27 Sep
|
engineersmind
|
Pune
27 Sep
engineersmind
Pune
nKey Responsibilities
n
n
- Support SOC 2 Type 2 audit activities from planning through completion.
n
- Assist in reviewing and testing controls related to Security, Availability, Confidentiality, Processing Integrity, and Privacy, as applicable.
n
- Collect, organize, and validate audit evidence from control owners.
n
- Perform preliminary testing of controls for design and operating effectiveness under the supervision of senior auditors.
n
- Review evidence for completeness, accuracy, relevance, and appropriate audit periods.
n
- Identify control gaps, exceptions, and missing evidence and communicate them to relevant stakeholders.
n
- Maintain audit workpapers, testing documentation, evidence trackers, and issue logs.
n
- Follow up with control owners to obtain missing or updated evidence.
n
- Assist in preparing audit findings and documenting observations, exceptions, and remediation activities.
n
- Support management in tracking remediation plans and closure of identified control deficiencies.
n
- Participate in walkthroughs and discussions with IT, Security, Engineering, HR, Legal, Finance, and other business teams.
n
- Assist with maintaining SOC 2 policies, procedures, control descriptions, and supporting documentation.
n
- Stay current with SOC 2 requirements, security and compliance practices, and relevant industry standards.
n
n
nRequired Qualifications
n
n
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Accounting,
Risk Management, or a related field.
n
- 1–2 years of experience in IT Audit, Information Security, GRC, Risk, Compliance, or a related field. Relevant internship or equivalent experience may be considered.
n
- Good understanding of SOC 2 Trust Services Criteria.
n
- Familiarity with IT General Controls (ITGC), including:
n
- Access Management
n
- Change Management
n
- Logical Security
n
- Backup and Recovery
n
- Incident Management
n
- Risk Management
n
- Vendor Management
n
- Security Awareness
n
- Basic understanding of audit concepts, including control objectives, control testing, evidence evaluation, exceptions, and remediation.
n
- Strong documentation and analytical skills.
n
- Excellent attention to detail and ability to work with large volumes of evidence.
n
- Positive written and verbal communication skills.
n
- Ability to work collaboratively with multiple teams and stakeholders.
n
n
nPreferred Qualifications
n
n
- Experience supporting a SOC 2 Type 2 audit.
n
- Familiarity with AICPA Trust Services Criteria.
n
- Exposure to ISO 27001, HIPAA, HITRUST, PCI DSS, NIST, or other security/compliance frameworks.
n
- Experience with GRC or audit management platforms.
n
- Certifications such as Security+, CISA, ISO 27001 Foundation/Lead Auditor, or similar are a plus.
n
- Familiarity with cloud environments such as AWS, Azure, or GCP is beneficial.
n
n
📌 Junior SOC 2 Type 2 Auditor (Pune)
🏢 engineersmind
📍 Pune