Review the organization's existing documentation, policies, and control environment against applicable SOC 2 Trust Services Criteria.
Conduct a gap analysis identifying missing, weak, or undocumented controls.
Design and recommend new or enhanced controls to close identified gaps.
Draft policies, procedures, and supporting documentation required for SOC 2 readiness (e.g., access control policy, change management procedures, incident response plan, vendor risk policy).
Partner with control owners across Information Security, IT, Engineering, Compliance, Risk, and Operations to socialize and operationalize new controls.
Advise on evidence collection practices so controls are demonstrable and audit-ready once implemented.
Evaluate readiness across areas such as:
Identity and access management
User access reviews
Change management
Vulnerability management
Incident response
Logging and monitoring
Business continuity / disaster recovery
Vendor / third-party risk
Data security and confidentiality
Security awareness
Asset management
System development lifecycle
Build and maintain a readiness roadmap/tracker with prioritized remediation items, owners, and target dates.
Prepare the organization to engage an external audit firm advising on scoping, evidence packaging, and audit logistics (without performing the independent audit itself).
Provide senior-level reporting on readiness status, open gaps, and remediation progress to leadership.
Required Qualifications
10+ years of experience in IT audit, compliance, risk, cybersecurity governance, GRC, or SOC 2 readiness/advisory work.
Demonstrated experience leading SOC 2 readiness engagements not solely as an examiner/tester, but as an advisor who has built control environments from scratch or matured them toward certification.
Strong understanding of the AICPA Trust Services Criteria and how to operationalize them into practical controls and policies.
Experience working within fintech, banking, payments, financial services, SaaS, or another highly regulated technology environment.
Proven ability to draft clear, audit-ready policies and procedures.
Strong understanding of IT general controls and business process controls.
Ability to identify gaps and translate them into actionable, prioritized remediation plans.
Strong written and verbal communication skills, including the ability to present findings and roadmaps to senior management.
Ability to work independently in a remote consulting environment.
Preferred Qualifications
CPA, CISA, CISSP, CIA, CISM, CRISC, or comparable certification.
Prior experience taking a fintech or SaaS company through its first SOC 2 Type I or Type II certification.
Experience working directly with external audit/attestation firms during the audit handoff.
Experience with GRC and compliance platforms such as Drata, Vanta, Secureframe, OneTrust, Archer, ServiceNow GRC, or similar.
Experience with cloud environments, particularly AWS, Azure, or GCP.
Knowledge of PCI DSS, ISO 27001, NIST, FFIEC, GLBA, or other financial-services control frameworks.
Numbers & Facts
Location
New York, NY (Remote)
Industry
Staffing/Employment Agencies
Salary
$50–$100 Per Hour
Company Size
50 to 99 employees
Year Founded
2002
Website
https://phaxis.com/
About Company
We stand for PERSEVERANCE, as we refuse to quit when the journey gets tough. Your gold is our mission, and we search day and night to find it.
Skills
Access Controlunmatched
Amazon Web Services (AWS)unmatched
American Institute of Certified Public Accountants (AICPA)unmatched
Asset Managementunmatched
Auditingunmatched
Banking Servicesunmatched
Business Processesunmatched
Change Managementunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Computer Securityunmatched
Consultingunmatched
Disaster Recoveryunmatched
Documentationunmatched
Establish Prioritiesunmatched
External Auditunmatched
Financial Servicesunmatched
GCP (Good Clinical Practices)unmatched
Gap Analysisunmatched
ISO (International Organization for Standardization)unmatched
Identity Data Managementunmatched
Incident Responseunmatched
Information Technology/Systems Auditunmatched
Information/Data Security (InfoSec)unmatched
Internet Securityunmatched
Leadershipunmatched
Logisticsunmatched
Microsoft Windows Azureunmatched
PCI-DSSunmatched
Policy Developmentunmatched
Presentation/Verbal Skillsunmatched
Procedure Developmentunmatched
Process Control Engineeringunmatched
Riskunmatched
ServiceNowunmatched
Software Development Lifecycle (SDLC)unmatched
Software as a Service (SaaS)unmatched
U.S. National Institute of Standards and Technology (NIST)unmatched
Vendor/Supplier Planningunmatched
Writing Skillsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.