Security Compliance Analyst
$50 - $55 per hourActalent
Job Title: Security Compliance Analyst
100% REMOTE!
Job Description
The Security Compliance Analyst leads the full certification lifecycle for key security frameworks, acting as the primary bridge between technical engineering teams and external auditors. This role focuses on managing ISO and SOC 2 Type 2 audits end-to-end, translating complex technical environments into audit-ready evidence, and using AI and automation to reduce the compliance burden on engineering teams. The ideal candidate is a hands-on compliance practitioner who understands the realities of SaaS products and can clearly articulate technical control requirements to both technical and non-technical stakeholders.
Responsibilities
Own and drive the full lifecycle of ISO and SOC 2 Type 2 audits, from initial planning through final reporting.
Define detailed audit requirements and translate control language into clear, actionable technical requests for engineering teams.
Request, collect, and organize evidence from technical owners, ensuring completeness, accuracy, and audit readiness.
Review and validate the integrity and sufficiency of technical evidence, identifying gaps, inconsistencies, or invalid submissions.
Track remediation activities for identified gaps and follow up with stakeholders to ensure timely closure of issues.
Serve as the primary liaison with external audit firms, speaking the language of auditors and effectively defending the control environment.
Create and maintain an annual audit calendar, including timelines, milestones, and preparation activities for audit windows.
Ensure the organization is well prepared for audits by coordinating pre-audit reviews, walkthroughs, and readiness assessments.
Utilize AI and large language models to automate evidence collection, parse system logs, draft control descriptions, and identify potential compliance gaps before audits.
Apply a human-in-the-loop approach to AI usage by critically reviewing and validating AI-generated outputs for accuracy and completeness.
Review technical configuration reports for infrastructure, networking, containers, and databases to determine whether settings align with secure configuration expectations.
Research and identify appropriate secure configurations and control implementations for technologies not previously encountered.
Clearly explain to engineers what specific evidence or configurations are required, using precise technical language rather than generic control descriptions.
Collaborate with engineering and security teams to define and refine technical controls that align with ISO, SOC 2 Type 2, and other relevant frameworks.
Communicate complex compliance requirements in clear, accessible terms to non-technical stakeholders across the organization.
Push back constructively on auditors when appropriate, providing reasoned explanations and evidence to support the existing control environment.
Contribute to the continuous improvement of compliance processes by identifying opportunities to streamline workflows and reduce manual effort through automation and AI.
Essential Skills
Proven, specific experience managing end-to-end ISO and SOC 2 Type 2 audits, including planning, execution, and final reporting.
Baseline understanding of ISO and SOC 2 Type 2 frameworks and their associated control requirements.
Experience running audits, with a preference for technology-focused auditing experience.
Demonstrated ability to understand and assess technical controls in cloud and SaaS environments.
Technical literacy in cloud platforms, with a particular preference for experience with AWS.
Ability to read and interpret technical configuration reports and determine whether configurations meet secure standards.
Capability to identify when provided technical evidence is insufficient or invalid and to request appropriate corrective evidence.
Demonstrated experience using AI and large language models to streamline compliance and audit tasks, including evidence collection and analysis.
A clear human-in-the-loop philosophy for validating AI output to ensure accuracy and reliability.
Strong communication skills, including the ability to explain complex compliance requirements to non-technical stakeholders.
Ability to understand and articulate detailed technical requests from engineers and translate them into compliance terms.
Confidence and professionalism in pushing back on auditors when necessary, supported by clear evidence and reasoning.
Comfort discussing and auditing SaaS infrastructure running on public cloud environments such as AWS, Azure, or GCP and private cloud environments.
Familiarity with networking concepts and components, including firewalls, switches, routers, VPNs, and secure remote access.
Exposure to Linux-based server environments and various database management systems.
Understanding of containerized environments, including Kubernetes and Docker.
Ability to research and determine appropriate secure settings and configurations for unfamiliar technologies.
Additional Skills & Qualifications
Understanding of the NIST framework, particularly as it applies to security controls and policy design.
Experience working with security controls that align with NIST-based policies.
Creative use of AI to collect, review, and automate evidence handling in a flexible and scalable way.
CISSP certification, which demonstrates a deep understanding of technical security controls (strongly valued but not required).
Experience at a CISO or senior security leadership level is beneficial, though practical hands-on experience is preferred over certifications alone.
Baseline familiarity with NIST and other security frameworks used to structure security controls and policies.
Interest in continuously improving audit and compliance processes through automation and innovative tooling.
