24 Sep
|
engineersmind
|
Pune
24 Sep
engineersmind
Pune
Job Description
Key Responsibilities
- Support SOC 2 Type 2 audit activities from planning through completion.
- Assist in reviewing and testing controls related to Security, Availability, Confidentiality, Processing Integrity, and Privacy, as applicable.
- Collect, organize, and validate audit evidence from control owners.
- Perform preliminary testing of controls for design and operating effectiveness under the supervision of senior auditors.
- Review evidence for completeness, accuracy, relevance, and appropriate audit periods.
- Identify control gaps, exceptions, and missing evidence and communicate them to relevant stakeholders.
- Maintain audit workpapers, testing documentation, evidence trackers, and issue logs.
- Follow up with control owners to obtain missing or updated evidence.
- Assist in preparing audit findings and documenting observations, exceptions, and remediation activities.
- Support management in tracking remediation plans and closure of identified control deficiencies.
- Participate in walkthroughs and discussions with IT, Security, Engineering, HR, Legal, Finance, and other business teams.
- Assist with maintaining SOC 2 policies, procedures, control descriptions, and supporting documentation.
- Stay current with SOC 2 requirements, security and compliance practices, and relevant industry standards.
Required Qualifications
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity,
Accounting, Risk Management, or a related field.
- 1–2 years of experience in IT Audit, Information Security, GRC, Risk, Compliance, or a related field. Relevant internship or equivalent experience may be considered.
- Good understanding of SOC 2 Trust Services Criteria.
- Familiarity with IT General Controls (ITGC), including:
- Access Management
- Change Management
- Logical Security
- Backup and Recovery
- Incident Management
- Risk Management
- Vendor Management
- Security Awareness
- Basic understanding of audit concepts, including control objectives, control testing, evidence evaluation, exceptions, and remediation.
- Solid documentation and analytical skills.
- Excellent attention to detail and ability to work with large volumes of evidence.
- Good written and verbal communication skills.
- Ability to work collaboratively with multiple teams and stakeholders.
Preferred Qualifications
- Experience supporting a SOC 2 Type 2 audit.
- Familiarity with AICPA Trust Services Criteria.
- Exposure to ISO 27001, HIPAA, HITRUST, PCI DSS, NIST, or other security/compliance frameworks.
- Experience with GRC or audit management platforms.
- Certifications such as Security+, CISA, ISO 27001 Foundation/Lead Auditor, or similar are a plus.
- Familiarity with cloud environments such as AWS, Azure, or GCP is beneficial.
📌 Junior SOC 2 Type 2 Auditor (Pune)
🏢 engineersmind
📍 Pune