SOC 2 Advisory Consultant
Phaxis · New York, NY · 2 wk ago
RemoteRemoteConsultingContract
Responsibilities
- Review the organization's existing documentation, policies, and control environment against applicable SOC 2 Trust Services Criteria.
- Conduct a gap analysis identifying missing, weak, or undocumented controls.
- Design and recommend new or enhanced controls to close identified gaps.
- Draft policies, procedures, and supporting documentation required for SOC 2 readiness (e.g., access control policy, change management procedures, incident response plan, vendor risk policy).
- Partner with control owners across Information Security, IT, Engineering, Compliance, Risk, and Operations to socialize and operationalize new controls.
- Advise on evidence collection practices so controls are demonstrable and audit-ready once implemented.
- Evaluate readiness across areas such as:
- Identity and access management
- User access reviews
- Change management
- Vulnerability management
- Incident response
- Logging and monitoring
- Business continuity / disaster recovery
- Vendor / third-party risk
- Data security and confidentiality
- Security awareness
- Asset management
- System development lifecycle
- Build and maintain a readiness roadmap/tracker with prioritized remediation items, owners, and target dates.
- Prepare the organization to engage an external audit firm — advising on scoping, evidence packaging, and audit logistics (without performing the independent audit itself).
- Provide senior-level reporting on readiness status, open gaps, and remediation progress to leadership.
Requirements
- 10+ years of experience in IT audit, compliance, risk, cybersecurity governance, GRC, or SOC 2 readiness/advisory work.
- Demonstrated experience leading SOC 2 readiness engagements — not solely as an examiner/tester, but as an advisor who has built control environments from scratch or matured them toward certification.
- Strong understanding of the AICPA Trust Services Criteria and how to operationalize them into practical controls and policies.
- Experience working within fintech, banking, payments, financial services, SaaS, or another highly regulated technology environment.
- Proven ability to draft clear, audit-ready policies and procedures.
- Strong understanding of IT general controls and business process controls.
- Ability to identify gaps and translate them into actionable, prioritized remediation plans.
- Strong written and verbal communication skills, including the ability to present findings and roadmaps to senior management.
- Ability to work independently in a remote consulting environment.
Preferred Qualifications
- CPA, CISA, CISSP, CIA, CISM, CRISC, or comparable certification.
- Prior experience taking a fintech or SaaS company through its first SOC 2 Type I or Type II certification.
- Experience working directly with external audit/attestation firms during the audit handoff.
- Experience with GRC and compliance platforms such as Drata, Vanta, Secureframe, OneTrust, Archer, ServiceNow GRC, or similar.
- Experience with cloud environments, particularly AWS, Azure, or GCP.
- Knowledge of PCI DSS, ISO 27001, NIST, FFIEC, GLBA, or other financial-services control frameworks.