Security Compliance Analyst Remote
Overview
Security Compliance Analyst leads full certification lifecycle for ISO and SOC 2 Type 2 audits, bridging technical engineering teams and external auditors. This fully remote role involves owning end-to-end audit processes, defining technical requirements, and utilizing AI automation to streamline compliance tasks. The ideal candidate is a hands-on practitioner skilled in SaaS environments and capable of articulating technical controls to diverse stakeholders.
What You'll Do16
- 1Own and drive ISO and SOC 2 Type 2 audit lifecycles from planning to final reporting
- 2Define detailed audit requirements and translate control language into technical requests for engineering teams
- 3Request collect and organize evidence while maintaining audit readiness
- 4Review and validate technical evidence identifying gaps or inconsistencies
- 5Track remediation activities and follow up with stakeholders for issue resolution
- 6Serve as primary liaison with external audit firms and defend control environments
- 7Create and maintain annual audit calendars with preparation activities
- 8Coordinate pre-audit reviews and readiness assessments
- 9Utilize AI and LLMs to automate evidence collection and parse system logs
- 10Review technical configuration reports for infrastructure and database security alignment
- 11Research secure configurations for unfamiliar technologies and recommend implementations
- 12Explain specific evidence requirements to engineers using precise technical language
- 13Collaborate with engineering and security teams to define technical controls aligned with frameworks
- 14Communicate complex compliance requirements to non-technical stakeholders
- 15Push back constructively on auditors with evidence-based explanations
- 16Contribute to continuous improvement of compliance processes through automation
Requirements13
- 1Proven experience managing end-to-end ISO and SOC 2 Type 2 audits
- 2Baseline understanding of ISO and SOC 2 frameworks and control requirements
- 3Experience running audits with preference for technology-focused auditing
- 4Technical literacy in cloud platforms especially AWS
- 5Ability to interpret technical configuration reports for security standards
- 6Experience identifying insufficient or invalid technical evidence
- 7Demonstrated use of AI and LLMs for compliance tasks with human-in-the-loop validation
- 8Strong communication skills for explaining complex requirements to non-technical audiences
- 9Understanding of SaaS infrastructure on public and private clouds
- 10Familiarity with networking concepts and Linux-based server environments
- 11Exposure to containerized environments including Kubernetes and Docker
- 12Knowledge of NIST framework and related security policies
- 13Interest in improving audit processes through automation and innovative tooling
Salary Insight
$50 - $55k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
AWS Security Assurance Services LLC
VerifiedSecurity & Compliance Engineer II - AWS Security Assurance Services
Design and deploy secure AWS solutions for regulated customers. Lead threat modeling and architecture reviews. Build custom controls and automate compliance monitoring. Drive risk reduction at scale. This role differs by focusing on end-to-end ownership of security engineering deliverables across the full lifecycle. It emphasizes translating compliance frameworks into secure-by-design AWS implementations.
Clinicallyai
VerifiedSecurity and Compliance Manager at Clinically AI
Security and Compliance Manager leading compliance program end to end at Clinically AI. Own frameworks SOC2 Type II HIPAA NIST ensuring audit readiness and continuous compliance while scaling rapidly.
Mercor
VerifiedSecurity Review Expert - SOC 2
Mercor seeks a Security Review Expert to evaluate vendor SOC 2 reports and security questionnaires. This remote contract role involves analyzing compliance evidence and providing rubric-based feedback. The ideal candidate will improve AI model performance while working independently.

Saicon Consultants Inc.
VerifiedCyber Security Analyst - Saicon Consultants Inc.
Lead ownership of GRC Risk Management Analyst duties supporting information security and third-party risk management at a fast-paced environment. This role blends structured governance with hands-on technical expertise to evaluate vendor security postures across the entire relationship lifecycle. You will drive continuous monitoring and offboarding processes while delivering actionable insights that enhance organizational resilience. What sets this position apart is the emphasis on proactive threat scenario modeling and deep architectural analysis.

Virtusa Corporation
VerifiedLead Cyber Security Engineer IAM Cloud Architecture
Own and scale secure identity access management solutions across cloud platforms. Lead cross functional teams to design and implement robust security frameworks. Drive adoption of modern authentication protocols and zero trust architectures.

Mercor
VerifiedSOC Investigation Specialist Talent Network | $70-$95/hr Remote
Are you a seasoned SOC analyst looking to put your investigative skills to work on next-generation security challenges? Mercor is partnering with high-growth tech and enterprise companies to build AI-driven SOC automation, and we need your real-world expertise to review, validate, and construct high-quality security investigations. In this remote, part-time role, you'll dig into alerts across SIEM, endpoint, cloud, and identity platforms—using Splunk heavily to pivot through logs and reason about SPL queries. Your judgment will directly shape how automated systems and human teams investigate threats, making this a high-impact opportunity for someone who loves the craft of investigation.