Junior SOC 2 Auditor - CISA/CISSP Track

ConstellationGRC CPA PC
Seal Beach, CA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Compensation
$41,600.0
Working hours
Shift work
Job source

Tech stack

Microsoft Windows Spreadsheets Cyber Security Identity and Access Management Issue Tracking Systems Information Technology Audit Screenshots IT General Controls (ITGC) Gsuite CIS Benchmarks

Job description

ConstellationGRC CPA P.C. helps companies navigate SOC 2 audits and related security compliance requirements with practical, organized, and client-focused audit support., We are growing our SOC 2 audit team and are seeking a Junior SOC 2 Auditor to assist with evidence review, control testing, documentation, and audit support.

The Opportunity

This is a junior audit role for someone who is building a career in IT audit, cybersecurity compliance, or GRC. The ideal candidate holds an active CISA or CISSP, but we will also consider candidates who have passed the CISA or CISSP exam and are actively working toward full certification or endorsement.

You will work closely with senior auditors and managers to review client evidence, test controls, prepare workpapers, and help keep engagements organized.

This position is hybrid and is currently based out of our office at:

3020 Old Ranch Pkwy, Ste 300 Seal Beach, CA 90740

Candidates must be able to reliably work on-site in Seal Beach as scheduled.

What You’ll Do

  • Assist with SOC 2 audit engagements from evidence collection through testing and documentation.
  • Review client-submitted audit evidence for completeness, relevance, and accuracy.
  • Test controls under supervision, including access controls, change management, vendor management, security monitoring, incident response, and policy controls.
  • Maintain organized audit workpapers, trackers, evidence folders, and testing notes.
  • Identify missing, incomplete, or unclear evidence and draft follow-up requests.
  • Document exceptions, observations, and open items for senior auditor review.
  • Assist with control walkthrough notes and internal audit preparation.
  • Support audit-related administrative tasks, including scheduling, reminders, status updates, and file organization.
  • Learn and apply SOC 2 Trust Services Criteria and ConstellationGRC audit methodology.

Requirements

Do you have experience in Schedule management?, Do you have a Bachelor’s degree?, * One of the following:

  • Active CISA credential;
  • Active CISSP credential; or
  • Passed the CISA or CISSP exam and currently working toward full certification, endorsement, or experience requirements.
  • Foundational understanding of cybersecurity, IT controls, audit, risk, or compliance.
  • Strong attention to detail and ability to follow structured audit procedures.
  • Clear written communication skills.
  • Comfortable reviewing screenshots, system exports, policies, tickets, logs, and access reports.
  • Proficiency with spreadsheets, Google Workspace or Microsoft 365, and common business tools.
  • Ability to work full-time during normal business hours.
  • Ability to work hybrid from the Seal Beach office as scheduled.
  • Authorized to work in the United States.

Nice to Have

  • Prior SOC 2, IT audit, GRC, cybersecurity, or compliance experience.
  • Familiarity with the SOC 2 Trust Services Criteria.
  • Experience with ISO 27001, NIST, CIS Controls, or similar frameworks.
  • Experience using audit platforms, ticketing systems, cloud consoles, or identity/access management tools.
  • Client-facing or professional services experience., * Active CISA;
  • Active CISSP;
  • Passed CISA exam and working toward certification;
  • Passed CISSP exam and working toward endorsement/certification.

Benefits & conditions

Pulled from the full job description

  • Flexible schedule

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:32 min

Recognizing the persistence and utility of spreadsheet applications

John Bettiol · WWC 2022

2:23 min

Automating frontend quality with screenshot comparison and visual review

Ramona Schwering Ramona Schwering · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

6:10 min

Transitioning agile recruiting teams away from manual spreadsheet management

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

53 sec

Exploring the security risks of mobile screenshot folders

Chris Heilmann +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all