This one is closed
Live roles like this one
-
C
7h ago
Werkstudent (m/w/d) Schwachstellenmanagement: Von der SBOM zur Entscheidung
Langlauf Security Automation GmbH Lippstadt
-
C
23h ago
Senior Security Engineer, Identity and Access Management
HackerOne Netherlands, UK, USA
- D 20h ago
- C 1d ago
See every "Security Compliance Consultant" role →
Get new “Security Compliance Consultant” roles by email
One email a day with what is new in "Security Compliance Consultant". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Why this grade This listing scored 52/100, which is a D. It lost the most ground on pay transparency. See the breakdown
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Remote clarity 15 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Freshness 12 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
- Corroboration 5 / 10 Whether more than one source carries this listing.
- Role specificity 0 / 10 Whether the listing is tagged well enough to tell what the role actually is.
- Pay transparency 0 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
This listing does not state a salary
$112k – $155k
That is the middle half of what comparable roles paid on this board over the last 90 days — 50 listings that did publish a figure, median $136k. It is not this employer's offer, and we have no idea what they pay. It is only what the rest of the market advertised.
Headquarters:
Summary
We are seeking an elite, hands-on Senior Security Compliance Consultant (SOC 2 & GRC Specialist) to lead a critical, company-wide SOC 2 Type II audit readiness initiative. In this strategic engagement, you will perform comprehensive gap analyses, assess existing security controls, design robust compliance workflows, and drive cross-functional teams toward audit completion.
The ideal candidate brings a proven track record in GRC frameworks, control mapping, evidence automation, and policy development. Utilizing automated compliance platforms such as Sprinto, you will build repeatable compliance processes, validate technical controls, and ensure a seamless audit experience across the entire organization.
General Information (About the Client)
Our client is a fast-scaling, cloud-native technology platform committed to maintaining enterprise-grade trust, security, and data privacy. To support their rapid commercial growth and enterprise sales pipeline, they are establishing a formal, highly disciplined security governance model.
They operate a modern, cloud-first environment where compliance is treated not as a passive checklist, but as an active, automated operational advantage. By leveraging modern GRC platforms and fostering a security-conscious culture, they provide an empowering environment for compliance experts to drive real architectural and procedural improvements.
Tasks and Deliverables
SOC 2 Readiness & Gap Analysis: Conduct a thorough assessment of existing technical and operational security controls, pinpointing compliance gaps and building an actionable remediation roadmap.
Control Design & Implementation: Author, refine, and operationalize security controls, policies, and procedures aligned with SOC 2 Trust Services Criteria (TSC) and PCI DSS standards.
Automated Evidence Collection: Lead evidence-gathering workflows using automated GRC tooling (Sprinto), ensuring all technical artifacts, access logs, and policy attestations are validated and audit-ready.
PCI DSS Guidance: Provide expert advisory on maintaining PCI DSS alignment alongside SOC 2, ensuring overlapping control requirements are mapped efficiently to reduce operational drag.
Cross-Functional Coordination: Collaborate with engineering, DevOps, HR, and IT teams to embed compliance workflows into daily operations without slowing down feature execution.
Auditor Interface & Readiness: Serve as the primary liaison during the audit preparation phase, coordinating directly with external auditors to present evidence, resolve findings, and ensure a successful audit cycle.
Required Experience
SOC 2 Mastery: Proven track record of leading end-to-end SOC 2 readiness, gap remediation, and audit preparation initiatives for cloud-native or B2B SaaS companies.
GRC & PCI DSS Acumen: Deep familiarity with Governance, Risk, and Compliance (GRC) frameworks, risk assessment methodologies, and PCI DSS compliance requirements.
Tooling Proficiency (Sprinto): Direct, practical experience leveraging automated compliance and evidence-collection platforms, specifically Sprinto (or equivalent modern platforms like Vanta/Drata).
Policy & Control Mapping: Exceptional capability to author clear, enforceable security policies and translate abstract regulatory requirements into concrete engineering controls.
Cross-Functional Facilitation: Strong stakeholder management skills with a history of driving accountability across distributed engineering, product, and operations teams.
Apply for this role Opens weworkremotely.com — the link as listed; we have not yet verified it is the employer's own page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 09 Sep 2026 We Work Remotely first sighting
Seen on 1 board over 5 days.