SOC 1 and SOC 2 Security Auditor
Duties:
It is the responsibility of the Security Auditor to interact directly with the client point of contact during any engagement or assessment. The Security Auditor must be able to successfully perform all functions of the audit lifecycle up to and including project management, reporting and engagement closing.
Responsibility:
The Security Auditor is responsible for the following aspects of the audit lifecycle:
- Engagement Inception: Kick off the engagement with all relevant parties on client side. Set timelines and expectations for major audit milestones.
- Planning and Scoping: Determine the audit scope and risk identification.
- Evidence analysis: Ensure the integrity of the evidence or population sample and determine applicability to the corresponding test procedure(s).
- Walkthrough Procedures: must be able to communicate effectively with client subject matter experts at a high level to ensure interviews and systems reviewed are appropriate.
- Reporting: Author the report and ensure it is in a “QA” ready state.
- Close out: Participate in any edit requests of client draft report for final delivery.
Authority:
The Security Auditor will report directly to the Partner.
Minimum Qualifications:
Level of education must be a minimum of Bachelor’s degree from a recognized four year educational institution (practical experience may be substituted). The following disciplines are preferred:
- MIS (Management Information Systems)
- Finance
- CIS (Computer Information Systems)
- Accounting
In lieu of formal education, candidate should have a minimum of two years’ field audit experience to qualify.
Demeanor:
Candidate must be:
- professional,
- dependable,
- success / career minded, and,
- able to work remotely during core business hours.