Source description
About the role
SOC Audit & Compliance
Support SOC 2 (Type I & Type II) , Future ISO 27001 readiness, and internal security audits as they relate to SOC and IT operations.
Map security and SOC controls to applicable frameworks (AICPA Trust Services Criteria, ITGCs).
Coordinate and manage audit evidence collection from SOC, endpoint, identity, and infrastructure teams.
Perform control design and operating effectiveness reviews for SOC adjacent controls.
Track audit findings, risks, and remediation actions through closure.
Maintain continuous audit readiness rather than point-in-time compliance.
Vulnerability & Remediation Governance
Partner with IT and GRC to support vulnerability management oversight .
Review and validate vulnerability findings from Nessus scans.
Track remediation of SLAs, compensating controls, and risk exceptions.
Perform remediation validation testing post-patching or configuration changes.
Produce vulnerability compliance metrics and audit-ready reports.
Endpoint & Device Security Compliance
Support endpoint security control assurance across corporate devices using Microsoft Intune .
Validate enforcement of:
Device compliance policies
Security baselines
Patch and configuration standards
Support audit evidence related to:
Device enrollment
Configuration compliance
Endpoint protection integration (e.g., Defender ecosystem)
Partner with endpoint teams during audits to explain control design and operation.
Data Governance & Compliance
Support data protection and information governance controls using Microsoft Purview .
Assist in audits related to:
Data classification and labelling
DLP policy enforcement
Retention and records management
Insider risk and audit logging
Validate evidence of operational effectiveness for Purview-based controls.
Maintain compliance documentation related to data security and privacy controls.
Documentation & Stakeholder Coordination
Maintain SOC-related policies, standards, procedures, and control narratives.
Translate technical SOC and security processes into audit-ready documentation .
Collaborate with:
SOC Operations
Endpoint & IAM teams
Internal Audit
Risk & Compliance stakeholders
Prepare audit responses, management action plans, and status reporting.
More at Beghou
Related open roles
Consultant, Data Analytics
United States · Hybrid
Associate - 323
Mumbai · Hybrid
Consultant - Data Management
Chicago · Hybrid
Senior Consultant, Commercial Operations & Analytics
Chicago · Hybrid
Associate Consultant- Advanced Analytics (I0048)
Bangalore · Hybrid
Consultant- Data Aggregation(336)
India · Hybrid
