> Markdown version of [/jobs/ext/569265-soc-2-type-2-five-tsc-saas-cloud-compliance-lead](https://www.wearedevelopers.com/jobs/ext/569265-soc-2-type-2-five-tsc-saas-cloud-compliance-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead - **Company:** FYI-For Your Information, Inc. - **Location:** Silver Spring, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Confluence, JIRA, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Code Review, CompTIA Security+, Cyber Security, Continuous Integration, Disk Controller, Multi-Factor Authentication, Identity and Access Management, Information Technology Audit, PCI Data Security Standards, Systems Development Life Cycle, Software Vulnerability Management, Privacy Controls, Data Logging, Google Cloud, Software Version Control, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e68d22afdbe51f3f ## About the Role Do you have a valid CPA license?, Do you have experience in SOC 2?, * 8+ years of cybersecurity, GRC, IT audit, compliance, SaaS security, cloud security, security consulting, or related experience. * GRC platform experience (Drata preferred, others include Vanta or SecureFrame) * Direct hands-on experience supporting SOC 2 Type 2 audits. * Experience with SaaS or cloud-hosted application environments. * Experience reviewing evidence for control design and operating effectiveness. * Ability to translate audit requirements into operational tasks for engineering, IT, security, HR, legal, operations, and leadership stakeholders. * Strong written communication skills and ability to produce auditor-ready explanations. * Ability to drive control owners and follow-ups without constant prompting. * Ability to work through ambiguity and produce clean, organized, audit-ready documentation. Nice to have * Prior SOC 2 auditor, CPA-firm, or audit-support experience. * Experience with all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. * CISA, CISSP, CISM, Security+, CPA, ISO 27001 Lead Auditor, or equivalent certification. * Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, CI/CD tooling, SAST, DAST, SCA, vulnerability management, or cloud security tools. * PCI DSS familiarity, especially where SOC 2 controls overlap with PCI requirements., This role requires a senior operator who can own the SOC 2 lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required. ## Description FYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an active SOC 2 Type 2 program across Security, Availability, Processing Integrity, Confidentiality, and Privacy. This role will own the SOC 2 domain in a fractional capacity, including evidence review, control operation support, auditor communication support, recurring compliance cadence, and SaaS/cloud control maturity. The right candidate has supported real SOC 2 Type 2 audits and can work with engineering, IT, security, HR, operations, leadership, and auditors., * Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria. * Review evidence requests and determine whether evidence is complete, partial, missing, stale, unclear, or misaligned to the control being tested. * Draft and review auditor responses, management explanations, control narratives, and evidence summaries. * Support control operations for access reviews, vendor risk management, risk assessment, policy review, security awareness, incident response, change management, and security steering activities. * Review evidence for IAM, MFA, logging, monitoring, encryption, vulnerability management, secure SDLC, code review, release approvals, CI/CD security, SAST, DAST, SCA, backups, availability, confidentiality, processing integrity, and privacy controls. * Coordinate with control owners to obtain timestamped, complete, and audit-ready artifacts. * Help maintain the recurring compliance calendar for monthly, quarterly, and annual SOC 2 control activities. * Support policy and documentation management, version control, approvals, and annual review cadence. * Identify control design gaps, operating effectiveness gaps, evidence issues, and audit risks. * Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO., Expected deliverables * SOC 2 Five-TSC evidence and gap tracker inputs. * Control evidence sufficiency reviews. * Auditor response drafts and management-response drafts. * Control narrative and control-description updates. * Recurring compliance calendar inputs for access reviews, vendor reviews, risk assessments, policy reviews, steering meetings, and evidence refresh cycles. * Policy, procedure, and documentation review notes. * SOC 2 blocker, risk, and next-action summaries. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [42 x 2 Canvases Later: Two Years, Two Minds, Many Lessons](https://www.wearedevelopers.com/videos/1458-42-x-2-canvases-later-two-years-two-minds-many-lessons) - [A Founder's Journey : From Startup Chaos to Purposeful Growth](https://www.wearedevelopers.com/videos/1926-a-founder-s-journey-from-startup-chaos-to-purposeful-growth) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026)