Work Environment
The role focuses on a SaaS product operating across both public cloud platforms (such as AWS, Azure, and GCP) and private cloud environments. You will regularly interact with infrastructure components, including firewalls, switches, routers, VPNs, and secure remote access solutions, as well as Linux-based server environments and various database management systems. The environment makes extensive use of container technologies like Kubernetes and Docker. Collaboration with engineering and security teams is central to the role, and you will frequently work with technical configuration reports, system logs, and automated tools. AI and large language models are an integral part of the workflow, particularly for evidence collection, log parsing, and drafting control documentation. The position emphasizes a professional, detail-oriented, and collaborative culture, where clear communication, proactive planning, and continuous improvement of compliance processes are highly valued.
Job Type & Location
This is a Contract position based out of Raleigh, NC.
Pay and Benefits
The pay range for this position is $50.00 - $55.00/hr.
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: • Medical, dental & vision • Critical Illness, Accident, and Hospital • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available • Life Insurance (Voluntary Life & AD&D for the employee and dependents) • Short and long-term disability • Health Spending Account (HSA) • Transportation benefits • Employee Assistance Program • Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a hybrid position in Raleigh,NC.
Application Deadline
This position is anticipated to close on Aug 15, 2026.
About Actalent
Actalent is a global leader in engineering and sciences services and talent solutions. We help visionary companies advance their engineering and science initiatives through access to specialized experts who drive scale, innovation and speed to market. With a network of almost 20,000 consultants and 5,000 clients across the U.S., Canada, Asia and Europe, Actalent serves many of the Fortune 500. We are proud to be an Engineering News-Record (ENR) Top 500 Design Firm for our engineering design services and a ClearlyRated Best of Staffing® winner for both client and talent service.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
If you would like to request a reasonable accommodation, such as the modification or adjustment of the job application process or interviewing process due to a disability, please email View email address on click.appcast.io for other accommodation options.
San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.
Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.
- ...environment that is respectful and inclusive for everyone.As a Security Analyst at Lucid Software, you will protect our corporate assets,... ...focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations, third-party risk assessments, and championing...SuggestedRemote work
- ...environment that is respectful and inclusive for everyone.As a security analyst at Lucid you will be helping to protect corporate assets,... ...security, legal, and business requirements through a risk and compliance mindset. Our mission is to protect and support the...SuggestedRemote work
$75k - $95k
...Overview What You’ll Be Doing This Junior Security Analyst role will have client facing responsibilities that encompass security analyst... ...sets. Responsibilities include ensuring security and FISMA compliance of Cadmus’s client’s systems that are currently in the cloud...SuggestedPermanent employmentWork experience placementLocal areaWorldwide- ...Security Contracts Manager We believe that the way people interact with their finances will drastically improve in the next few years... .... About the Team The Security Governance, Risk, and Compliance (GRC) team is part of Plaid's security organization, focused on...SuggestedContract workWork experience placementLocal area
- ...configure, maintain, and troubleshoot Policy-Based Access Control (PBAC) policies in PlainID. Experience in Identity Governance & Compliance processes, including Role-Based and Policy-Based Access Control (RBAC/PBAC). Experience in Postman, Power BIPreferred Skill and...SuggestedFull timeTemporary workRelocation
$95.25k - $165.1k
...supports the Cyber Third Party risk management programs within the Bank at an advanced level of ability. Analyzes the Information Security risk posture of third parties through the review of the Information Security risk due diligence process, track potential threats and...Remote work$76.4k - $138.6k
...systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950... ...business value. The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role...Summer holidayLocal areaFlexible hours- IT Security Analyst needs 3+ years experience IT Security Analyst requires: IT security Cyber security Finance industry IT Security Analyst duties: Supports Information Security and Cyber Threat management programs within the Bank at an advanced level of ability. Analyzes...
- Role Summary: HRIS Security Administrator (Workday) This role serves as the primary authority for security configuration within a Workday... ...system access to protect sensitive data, ensure regulatory compliance, and support efficient HR operations. The role works closely...
$72k - $90k
...clients' most complex challenges. Position Overview: The Security Analyst supports customer engagements by helping to deliver business... ...cross-functional teams (security engineers, architects, compliance, IT, and business stakeholders) to deliver security projects...Full timeRemote workShift work- ...vulnerabilities and control gaps. Respond directly to standard vendor security questionnaires and support internal teams (i.e. Sales,... ...and collecting evidence for ongoing SOC 2 and ISO 27001 compliance audits. Proactively identify emerging threats and associated...
