
Senior SOC 2 Readiness, Remediation & Audit Support Lead (PL865)
- Hybrid
- Toronto, Ontario, Canada
Job description
Engagement Type: Contract
Initial Term: Six months, with potential extension through completion of the SOC 2 Type II audit, remediation follow-up, and annual SOC 2 maintenance.
Position Overview
Paralucent is preparing for a SOC 2 Type II report covering an application/AWS-hosted environment and supporting corporate controls. We are seeking a senior, hands-on SOC 2 Readiness & Remediation Consultant to lead the majority of internal preparation, reduce the effort required from Paralucent stakeholders, and drive a six-month path to audit readiness.
The consultant will own day-to-day SOC 2 readiness, remediation planning, evidence collection, control implementation support, AWS and Microsoft 365 remediation coordination, vendor evidence management, observation-period evidence retention, auditor request preparation, and client evidence support.
This role excludes formal penetration testing execution and independent SOC 2 Type II attestation, which will be performed by separate providers.
Key Responsibilities
SOC 2 Readiness & Roadmap
Lead the SOC 2 readiness assessment across the application/AWS environment and corporate controls.
Review existing policies, technical evidence, security assessments, architecture, vendor documentation, and prior security questionnaires.
Identify control, remediation, evidence, and ownership gaps and map controls to applicable SOC 2 criteria.
Develop a prioritized remediation roadmap, control matrix, evidence gap register, and executive readiness/status reporting.
Coordinate with the independent CPA attestation firm to confirm scope, criteria, evidence expectations, and observation-period timing.
2. Six-Month Execution & Remediation
Build and own the integrated six-month SOC 2 plan covering readiness, remediation, evidence, observation-period support, penetration testing coordination, and audit preparation.
Manage the remediation backlog, critical path, risks, dependencies, and blockers.
Work with internal owners to implement and validate controls, prepare remediation evidence, capture before/after evidence, and track issues through closure.
Maintain remediation, control implementation, issue closure, and audit-readiness tracking.
3. AWS Security & Remediation
Review AWS configurations relevant to SOC 2 and coordinate or, where approved, perform remediation.
Collect evidence covering IAM, MFA, privileged access, access keys, encryption, logging, monitoring, backups, vulnerability management, CloudTrail, GuardDuty, Security Hub, Inspector, S3, KMS, Lambda, DynamoDB, CloudFront, and data segregation.
Validate production impact with technical owners and maintain required change-management evidence.
4. Microsoft 365 & Entra ID
Review and remediate SOC 2-related Microsoft 365 and Entra ID controls.
Collect evidence for MFA, Conditional Access, admin roles, access reviews, security policies, audit logs, SharePoint/OneDrive, email security, endpoint/security baselines, and onboarding/offboarding.
Document configuration changes and maintain audit-ready evidence.
5. Evidence & Observation-Period Management
Establish and maintain the SOC 2 evidence repository, naming/versioning standards, evidence index, and control-to-evidence matrix.
Collect, review, organize, and quality-check technical, policy, HR/training, vendor, governance, operational, and client-specific evidence.
Establish recurring evidence collection and retention processes throughout the observation period.
Track exceptions, missed controls, compensating actions, remediation, and evidence completeness.
6. Vendor Risk & Evidence
Maintain the vendor inventory and identify critical vendors and subservice organizations.
Collect and track vendor SOC reports, contracts, DPAs, MSAs, security addenda, and supporting documentation.
Maintain vendor review status, identify evidence gaps, and prepare vendor/subservice organization evidence packages for audit.
7. Penetration Testing Coordination
Coordinate scope, timing, access, and evidence requirements with the independent penetration testing provider.
Track findings through remediation and maintain evidence of closure for Critical/High findings.
Prepare penetration testing evidence for auditors and client stakeholders.
8. Audit Support & Management Responses
Coordinate auditor requests and prepare complete evidence packages and responses.
Prepare stakeholders for auditor interviews and draft management responses to requests, findings, exceptions, and clarifications.
Track outstanding auditor items through closure and maintain a final audit support handoff package.
Key Guardrails
AWS and Microsoft 365 production/security-impacting changes require Paralucent approval before implementation.
Vendor legal interpretation, commercial negotiation, contract approval, and final vendor risk acceptance remain with Paralucent leadership or legal counsel.
Formal penetration testing and independent SOC 2 Type II attestation will be performed by separate independent providers.
Job requirements
Must Have
Direct experience leading or executing SOC 2 Type II readiness and remediation.
Hands-on experience with GRC, control implementation, and audit evidence management.
Practical AWS security configuration and remediation experience.
Hands-on Microsoft 365 and Entra ID security configuration experience.
Experience with vendor risk management and third-party security assessments.
Experience preparing and organizing evidence for CPA auditors and SOC 2 audits.
Experience coordinating with independent penetration testing providers.
Strong ability to develop policies, procedures, control narratives, remediation documentation, and audit responses.
Proven ability to manage cross-functional stakeholders, technical SMEs, and external providers.
Ability to work independently, take ownership, and minimize the workload required from internal stakeholders.
Strongly Preferred
Experience supporting financial services or other regulated organizations.
Experience with AWS-hosted SaaS or custom application environments.
Experience working across SOC 2 Security, Availability, and Confidentiality criteria.
Experience reviewing and assessing vendor SOC 2 reports.
Experience working directly with CPA audit/attestation firms.
Familiarity with enterprise supplier/vendor assessment and risk-management processes.
or
All done!
Your application has been successfully submitted!
You've already applied for this job
We appreciate your interest in this position. Unfortunately, you have already applied for this job.