SITA logo
SITAPosted 1 month ago
EXPIRED

Senior Cyber Security Analyst (SOC 2 Type 2)

On-siteDelhi, Delhi, India or Delhi, California, United States

Full TimeSenior LevelLarge

Job Summary

Develop and execute a SOC 2 Type 2 compliance programme by creating documentation, control matrices, and audit evidence aligned with Trust Services Criteria. Coordinate with internal stakeholders and external auditors to ensure timely delivery of compliance artefacts while supporting the implementation of technical controls like access management and incident response. Monitor control effectiveness, track audit findings, and facilitate mock audits to maintain readiness for formal evaluations. Manage resource planning and lead training sessions to ensure all personnel understand their duties within the compliance scope.

Required Qualifications

  • Minimum of 5 years' experience in a Quality Assurance, Information Security, or Compliance environment
  • hands-on involvement in regulatory frameworks and standards such as SOC 2, ISO 27001, or PCI DSS
  • Demonstrated experience in implementing and supporting SOC 2 Type 2 compliance programmes
  • experience including evidence collection, control validation, and audit readiness
  • Familiarity with secure system development lifecycle (SSDLC), access control management, incident response, and risk-based control assessments aligned with the Trust Services Criteria
  • Experience working with cross-functional teams (e.g. infrastructure, development, operations, and GRC) to implement security controls, respond to audit findings, and drive continuous improvement
  • Strong understanding of SOC 2 Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy), including scoping, control mapping, and evidence documentation
  • Knowledge of security best practices for access control, system monitoring, data encryption, secure configuration, and incident response
  • Ability to interpret audit requirements and translate them into actionable tasks for technical and non-technical stakeholders
  • Proficiency in preparing and maintaining compliance artefacts such as control matrices, risk assessments, roles and responsibilities documentation, and policy/procedure manuals
  • Familiarity with tools and platforms used for log management, access reviews, vulnerability assessments, and change tracking
  • Excellent communication and documentation skills, with the ability to explain complex compliance topics clearly and effectively across diverse teams
  • University degree or equivalent, preferably in Computer Science, Information Security, Engineering, or a related field

Desired Qualifications

  • Industry certifications such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), SOC 2 Certified Practitioner, or ISO 27001 Lead Implementer
  • ISEB Foundation or equivalent quality assurance qualification
  • Familiarity with audit frameworks and regulatory standards including SOC 2, ISO 27001, and PCI DSS

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles