EnglishWillDo

31 - SOC 2 Subject Matter Expert (Partime)

Tunga · Sweden

No Swedish requiredPosted yesterday
Apply for this job

You apply on the site where the job is posted. I never handle applications.

Developer profile: We are looking for an experienced SOC 2 Subject Matter Expert to guide and strengthen a client's SOC 2 compliance program.

The organisation has already achieved SOC 2 Type I certification and is currently working toward SOC 2 Type II certification, supported by an external audit firm and a compliance automation platform. This is not an implementation or audit role. Instead, we are looking for someone who can provide expert guidance, validate the overall compliance approach, and ensure the organisation has the appropriate controls and risk management processes in place.

Following certification, the engagement will continue in a lighter capacity to help maintain ongoing SOC 2 compliance.

Responsibilities

  • Act as the internal SOC 2 subject matter expert.
  • Review and validate the organisation's control framework and risk management approach.
  • Ensure the appropriate risks, policies, and controls are in place to successfully achieve SOC 2 Type II certification.
  • Advise internal stakeholders on SOC 2 best practices and compliance requirements.
  • Work alongside external partners, including the audit firm and compliance platform provider, throughout the certification process.
  • Identify gaps and recommend improvements to strengthen the compliance program.
  • Support ongoing SOC 2 monitoring and continuous compliance after certification is achieved.

Technical requirements

  • Proven experience leading or advising organisations through SOC 2 Type II certification.
  • Strong understanding of SOC 2 Trust Services Criteria, risk assessments, and internal controls.
  • Experience working with SOC 2 audit firms and compliance automation platforms.
  • Ability to assess existing controls and recommend practical improvements.
  • Excellent stakeholder communication skills, with the ability to explain technical compliance concepts to non-specialists.
  • Experience maintaining ongoing SOC 2 compliance programs is highly preferred.

Nice to have

  • Experience with additional security frameworks such as ISO 27001, NIST, or CIS Controls.
  • Background in cloud security, SaaS environments, or information security governance.

Engagement

  • Fractional / part-time engagement.
  • Fully remote, flexible hours based on project needs.
  • Initial focus on achieving SOC 2 Type II certification, followed by ongoing advisory and monitoring responsibilities to maintain compliance.