Qureos

Find The RightJob.

Senior Engineer

Contract to Hire : Cyber Security Consultant for SOC-2 Type-II Implementation for a Banking project :


Role Summary

We are seeking a Senior Technical Lead to drive the technical implementation and operational readiness of our SOC 2 Type II compliance program. The role will partner closely with Security, Engineering, DevOps, IT, Product, Legal, and external auditors to design, implement, automate, and continuously monitor controls across the organization. Similar roles typically involve owning evidence readiness, control mapping, remediation tracking, and auditor support across SOC 2 Trust Services Criteria.linkedin+2

Key Responsibilities

  • Lead end-to-end technical execution of the SOC 2 Type II implementation program.
  • Map existing systems, processes, and controls to SOC 2 Trust Services Criteria.
  • Identify control gaps and drive remediation plans with engineering and operations teams.
  • Design and operationalize technical controls for access management, MFA, logging, monitoring, encryption, vulnerability management, backup, incident response, change management, and secure SDLC.
  • Build scalable evidence collection and continuous compliance workflows.
  • Coordinate auditor walkthroughs, evidence requests, and responses.
  • Maintain control narratives, policies, procedures, and audit artifacts.
  • Track remediation tasks, risks, exceptions, and compliance milestones.
  • Collaborate with stakeholders to ensure controls are sustainable in cloud-native and SaaS environments.
  • Support awareness, training, and readiness activities across teams.
  • Recommend automation opportunities to reduce manual compliance effort.linkedin+3

Required Qualifications

  • 8+ years of experience in technical leadership, security engineering, infrastructure, DevOps, or cloud engineering.
  • Hands-on experience supporting SOC 2 Type II, ISO 27001, or similar assurance/compliance programs.
  • Strong understanding of cloud security, IAM, logging, monitoring, encryption, CI/CD, and vulnerability management.
  • Experience working with auditors, cross-functional teams, and evidence collection workflows.
  • Ability to translate compliance requirements into technical controls and operational processes.
  • Familiarity with SaaS, cloud-native, and modern software delivery environments.
  • Excellent documentation, stakeholder management, and program coordination skills.

Preferred Qualifications

  • Experience with compliance automation tools such as Vanta, Drata, or similar platforms.
  • Knowledge of NIST, CIS, ISO 27001, or other security frameworks.
  • Experience with risk assessments, control testing, and remediation tracking.
  • Background in secure SDLC, DevSecOps, and cloud architecture.
  • Exposure to privacy, vendor risk management, and business continuity controls.linkedin+2

Core Deliverables

  • SOC 2 Type II readiness plan and implementation roadmap.
  • Control matrix mapped to TSC requirements.
  • Evidence repository and recurring collection process.
  • Audit-ready documentation and narratives.
  • Gap remediation tracker and risk register.
  • Reporting dashboard for leadership and auditors.

Nice-to-Have Impact Areas

  • Automating evidence collection from cloud, identity, CI/CD, and ticketing systems.
  • Embedding compliance checks into release pipelines.
  • Standardizing policies and operational procedures.
  • Building a repeatable compliance operating model for future audits and certifications.

© 2026 Qureos. All rights reserved.