08 Aug
|
Paralucent
|
Canada
Engagement Type: Contract
Initial Term: Six months, with potential extension through completion of the SOC 2 Type II audit, remediation follow-up, and annual SOC 2 maintenance.
Position Overview
Paralucent is preparing for a SOC 2 Type II report covering an application/AWS-hosted workplace and supporting corporate controls. We are seeking a senior, hands-on SOC 2 Readiness & Remediation Consultant to lead the majority of internal preparation, reduce the effort required from Paralucent stakeholders, and drive a six-month path to audit readiness.
The consultant will own day-to-day SOC 2 readiness, remediation planning, evidence collection, control implementation support, AWS and Microsoft 365 remediation coordination, vendor evidence management, observation-period evidence retention, auditor request preparation, and client evidence support.
This role excludes formal penetration testing execution and independent SOC 2 Type II attestation, which will be performed by separate providers.
Key Responsibilities
- SOC 2 Readiness & Roadmap
- Lead the SOC 2 readiness assessment across the application/AWS environment and corporate controls.
- Review existing policies, technical evidence, security assessments, architecture, vendor documentation, and prior security questionnaires.
- Identify control, remediation, evidence, and ownership gaps and map controls to applicable SOC 2 criteria.
- Develop a prioritized remediation roadmap, control matrix, evidence gap register, and executive readiness/status reporting.
- Coordinate with the independent CPA attestation firm to confirm scope, criteria, evidence expectations, and observation-period timing.
2. Six-Month Execution & Remediation
- Build and own the integrated six-month SOC 2 plan covering readiness, remediation, evidence, observation-period support, penetration testing coordination, and audit preparation.
- Manage the remediation backlog, critical path, risks, dependencies, and blockers.
- Work with internal owners to implement and validate controls, prepare remediation evidence, capture before/after evidence, and track issues through closure.
- Maintain remediation, control implementation, issue closure, and audit-readiness tracking.
3. AWS Security & Remediation
- Review AWS configurations relevant to SOC 2 and coordinate or, where approved, perform remediation.
- Collect evidence covering IAM, MFA, privileged access, access keys, encryption, logging, monitoring, backups, vulnerability management, CloudTrail, GuardDuty, Security Hub, Inspector, S3, KMS, Lambda, DynamoDB, CloudFront, and data segregation.
- Validate production impact with technical owners and maintain required change-management evidence.
4. Microsoft 365 & Entra ID
- Review and remediate SOC 2-related Microsoft 365 and Entra ID controls.
- Collect evidence for MFA, Conditional Access, admin roles, access reviews, security policies, audit logs, SharePoint/OneDrive, email security, endpoint/security baselines, and onboarding/offboarding.
- Document configuration changes and maintain audit-ready evidence.
5. Evidence & Observation-Period Management
- Establish and maintain the SOC 2 evidence repository, naming/versioning standards, evidence index, and control-to-evidence matrix.
- Collect, review, organize, and quality-check technical, policy, HR/training, vendor, governance, operational, and client-specific evidence.
- Establish recurring evidence collection and retention processes throughout the observation period.
- Track exceptions, missed controls, compensating actions, remediation, and evidence completeness.
6. Vendor Risk & Evidence
- Maintain the vendor inventory and identify critical vendors and subservice organizations.
- Collect and track vendor SOC reports, contracts, DPAs, MSAs, security addenda, and supporting documentation.
- Maintain vendor review status, identify evidence gaps, and prepare vendor/subservice organization evidence packages for audit.
7. Penetration Testing Coordination
- Coordinate scope, timing, access, and evidence requirements with the independent penetration testing provider.
- Track findings through remediation and maintain evidence of closure for Critical/High findings.
- Prepare penetration testing evidence for auditors and client stakeholders.
8. Audit Support & Management Responses
- Coordinate auditor requests and prepare complete evidence packages and responses.
- Prepare stakeholders for auditor interviews and draft management responses to requests, findings, exceptions, and clarifications.
- Track outstanding auditor items through closure and maintain a final audit support handoff package.
Key Guardrails
- AWS and Microsoft 365 production/security-impacting changes require Paralucent approval before implementation.
- Vendor legal interpretation, commercial negotiation, contract approval, and final vendor risk acceptance remain with Paralucent leadership or legal counsel.
- Formal penetration testing and independent SOC 2 Type II attestation will be performed by separate independent providers.
Must Have
- Direct experience leading or executing SOC 2 Type II readiness and remediation.
- Hands-on experience with GRC, control implementation, and audit evidence management.
- Practical AWS security configuration and remediation experience.
- Hands-on Microsoft 365 and Entra ID security configuration experience.
- Experience with vendor risk management and third-party security assessments.
- Experience preparing and organizing evidence for CPA auditors and SOC 2 audits.
- Experience coordinating with independent penetration testing providers.
- Strong ability to develop policies, procedures, control narratives, remediation documentation, and audit responses.
- Proven ability to manage cross-functional stakeholders, technical SMEs, and external providers.
- Ability to work independently, take ownership, and minimize the workload required from internal stakeholders.
Strongly Preferred
- Experience supporting financial services or other regulated organizations.
- Experience with AWS-hosted SaaS or custom application environments.
- Experience working across SOC 2 Security, Availability, and Confidentiality criteria.
- Experience reviewing and assessing vendor SOC 2 reports.
- Experience working directly with CPA audit/attestation firms.
- Familiarity with enterprise supplier/vendor assessment and risk-management processes.
📌 Senior SOC 2 Readiness, Remediation & Audit Support Lead (Canada)
🏢 Paralucent
📍 Canada