Saltar al contenido

Senior SOC 2 Readiness, Remediation & Audit Support Lead (PL865)

  • Hybrid
    • Toronto, Ontario, Canada

Job description

Engagement Type: Contract
Initial Term: Six months, with potential extension through completion of the SOC 2 Type II audit, remediation follow-up, and annual SOC 2 maintenance.

Position Overview

Paralucent is preparing for a SOC 2 Type II report covering an application/AWS-hosted environment and supporting corporate controls. We are seeking a senior, hands-on SOC 2 Readiness & Remediation Consultant to lead the majority of internal preparation, reduce the effort required from Paralucent stakeholders, and drive a six-month path to audit readiness.

The consultant will own day-to-day SOC 2 readiness, remediation planning, evidence collection, control implementation support, AWS and Microsoft 365 remediation coordination, vendor evidence management, observation-period evidence retention, auditor request preparation, and client evidence support.

This role excludes formal penetration testing execution and independent SOC 2 Type II attestation, which will be performed by separate providers.

Key Responsibilities

  1. SOC 2 Readiness & Roadmap

  • Lead the SOC 2 readiness assessment across the application/AWS environment and corporate controls.

  • Review existing policies, technical evidence, security assessments, architecture, vendor documentation, and prior security questionnaires.

  • Identify control, remediation, evidence, and ownership gaps and map controls to applicable SOC 2 criteria.

  • Develop a prioritized remediation roadmap, control matrix, evidence gap register, and executive readiness/status reporting.

  • Coordinate with the independent CPA attestation firm to confirm scope, criteria, evidence expectations, and observation-period timing.

2. Six-Month Execution & Remediation

  • Build and own the integrated six-month SOC 2 plan covering readiness, remediation, evidence, observation-period support, penetration testing coordination, and audit preparation.

  • Manage the remediation backlog, critical path, risks, dependencies, and blockers.

  • Work with internal owners to implement and validate controls, prepare remediation evidence, capture before/after evidence, and track issues through closure.

  • Maintain remediation, control implementation, issue closure, and audit-readiness tracking.

3. AWS Security & Remediation

  • Review AWS configurations relevant to SOC 2 and coordinate or, where approved, perform remediation.

  • Collect evidence covering IAM, MFA, privileged access, access keys, encryption, logging, monitoring, backups, vulnerability management, CloudTrail, GuardDuty, Security Hub, Inspector, S3, KMS, Lambda, DynamoDB, CloudFront, and data segregation.

  • Validate production impact with technical owners and maintain required change-management evidence.

4. Microsoft 365 & Entra ID

  • Review and remediate SOC 2-related Microsoft 365 and Entra ID controls.

  • Collect evidence for MFA, Conditional Access, admin roles, access reviews, security policies, audit logs, SharePoint/OneDrive, email security, endpoint/security baselines, and onboarding/offboarding.

  • Document configuration changes and maintain audit-ready evidence.

5. Evidence & Observation-Period Management

  • Establish and maintain the SOC 2 evidence repository, naming/versioning standards, evidence index, and control-to-evidence matrix.

  • Collect, review, organize, and quality-check technical, policy, HR/training, vendor, governance, operational, and client-specific evidence.

  • Establish recurring evidence collection and retention processes throughout the observation period.

  • Track exceptions, missed controls, compensating actions, remediation, and evidence completeness.

6. Vendor Risk & Evidence

  • Maintain the vendor inventory and identify critical vendors and subservice organizations.

  • Collect and track vendor SOC reports, contracts, DPAs, MSAs, security addenda, and supporting documentation.

  • Maintain vendor review status, identify evidence gaps, and prepare vendor/subservice organization evidence packages for audit.

7. Penetration Testing Coordination

  • Coordinate scope, timing, access, and evidence requirements with the independent penetration testing provider.

  • Track findings through remediation and maintain evidence of closure for Critical/High findings.

  • Prepare penetration testing evidence for auditors and client stakeholders.

8. Audit Support & Management Responses

  • Coordinate auditor requests and prepare complete evidence packages and responses.

  • Prepare stakeholders for auditor interviews and draft management responses to requests, findings, exceptions, and clarifications.

  • Track outstanding auditor items through closure and maintain a final audit support handoff package.

Key Guardrails

  • AWS and Microsoft 365 production/security-impacting changes require Paralucent approval before implementation.

  • Vendor legal interpretation, commercial negotiation, contract approval, and final vendor risk acceptance remain with Paralucent leadership or legal counsel.

  • Formal penetration testing and independent SOC 2 Type II attestation will be performed by separate independent providers.

Job requirements

Must Have

  • Direct experience leading or executing SOC 2 Type II readiness and remediation.

  • Hands-on experience with GRC, control implementation, and audit evidence management.

  • Practical AWS security configuration and remediation experience.

  • Hands-on Microsoft 365 and Entra ID security configuration experience.

  • Experience with vendor risk management and third-party security assessments.

  • Experience preparing and organizing evidence for CPA auditors and SOC 2 audits.

  • Experience coordinating with independent penetration testing providers.

  • Strong ability to develop policies, procedures, control narratives, remediation documentation, and audit responses.

  • Proven ability to manage cross-functional stakeholders, technical SMEs, and external providers.

  • Ability to work independently, take ownership, and minimize the workload required from internal stakeholders.

Strongly Preferred

  • Experience supporting financial services or other regulated organizations.

  • Experience with AWS-hosted SaaS or custom application environments.

  • Experience working across SOC 2 Security, Availability, and Confidentiality criteria.

  • Experience reviewing and assessing vendor SOC 2 reports.

  • Experience working directly with CPA audit/attestation firms.

  • Familiarity with enterprise supplier/vendor assessment and risk-management processes.

or