Senior Analyst, Security Compliance
Leads SOC examinations, SOX compliance, IT control assessments, and remediation across security, technology, engineering, and finance teams. Requires 5+ years of external IT audit or technology risk experience, strong ICFR/SOX expertise, and familiarity with cloud environments.
About the job
Responsibilities
- Lead and manage SOC 1 and SOC 2 examinations under AICPA standards, partnering with external auditors and internal teams to design, implement, and improve IT control processes.
- Support end-to-end SOX planning and execution, including IT system scoping, audit readiness, and training for control owners.
- Advise Security, IT, Infrastructure, Engineering, Data, and Finance teams by translating SOX and audit requirements into practical, scalable controls.
- Lead security and IT control gap assessments, evaluate control design and operating effectiveness, and drive remediation to completion.
- Mature IT general controls (ITGCs) and IT application controls (ITACs) while balancing regulatory expectations with product and platform innovation.
- Oversee audit initiatives, identify control gaps, assess risk, and guide teams through complex audit and compliance matters.
- Perform SOX control-deficiency impact assessments and develop risk-based remediation plans.
- Implement and enhance controls monitoring and defense-in-depth across key IT risk areas.
- Identify systemic program challenges, recommend process improvements, and drive durable solutions.
- Develop auditor-ready documentation, including data-flow diagrams and process flowcharts for high-risk security and financial processes.
- Work with internal and external auditors to navigate the IT control environment and ensure efficient, high-quality audits.
- Support evidence collection and continuous improvement, including automation to improve efficiency, consistency, and scalability.
Requirements
- 5+ years of experience in external IT audit and/or technology risk assurance or advisory.
- Hands-on experience with Internal Controls over Financial Reporting (ICFR), including SOX 404 frameworks, control design, and operating-effectiveness testing.
- Experience at a Big Four or other large public accounting firm, or equivalent experience working with external auditors in a highly regulated environment.
- Experience leading compliance and audit initiatives from planning and risk assessment through remediation and audit close.
- Experience auditing or assessing hybrid and cloud-based environments, including IaaS, PaaS, and SaaS.
- Knowledge of access management, change management, and logging and monitoring controls.
- Ability to operate autonomously in ambiguous, fast-paced environments and drive cross-functional outcomes.
- Strong oral and written communication skills for technical and non-technical stakeholders.
- Ability to manage multiple priorities, coordinate cross-functional work, and hold stakeholders accountable.
- Strong organizational and time-management skills, self-motivation, and effectiveness in remote or distributed environments.
Nice to Have
- Exposure to fintech, payments, crypto, or digital asset business models, including crypto audit experience.
- Familiarity with NIST, ISO 27001, or COBIT.
- CPA, CISA, CRISC, or similar professional certification.
Compensation and Benefits
- Work in a modern infrastructure environment with exposure to cloud-native architectures and complex, real-time systems.
- Collaborate with globally distributed teams and professionals across engineering, security, and other technical disciplines.
- Influence how controls are designed and scaled in a fast-growing, regulated technology business.
- Gain ownership and visibility while helping shape a maturing audit and compliance program.
Skills
Soc 1, SOC 2, Sox 404, It Audit, Icfr, It General Controls, It Application Controls, Cloud Computing, Iaas, Paas, SaaS, Access Management, Change Management, Nist, ISO 27001
Similar jobs
Security Engineering jobsSenior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.