation platforms.
- Experience managing SOC 2 evidence collection, control validation, and audit preparation.
- Working knowledge of frameworks such as NIST, ISO 27001, and CIS Controls.
- Strong documentation, communication, and project management skills.
Preferred Qualifications
- Experience with SaaS, cloud, or technology organizations.
- Background as a SOC auditor, GRC consultant, or security consultant.
- Familiarity with AWS, Azure, or other cloud security environments.
- Experience supporting first-time SOC 2 Type II engagements.
Engagement Details
- Duration: Approximately 6–8 weeks
- Type: Short-term Contractor / Consultant
- Focus: SOC 2 Type II readiness, Vanta optimization, evidence preparation, remediation, and audit support