> Markdown version of [/jobs/ext/204718-junior-soc-2-auditor-cisa-cissp-track](https://www.wearedevelopers.com/jobs/ext/204718-junior-soc-2-auditor-cisa-cissp-track). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Junior SOC 2 Auditor - CISA/CISSP Track - **Company:** ConstellationGRC CPA PC - **Location:** San Marcos, CA, United States - **Experience:** Starter - **Salary:** $41,600.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Spreadsheets, Cyber Security, Identity and Access Management, Issue Tracking Systems, Information Technology Audit, Productivity Software, Screenshots, IT General Controls (ITGC), Gsuite, CIS Benchmarks - **Published:** May 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=efdc99e8d0519f73 ## About the Role Do you have experience in Productivity software?, * One of the following: * Active CISA credential; * Active CISSP credential; or * Passed the CISA or CISSP exam and currently working toward full certification, endorsement, or experience requirements. * Foundational understanding of cybersecurity, IT controls, audit, risk, or compliance. * Strong attention to detail and ability to follow structured audit procedures. * Clear written communication skills. * Comfortable reviewing screenshots, system exports, policies, tickets, logs, and access reports. * Proficiency with spreadsheets, Google Workspace or Microsoft 365, and common business tools. * Ability to work full-time during normal business hours. * Ability to work hybrid from the Seal Beach office as scheduled. * Authorized to work in the United States. Nice to Have * Prior SOC 2, IT audit, GRC, cybersecurity, or compliance experience. * Familiarity with the SOC 2 Trust Services Criteria. * Experience with ISO 27001, NIST, CIS Controls, or similar frameworks. * Experience using audit platforms, ticketing systems, cloud consoles, or identity/access management tools. * Client-facing or professional services experience., * Active CISA; * Active CISSP; * Passed CISA exam and working toward certification; * Passed CISSP exam and working toward endorsement/certification. ## Description ConstellationGRC CPA P.C. helps companies navigate SOC 2 audits and related security compliance requirements with practical, organized, and client-focused audit support., We are growing our SOC 2 audit team and are seeking a Junior SOC 2 Auditor to assist with evidence review, control testing, documentation, and audit support. The Opportunity This is a junior audit role for someone who is building a career in IT audit, cybersecurity compliance, or GRC. The ideal candidate holds an active CISA or CISSP, but we will also consider candidates who have passed the CISA or CISSP exam and are actively working toward full certification or endorsement. You will work closely with senior auditors and managers to review client evidence, test controls, prepare workpapers, and help keep engagements organized. This position is hybrid , Currently Remote But Will Soon Open an Office in or near San Marcos or Escondido California What You'll Do * Assist with SOC 2 audit engagements from evidence collection through testing and documentation. * Review client-submitted audit evidence for completeness, relevance, and accuracy. * Test controls under supervision, including access controls, change management, vendor management, security monitoring, incident response, and policy controls. * Maintain organized audit workpapers, trackers, evidence folders, and testing notes. * Identify missing, incomplete, or unclear evidence and draft follow-up requests. * Document exceptions, observations, and open items for senior auditor review. * Assist with control walkthrough notes and internal audit preparation. * Support audit-related administrative tasks, including scheduling, reminders, status updates, and file organization. * Learn and apply SOC 2 Trust Services Criteria and ConstellationGRC audit methodology. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Launching a marketplace on-time: A lesson in taking shortcuts using spreadsheets!](https://www.wearedevelopers.com/videos/477-launching-a-marketplace-on-time-a-lesson-in-taking-shortcuts-using-spreadsheets) - [Let's get visual - Visual testing in your project](https://www.wearedevelopers.com/videos/303-let-s-get-visual-visual-testing-in-your-project) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From Global Capability Centers to AI-Powered Command Centers](https://www.wearedevelopers.com/videos/100096-from-global-capability-centers-to-ai-powered-command-centers) - [Let's get visual - Visual testing in your project](https://www.wearedevelopers.com/videos/540-let-s-get-visual-visual-testing-in-your-project) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)