HamburgerMenu
hirist

SOC II Compliance Analyst

HyrMe
2 - 4 Years
Bangalore

Posted on: 23/09/2026

Job Description

Role Overview :

We are looking for a SOC 2 Compliance Analyst to own and manage the organization's SOC 2 compliance program. The role will be responsible for SOC 2 readiness, control assessment, audit coordination, evidence management, remediation, and ongoing control monitoring.

You will work closely with control owners, auditors, and internal stakeholders to ensure that controls remain effective, documented, and audit-ready.

Key Responsibilities :

- Own the SOC 2 Type I and Type II compliance lifecycle from readiness through audit completion.

- Conduct SOC 2 readiness assessments and gap analysis.

- Define, document, and maintain controls aligned with the Trust Services Criteria.

- Coordinate with external auditors and manage the audit evidence request process.

- Drive remediation activities, establish deadlines, and track closure of identified gaps.

- Review and maintain policies, procedures, and supporting documentation to ensure audit readiness.

- Conduct internal control testing, sampling, and periodic assessments.

- Monitor control health and compliance risks and provide regular updates to leadership.

- Work with control owners to improve control effectiveness and compliance processes.

- Guide and support junior analysts and control owners on SOC 2 requirements.

- Continuously improve the organization's control and compliance program.

Required Skills & Experience :

- 2 - 4 years of experience in GRC, IT Audit, Information Security Compliance, or a related function.

- Hands-on experience managing a SOC 2 audit from start to finish.

- Strong understanding of the five SOC 2 Trust Services Criteria.

- Strong knowledge of control design, testing, evidence collection, and remediation.

- Experience working directly with external auditors and business stakeholders.

- Strong documentation, analytical, communication, and stakeholder-management skills.

Good to Have :

- Experience with other compliance frameworks such as ISO 27001, HIPAA, PCI DSS, or DPDP.

- Hands-on experience with GRC platforms such as Vanta, Drata, or Scrut.

- Understanding of cloud security environments across AWS, Azure, or GCP.

- ISO 27001 Lead Auditor certification.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...