Paralucent

Senior SOC 2 Readiness, Remediation & Audit Support Lead (PL865)

Paralucent  •  Toronto, CA (Onsite)  •  4 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Engagement Type: Contract
Initial Term: Six months, with potential extension through completion of the SOC 2 Type II audit, remediation follow-up, and annual SOC 2 maintenance.

Paralucent is preparing for a SOC 2 Type II report covering an application/AWS-hosted environment and supporting corporate controls. We are seeking a senior, hands-on SOC 2 Readiness & Remediation Consultant to lead the majority of internal preparation, reduce the effort required from Paralucent stakeholders, and drive a six-month path to audit readiness.

The consultant will own day-to-day SOC 2 readiness, remediation planning, evidence collection, control implementation support, AWS and Microsoft 365 remediation coordination, vendor evidence management, observation-period evidence retention, auditor request preparation, and client evidence support.

This role excludes formal penetration testing execution and independent SOC 2 Type II attestation, which will be performed by separate providers.

Key Responsibilities

  1. SOC 2 Readiness & Roadmap

  • Lead the SOC 2 readiness assessment across the application/AWS environment and corporate controls.

  • Review existing policies, technical evidence, security assessments, architecture, vendor documentation, and prior security questionnaires.

  • Identify control, remediation, evidence, and ownership gaps and map controls to applicable SOC 2 criteria.

  • Develop a prioritized remediation roadmap, control matrix, evidence gap register, and executive readiness/status reporting.

  • Coordinate with the independent CPA attestation firm to confirm scope, criteria, evidence expectations, and observation-period timing.

2. Six-Month Execution & Remediation

  • Build and own the integrated six-month SOC 2 plan covering readiness, remediation, evidence, observation-period support, penetration testing coordination, and audit preparation.

  • Manage the remediation backlog, critical path, risks, dependencies, and blockers.

  • Work with internal owners to implement and validate controls, prepare remediation evidence, capture before/after evidence, and track issues through closure.

  • Maintain remediation, control implementation, issue closure, and audit-readiness tracking.

3. AWS Security & Remediation

  • Review AWS configurations relevant to SOC 2 and coordinate or, where approved, perform remediation.

  • Collect evidence covering IAM, MFA, privileged access, access keys, encryption, logging, monitoring, backups, vulnerability management, CloudTrail, GuardDuty, Security Hub, Inspector, S3, KMS, Lambda, DynamoDB, CloudFront, and data segregation.

  • Validate production impact with technical owners and maintain required change-management evidence.

4. Microsoft 365 & Entra ID

  • Review and remediate SOC 2-related Microsoft 365 and Entra ID controls.

  • Collect evidence for MFA, Conditional Access, admin roles, access reviews, security policies, audit logs, SharePoint/OneDrive, email security, endpoint/security baselines, and onboarding/offboarding.

  • Document configuration changes and maintain audit-ready evidence.

5. Evidence & Observation-Period Management

  • Establish and maintain the SOC 2 evidence repository, naming/versioning standards, evidence index, and control-to-evidence matrix.

  • Collect, review, organize, and quality-check technical, policy, HR/training, vendor, governance, operational, and client-specific evidence.

  • Establish recurring evidence collection and retention processes throughout the observation period.

  • Track exceptions, missed controls, compensating actions, remediation, and evidence completeness.

6. Vendor Risk & Evidence

  • Maintain the vendor inventory and identify critical vendors and subservice organizations.

  • Collect and track vendor SOC reports, contracts, DPAs, MSAs, security addenda, and supporting documentation.

  • Maintain vendor review status, identify evidence gaps, and prepare vendor/subservice organization evidence packages for audit.

7. Penetration Testing Coordination

  • Coordinate scope, timing, access, and evidence requirements with the independent penetration testing provider.

  • Track findings through remediation and maintain evidence of closure for Critical/High findings.

  • Prepare penetration testing evidence for auditors and client stakeholders.

8. Audit Support & Management Responses

  • Coordinate auditor requests and prepare complete evidence packages and responses.

  • Prepare stakeholders for auditor interviews and draft management responses to requests, findings, exceptions, and clarifications.

  • Track outstanding auditor items through closure and maintain a final audit support handoff package.

Key Guardrails

  • AWS and Microsoft 365 production/security-impacting changes require Paralucent approval before implementation.

  • Vendor legal interpretation, commercial negotiation, contract approval, and final vendor risk acceptance remain with Paralucent leadership or legal counsel.

  • Formal penetration testing and independent SOC 2 Type II attestation will be performed by separate independent providers.

Requirements

Must Have

  • Direct experience leading or executing SOC 2 Type II readiness and remediation

  • Hands-on experience with GRC, control implementation, and audit evidence management

  • Practical AWS security configuration and remediation experience.

  • Hands-on Microsoft 365 and Entra ID security configuration experience.

  • Experience with vendor risk management and third-party security assessments

  • Experience preparing and organizing evidence for CPA auditors and SOC 2 audits

  • Experience coordinating with independent penetration testing providers

  • Strong ability to develop policies, procedures, control narratives, remediation documentation, and audit responses

  • Proven ability to manage cross-functional stakeholders, technical SMEs, and external providers

  • Ability to work independently, take ownership, and minimize the workload required from internal stakeholders

Strongly Preferred

  • Experience supporting financial services or other regulated organizations

  • Experience with AWS-hosted SaaS or custom application environments

  • Experience working across SOC 2 Security, Availability, and Confidentiality criteria.

  • Experience reviewing and assessing vendor SOC 2 reports

  • Experience working directly with CPA audit/attestation firms

  • Familiarity with enterprise supplier/vendor assessment and risk-management processes

Paralucent

About Paralucent

PARALUCENT is a global technology firm that lives at the intersection of technology and creativity, helping organizations grow in an age of digital transformation. Our customer-centric processes are aimed at delivering smarter work that changes behaviours and unlocks growth.

WE ARE

Strategists, architects, designers, project managers, developers, and QA with rich technology experience and mastery of leading methodologies.

WE CREATE

Highly effective solutions that live up to our promises and exceed expectations. We deliver technological solutions with great attention to quality, cost and functionality.

WE BELIEVE

Great things in the world come through committed partnerships that are built on trust and integrity and that have clear two-way communication. We believe in an inclusive environment that challenges traditional ways of working. We believe in curiosity, passion and collaboration so that everyone wins.

Industry
IT & Software
Company Size
11-50 employees
Headquarters
Toronto, ca
Year Founded
2003
Social Media