Log in
Top pay

Senior Security Compliance Consultant (SOC 2 & GRC Specialist)

Toptal · We Work Remotely18d

1 · Can you apply from ?

Open to
Anywhere in the WorldExact words from the ad · found 26 Sep 2026

2 · What reaches you

Pay not listed
The ad gives no pay, so we can’t work out what reaches you. Ask the company.

3 · How you get paid

Unknown — ask the company

How often
Unknown
Ask the company
First money
Unknown
Ask the company

4 · Your working hours

Not stated

The ad doesn’t say which hours. Ask the company.

5 · Trust

We Work Remotely · found 26 Sep 2026
Listing from We Work Remotely
No one should ask you to pay to work.
Report this post

They ask for

Experience not statedNo degreeSecurity complianceRegulatory complianceAuditRisk managementSprinto

Full description

Shown as posted, in English

Headquarters: Summary We are seeking an elite, hands-on Senior Security Compliance Consultant (SOC 2 & GRC Specialist) to lead a critical, company-wide SOC 2 Type II audit readiness initiative. In this strategic engagement, you will perform comprehensive gap analyses, assess existing security controls, design robust compliance workflows, and drive cross-functional teams toward audit completion. The ideal candidate brings a proven track record in GRC frameworks, control mapping, evidence automation, and policy development. Utilizing automated compliance platforms such as Sprinto, you will build repeatable compliance processes, validate technical controls, and ensure a seamless audit experience across the entire organization. General Information (About the Client) Our client is a fast-scaling, cloud-native technology platform committed to maintaining enterprise-grade trust, security, and data privacy. To support their rapid commercial growth and enterprise sales pipeline, they are establishing a formal, highly disciplined security governance model. They operate a modern, cloud-first environment where compliance is treated not as a passive checklist, but as an active, automated operational advantage. By leveraging modern GRC platforms and fostering a security-conscious culture, they provide an empowering environment for compliance experts to drive real architectural and procedural improvements. Tasks and Deliverables SOC 2 Readiness & Gap Analysis: Conduct a thorough assessment of existing technical and operational security controls, pinpointing compliance gaps and building an actionable remediation roadmap. Control Design & Implementation: Author, refine, and operationalize security controls, policies, and procedures aligned with SOC 2 Trust Services Criteria (TSC) and PCI DSS standards. Automated Evidence Collection: Lead evidence-gathering workflows using automated GRC tooling (Sprinto), ensuring all technical artifacts, access logs, and policy attestations are validated and audit-ready. PCI DSS Guidance: Provide expert advisory on maintaining PCI DSS alignment alongside SOC 2, ensuring overlapping control requirements are mapped efficiently to reduce operational drag. Cross-Functional Coordination: Collaborate with engineering, DevOps, HR, and IT teams to embed compliance workflows into daily operations without slowing down feature execution. Auditor Interface & Readiness: Serve as the primary liaison during the audit preparation phase, coordinating directly with external auditors to present evidence, resolve findings, and ensure a successful audit cycle. Required Experience SOC 2 Mastery: Proven track record of leading end-to-end SOC 2 readiness, gap remediation, and audit preparation initiatives for cloud-native or B2B SaaS companies. GRC & PCI DSS Acumen: Deep familiarity with Governance, Risk, and Compliance (GRC) frameworks, risk assessment methodologies, and PCI DSS compliance requirements. Tooling Proficiency (Sprinto): Direct, practical experience leveraging automated compliance and evidence-collection platforms, specifically Sprinto (or equivalent modern platforms like Vanta/Drata). Policy & Control Mapping: Exceptional capability to author clear, enforceable security policies and translate abstract regulatory requirements into concrete engineering controls. Cross-Functional Facilitation: Strong stakeholder management skills with a history of driving accountability across distributed engineering, product, and operations teams. To apply: https://weworkremotely.com/remote-jobs/toptal-senior-security-compliance-consultant-soc-2-grc-specialist

View on We Work Remotely
Top pay
JobToptal · We Work RemotelyPosted 18d ago

Senior Security Compliance Consultant (SOC 2 & GRC Specialist)

1 · Can you apply from ?

Open to
Anywhere in the WorldExact words from the ad · found 26 Sep 2026

4 · Your working hours

Not stated

The ad doesn’t say which hours. Ask the company.

5 · Trust

We Work RemotelyFound 26 Sep 2026Listing from We Work Remotely
No one should ask you to pay to work.
Something wrong?Report this post

They ask for

Full description

Shown as posted, in English

Headquarters: Summary We are seeking an elite, hands-on Senior Security Compliance Consultant (SOC 2 & GRC Specialist) to lead a critical, company-wide SOC 2 Type II audit readiness initiative. In this strategic engagement, you will perform comprehensive gap analyses, assess existing security controls, design robust compliance workflows, and drive cross-functional teams toward audit completion. The ideal candidate brings a proven track record in GRC frameworks, control mapping, evidence automation, and policy development. Utilizing automated compliance platforms such as Sprinto, you will build repeatable compliance processes, validate technical controls, and ensure a seamless audit experience across the entire organization. General Information (About the Client) Our client is a fast-scaling, cloud-native technology platform committed to maintaining enterprise-grade trust, security, and data privacy. To support their rapid commercial growth and enterprise sales pipeline, they are establishing a formal, highly disciplined security governance model. They operate a modern, cloud-first environment where compliance is treated not as a passive checklist, but as an active, automated operational advantage. By leveraging modern GRC platforms and fostering a security-conscious culture, they provide an empowering environment for compliance experts to drive real architectural and procedural improvements. Tasks and Deliverables SOC 2 Readiness & Gap Analysis: Conduct a thorough assessment of existing technical and operational security controls, pinpointing compliance gaps and building an actionable remediation roadmap. Control Design & Implementation: Author, refine, and operationalize security controls, policies, and procedures aligned with SOC 2 Trust Services Criteria (TSC) and PCI DSS standards. Automated Evidence Collection: Lead evidence-gathering workflows using automated GRC tooling (Sprinto), ensuring all technical artifacts, access logs, and policy attestations are validated and audit-ready. PCI DSS Guidance: Provide expert advisory on maintaining PCI DSS alignment alongside SOC 2, ensuring overlapping control requirements are mapped efficiently to reduce operational drag. Cross-Functional Coordination: Collaborate with engineering, DevOps, HR, and IT teams to embed compliance workflows into daily operations without slowing down feature execution. Auditor Interface & Readiness: Serve as the primary liaison during the audit preparation phase, coordinating directly with external auditors to present evidence, resolve findings, and ensure a successful audit cycle. Required Experience SOC 2 Mastery: Proven track record of leading end-to-end SOC 2 readiness, gap remediation, and audit preparation initiatives for cloud-native or B2B SaaS companies. GRC & PCI DSS Acumen: Deep familiarity with Governance, Risk, and Compliance (GRC) frameworks, risk assessment methodologies, and PCI DSS compliance requirements. Tooling Proficiency (Sprinto): Direct, practical experience leveraging automated compliance and evidence-collection platforms, specifically Sprinto (or equivalent modern platforms like Vanta/Drata). Policy & Control Mapping: Exceptional capability to author clear, enforceable security policies and translate abstract regulatory requirements into concrete engineering controls. Cross-Functional Facilitation: Strong stakeholder management skills with a history of driving accountability across distributed engineering, product, and operations teams. To apply: https://weworkremotely.com/remote-jobs/toptal-senior-security-compliance-consultant-soc-2-grc-specialist