- The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands‑on penetration testing and adversarial simulation. Working under the guidance of the Exposure...Summer holidayFlexible hours
$128.1k - $239.6k
...250,000 people in more than 140 countries, all of whom rely on secure technology to be able to do their job every single day. Everything... ...of security controls. We are seeking an Active Defense Analyst with a strong information security background and a passion for...Summer holidayLocal areaRemote workFlexible hoursNight shiftWeekend work- ...Summary The MAG Team is currently looking for a Information Security Analyst SME to provide a variety of services leveraging the Risk Management... ...and assigned projects. Requirements Knowledge and Skills In compliance with DoD Cyber Workforce 8570.01. Experience in Information...Local area
$102.5k - $210.6k
...long learners focused on technology and innovation. Recruiting for this role ends on 8/31/2026. Work you’ll do As a Lead Cloud Security Analyst, you are an advanced individual contributor pivotal to bridging Deloitte ’s cybersecurity expertise and cloud engineering...Full timeFlexible hoursShift work- ...Computer World Services Corp (CWS) is seeking an experienced Security Analyst/Data Security Specialist to support the planning,... ...incidents, system configurations, and process changes. Ensure compliance with organizational and industry security standards and best...Local area
- A leading consulting firm located in Cary, North Carolina seeks an IT Business Analyst with over a year of experience. Key responsibilities include running monthly security reports, establishing reporting schedules, and contributing to security vendor relationships. The...Work at office
- ...remote. Our direct client has a new opening for a Lead Security Analyst 141809 This job is 14 months to start, and the... ..., and cross-functional goal achievement Regulatory compliance & policy implementation Incident response & threat mitigation...Local areaRemote work
- ...Overview Position Summary The Loss Prevention Security Guard is responsible for helping maintain a safe and secure shopping environment for customers, team members, and company assets. This role focuses on theft deterrence, observation, reporting, and customer safety...Flexible hoursNight shift
- ...network. Responsibilities Sales - Promotes investment and securities products through sales outreach and calling efforts to mass... ...inquiries regarding their investments. Risk Management - Ensures compliance throughout activities with all applicable regulations,...
$65k - $75k
...estate planning, tax optimization, and supporting disciplines – into congruency. Eton Advisors is looking for an Investment Operations Analyst to assist in compiling, organizing, and interpreting a broad range of investment‑related data and research to support ongoing...Full timeLocal areaMonday to Friday- US Inspect US Inspect is the nations leading inspection services firm, delivering residential inspections since 1987. We have openings for experienced NC licensed inspectors to join our team of highly skilled inspectors. Home Inspector Our inspectors are more ...Extra incomeTemporary workWork at office
$90k
...Investment Banking Analyst FMI Corporation is seeking a talented professional to join FMI Capital Advisors, the firm's investment... ...proficiency in Microsoft Excel, PowerPoint, and Word. FINRA Securities Industry Essentials (SIE) Exam preferred but not required....Full timeApprenticeshipInternshipWork at officeRelocation package- ...parental leave Paid education assistance Team member discount Development programs for advancement and career growth Ensures a safe and secure environment for customers, team members, and vendors. Responsible for investigating of internal and external theft, to include ORC...Weekly payWork experience placementInternship
$105.4k - $207.8k
...Our Deloitte Cyber team helps organizations address evolving cybersecurity challenges across identity, access, and platform security. Join our team to deliver solutions that help clients strengthen resilience, modernize identity environments, and manage cyber risk...Local areaVisa sponsorship- ...Commitment to balance project economics with adherence to strategic prioritiesRequired Skill and Experience• Experience in Cyber Security, Network Security or Cloud Security Solutions, preferably in services companies / GSI (Global Systems Integrators).• Experience in...Full timeTemporary workRelocation
- ...PKI Security Administrator Onsite PKI Security Administrator with 5 years PKI experience, knowledgeable in Public Key Infrastructure (PKI), Venafi, and digital certificate management processes and leading practices. Provide customer support for hundreds of US Government...
- A state office in North Carolina is seeking a Program Coordinator I to serve as a Driver License Examiner, responsible for administering tests and ensuring adherence to DMV policies. The ideal candidate will have strong customer service skills, a valid North Carolina Driver...Hourly payTemporary workWork at office
- ...performing services as a Lube Technician. Job Responsibilities: Perform multi-point Inspection of automotive vehicles to ensure compliance to emission standards and governmental regulations and maintain detailed records of vehicles inspected. Communicate whether...Full timeTemporary workLocal areaFlexible hours
- ..., and delivering preventative maintenance services. Job Description Perform multi-point vehicle inspections to ensure compliance with emissions standards and state regulations. Document inspection results and maintain accurate records. Communicate pass...Full timeLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Compliance Analyst. Be the first to apply!
- application security analyst Raleigh, NC
- entry level information security analyst Raleigh, NC
- entry level security analyst Raleigh, NC
- information security analyst Raleigh, NC
- senior security analyst Raleigh, NC
- rate analyst Raleigh, NC
- IT security analyst Raleigh, NC
- work from home security analyst Raleigh, NC
- bond analyst Raleigh, NC
- information security compliance analyst Raleigh, NC


