
SOC Analyst
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants anywhere in the world.
• Ensure continuous readiness for SOC 2, ISO 27001, and Cyber Essentials throughout the year.
• Take ownership of routine compliance administration, evidence gathering, control monitoring, and follow-up actions.
• Convert compliance requirements into actionable steps for Engineering, DevOps, and IT teams.
• Proactively identify gaps, track remediation efforts to completion, and maintain thorough documentation demonstrating that controls are effectively designed and functioning.
• Coordinate compliance initiatives across SOC 2, ISO 27001, and Cyber Essentials.
• Collaborate closely with Engineering, DevOps, IT, and management to ensure that controls operate efficiently and remain audit-ready year-round.
• Navigate between policy development, evidence collection, endpoint/software compliance, risk management, access reviews, and audit coordination.
• Act as the primary owner of routine compliance operations and follow-up, with the Senior Engineering Manager serving as the management and escalation point.
• 2–4 years of relevant experience in GRC, information security compliance, security assurance, IT audit, or a closely related field.
• Hands-on experience with at least one major security/compliance framework such as SOC 2 or ISO 27001.
• Proficient in collecting, reviewing, and organizing audit evidence while collaborating with technical control owners.
• Strong skills in documentation and policy writing, with a focus on consistency and audit readiness.
• Working knowledge of cloud environments, identity and access management, endpoint security, vulnerability management, logging, backups, and change management.
• Ability to interpret technical evidence and formulate relevant questions without requiring software engineering or DevOps expertise.
• Excellent ownership, follow-up, and organizational abilities; adept at managing multiple recurring compliance activities simultaneously.
• Strong written and verbal communication skills, capable of engaging with both technical and non-technical stakeholders.
• Familiarity with Cyber Essentials is highly preferred.
• Experience with compliance automation or GRC platforms like Vanta, Drata, Sprinto, or similar tools.
• Background in a SaaS, software development, or cloud-first organization.
• Familiarity with MDM/endpoint management tools and software inventory assessments.
• Exposure to AWS, Azure, or other public cloud security measures.
• Experience assisting with customer security questionnaires or vendor risk assessments.
• Relevant certifications such as ISO 27001 Internal Auditor/Lead Implementer, Security+, CISA, CRISC, or similar are advantageous but not essential.
• Allowance for Internet/Phone expenses.
• Company hardware provided after successful completion of probation.
• Ongoing development and education allowances.
• Flexible remote work from anywhere (provided there is good internet and communication).
• Excellent growth opportunities, with potential advancement into leadership for suitable candidates.
• Generous leave policies, social benefits, and training allowances.
• End-of-year bonuses based on company and individual performance.
• Zero commute: Work while you work, play while you play. Achieve a perfect work/life balance.
• Remote job options and additional benefits to be discussed during the interview process.
• A flexible, family-friendly, and enjoyable work environment.
Thrive
Capgemini
Get handpicked remote jobs straight to your inbox weekly.