More on Temu
IT and programming
Senior Security Compliance Consultant (SOC 2 & GRC Specialist) - remote job
More on Temu
Toptal
The link takes you to the original advert. Donator takes no applications.
New vacancies on Telegram
Every new remote vacancy, posted as it lands.
@donator_jobs_en
Senior Security Compliance Consultant (SOC 2 & GRC Specialist) - IT and programming, remote
Toptal is hiring a Senior Security Compliance Consultant (SOC 2 & GRC Specialist) - a senior role, so the employer expects you to make the calls yourself. The role sits in IT and programming and is fully remote. The company places no restriction on where the candidate lives, so you can apply from anywhere.
The employer did not publish a figure; that is settled at interview. The advert sets no condition on working hours.
This vacancy passed an automated check: the list excludes any advert requiring a foreign work permit, visa sponsorship, a particular citizenship, or residence in a specific country.
In brief
- Company
- Toptal
- Category
- IT and programming
- Who may apply
- From anywhere in the world
- Work mode
- Fully remote
- Level
- Senior
- Posted
- 9 September 2026 (27 days ago)
- Active
- until 19 October 2026
- Source
- We Work Remotely
Get new IT and programming jobs by email
The board updates several times a day. We write only when a new, checked vacancy appears. No spam, no account needed.
Already subscribed? Manage your settings
About this job
Headquarters:
Summary We are looking for a seasoned, hands-on Senior Security Compliance Consultant (SOC 2 & GRC Specialist) to spearhead a crucial, company-wide initiative for SOC 2 Type II audit readiness. In this key role, you will conduct thorough gap analyses, evaluate current security controls, develop robust compliance processes, and lead cross-functional teams towards audit completion. The perfect candidate will bring a strong background in GRC frameworks, control mapping, evidence automation, and policy creation. Utilizing automated compliance software like Sprinto, you will establish repeatable compliance procedures, verify technical controls, and ensure a smooth audit process across the entire organization. About the Client Our client is a rapidly growing, cloud-based technology company dedicated to maintaining high-level trust, security, and data privacy. To support their swift commercial expansion and robust sales pipeline, they are developing a structured, highly organized security governance framework. They operate in a modern, cloud-centric environment where compliance is viewed as an active, automated operational benefit, not just a passive checklist. By harnessing modern GRC platforms and promoting a security-focused culture, they create a dynamic environment for compliance experts to drive meaningful architectural and procedural enhancements. Tasks and Deliverables SOC 2 Readiness & Gap Analysis: Perform an in-depth evaluation of existing technical and operational security controls, identifying compliance gaps and creating an actionable remediation plan. Control Design & Implementation: Draft, refine, and operationalize security controls, policies, and procedures that align with SOC 2 Trust Services Criteria (TSC) and PCI DSS standards. Automated Evidence Collection: Lead evidence-gathering processes using automated GRC tools (Sprinto), ensuring all technical documentation, access logs, and policy validations are ready for audit. PCI DSS Guidance: Offer expert advice on maintaining PCI DSS compliance while adhering to SOC 2, efficiently mapping overlapping control requirements to minimize operational challenges. Cross-Functional Coordination: Work closely with engineering, DevOps, HR, and IT teams to integrate compliance workflows into daily operations without hindering feature development. Auditor Interface & Readiness: Serve as the main point of contact during the audit preparation phase, collaborating directly with external auditors to present evidence, address findings, and ensure a successful audit cycle. Required Experience SOC 2 Expertise: Demonstrated experience in leading comprehensive SOC 2 readiness, gap remediation, and audit preparation projects for cloud-native or B2B SaaS companies. GRC & PCI DSS Knowledge: In-depth understanding of Governance, Risk, and Compliance (GRC) frameworks, risk assessment techniques, and PCI DSS compliance rules. Tooling Expertise (Sprinto): Practical experience with automated compliance and evidence-collection platforms, particularly Sprinto (or similar modern tools like Vanta/Drata). Policy & Control Mapping: Exceptional ability to create clear, enforceable security policies and convert abstract regulatory demands into specific engineering controls. Cross-Functional Skills: Strong communication and collaboration skills, with a proven track record of driving accountability across distributed engineering, product, and operations teams.
To apply: [Link to Remote Job Listing]
Donator wrote this description from the employer's advert. See the employer's original.
Frequently asked questions about this job
Can I apply for Senior Security Compliance Consultant (SOC 2 & GRC Specialist) from where I live?
Yes. Toptal accepts candidates for this vacancy from anywhere in the world, so you need no work permit for a foreign country. The advert passed an automated check: had the employer required a work permit, visa sponsorship or residence in a specific country, it would not be on this board.
What pay is stated?
Toptal did not publish pay for this vacancy. Most remote adverts publish no figure; it is settled at interview.
How do I apply?
You apply directly to the employer, through the original advert published on We Work Remotely. Donator takes no applications, charges no commission and stores no CV.
What kind of vacancy is this?
A fully remote role in IT and programming. Hybrid adverts and anything requiring office attendance are not published on this board.
Free certificates for this vacancy
The free certificates that carry the most weight in this field. Each one is verified on the provider's own page.
Applied Skills (scenario-based credentials)
exam is free tooMicrosoft · ~1 h
Microsoft's only free verifiable credential: a lab task in 30-45 minutes, with no proctor, no ID check and no card. Retakes are allowed.
It has to be finished in one session; there is no save and resume.
strong brandOCI Foundations Associate
exam is free tooOracle · ~12 h
A rare case where the certification exam itself is free and needs no Pearson VUE: you sit it inside MyLearn. Take the 2026 track, not the 2025 one.
Oracle's pages load via JS; confirm the $0 on the final step of registration.
strong brandValid: 18-24 monthsCS50x: Introduction to Computer Science
certificateHarvard CS50 · ~100 h
Harvard's own branded certificate is free once you pass every problem set and the final project. The edX verified certificate is a separate paid product and is not needed.
strong brandCS50P: Programming with Python
certificateHarvard CS50 · ~60 h
Same mechanism as CS50x: at least 70% on every assignment plus a final project. The certificate does not expire.
strong brand
Similar jobs
Solutions Architect
ModSquad · today
NewFrom anywhereZendeskSenior Node.js Backend Engineer (Infrastructure & High-Load Systems)
EasySoftGroup · yesterday
NewFrom anywhereNode.jsAWSSolution Architect
Digital Forms · yesterday
NewFrom anywherePythonJavaMSD 365 Customer Relationship Management (CRM) Lead
Sparix Global. · yesterday
NewFrom anywhereReactPython
