Security Compliance Analyst
$50 - $55 per hourActalent
Job Title: Security Compliance Analyst
Job Description
The Security Compliance Analyst leads the full certification lifecycle for key security frameworks, acting as the primary bridge between technical engineering teams and external auditors. This role focuses on managing ISO and SOC 2 Type 2 audits end-to-end, translating complex technical environments into audit-ready evidence, and using AI and automation to reduce the compliance burden on engineering teams. The ideal candidate is a hands-on compliance practitioner who understands the realities of SaaS products and can clearly articulate technical control requirements to both technical and non-technical stakeholders.
Responsibilities
Own and drive the full lifecycle of ISO and SOC 2 Type 2 audits, from initial planning through final reporting.
Define detailed audit requirements and translate control language into clear, actionable technical requests for engineering teams.
Request, collect, and organize evidence from technical owners, ensuring completeness, accuracy, and audit readiness.
Review and validate the integrity and sufficiency of technical evidence, identifying gaps, inconsistencies, or invalid submissions.
Track remediation activities for identified gaps and follow up with stakeholders to ensure timely closure of issues.
Serve as the primary liaison with external audit firms, speaking the language of auditors and effectively defending the control environment.
Create and maintain an annual audit calendar, including timelines, milestones, and preparation activities for audit windows.
Ensure the organization is well prepared for audits by coordinating pre-audit reviews, walkthroughs, and readiness assessments.
Utilize AI and large language models to automate evidence collection, parse system logs, draft control descriptions, and identify potential compliance gaps before audits.
Apply a human-in-the-loop approach to AI usage by critically reviewing and validating AI-generated outputs for accuracy and completeness.
Review technical configuration reports for infrastructure, networking, containers, and databases to determine whether settings align with secure configuration expectations.
Research and identify appropriate secure configurations and control implementations for technologies not previously encountered.
Clearly explain to engineers what specific evidence or configurations are required, using precise technical language rather than generic control descriptions.
Collaborate with engineering and security teams to define and refine technical controls that align with ISO, SOC 2 Type 2, and other relevant frameworks.
Communicate complex compliance requirements in clear, accessible terms to non-technical stakeholders across the organization.
Push back constructively on auditors when appropriate, providing reasoned explanations and evidence to support the existing control environment.
Contribute to the continuous improvement of compliance processes by identifying opportunities to streamline workflows and reduce manual effort through automation and AI.
Essential Skills
Proven, specific experience managing end-to-end ISO and SOC 2 Type 2 audits, including planning, execution, and final reporting.
Baseline understanding of ISO and SOC 2 Type 2 frameworks and their associated control requirements.
Experience running audits, with a preference for technology-focused auditing experience.
Demonstrated ability to understand and assess technical controls in cloud and SaaS environments.
Technical literacy in cloud platforms, with a particular preference for experience with AWS.
Ability to read and interpret technical configuration reports and determine whether configurations meet secure standards.
Capability to identify when provided technical evidence is insufficient or invalid and to request appropriate corrective evidence.
Demonstrated experience using AI and large language models to streamline compliance and audit tasks, including evidence collection and analysis.
A clear human-in-the-loop philosophy for validating AI output to ensure accuracy and reliability.
Strong communication skills, including the ability to explain complex compliance requirements to non-technical stakeholders.
Ability to understand and articulate detailed technical requests from engineers and translate them into compliance terms.
Confidence and professionalism in pushing back on auditors when necessary, supported by clear evidence and reasoning.
Comfort discussing and auditing SaaS infrastructure running on public cloud environments such as AWS, Azure, or GCP and private cloud environments.
Familiarity with networking concepts and components, including firewalls, switches, routers, VPNs, and secure remote access.
Exposure to Linux-based server environments and various database management systems.
Understanding of containerized environments, including Kubernetes and Docker.
Ability to research and determine appropriate secure settings and configurations for unfamiliar technologies.
Additional Skills & Qualifications
Understanding of the NIST framework, particularly as it applies to security controls and policy design.
Experience working with security controls that align with NIST-based policies.
Creative use of AI to collect, review, and automate evidence handling in a flexible and scalable way.
CISSP certification, which demonstrates a deep understanding of technical security controls (strongly valued but not required).
Experience at a CISO or senior security leadership level is beneficial, though practical hands-on experience is preferred over certifications alone.
Baseline familiarity with NIST and other security frameworks used to structure security controls and policies.
Interest in continuously improving audit and compliance processes through automation and innovative tooling.
Work Environment
The role focuses on a SaaS product operating across both public cloud platforms (such as AWS, Azure, and GCP) and private cloud environments. You will regularly interact with infrastructure components, including firewalls, switches, routers, VPNs, and secure remote access solutions, as well as Linux-based server environments and various database management systems. The environment makes extensive use of container technologies like Kubernetes and Docker. Collaboration with engineering and security teams is central to the role, and you will frequently work with technical configuration reports, system logs, and automated tools. AI and large language models are an integral part of the workflow, particularly for evidence collection, log parsing, and drafting control documentation. The position emphasizes a professional, detail-oriented, and collaborative culture, where clear communication, proactive planning, and continuous improvement of compliance processes are highly valued.
Job Type & Location
This is a Contract position based out of Raleigh, NC.
Pay and Benefits
The pay range for this position is $50.00 - $55.00/hr.
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: • Medical, dental & vision • Critical Illness, Accident, and Hospital • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available • Life Insurance (Voluntary Life & AD&D for the employee and dependents) • Short and long-term disability • Health Spending Account (HSA) • Transportation benefits • Employee Assistance Program • Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a hybrid position in Raleigh,NC.
Application Deadline
This position is anticipated to close on Jul 31, 2026.
About Actalent
Actalent is a global leader in engineering and sciences services and talent solutions. We help visionary companies advance their engineering and science initiatives through access to specialized experts who drive scale, innovation and speed to market. With a network of almost 20,000 consultants and 5,000 clients across the U.S., Canada, Asia and Europe, Actalent serves many of the Fortune 500. We are proud to be an Engineering News-Record (ENR) Top 500 Design Firm for our engineering design services and a ClearlyRated Best of Staffing® winner for both client and talent service.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
If you would like to request a reasonable accommodation, such as the modification or adjustment of the job application process or interviewing process due to a disability, please email View email address on click.appcast.io for other accommodation options.
San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.
Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.
$78.9k - $123.3k
Position Overview We are seeking a detail-oriented cybersecurity compliance professional to support system authorization and continuous... ...Federal environment. This role is responsible for managing the security authorization lifecycle for one or more information systems,...SuggestedPermanent employmentFull timePart timeWork at officeLocal areaRemote work$65k - $75k
...everyone, everywhere. To find out more visit and read about the latest news via our StoryHub. Description and Requirements The Security Compliance Analyst supports the development, automation, and continuous improvement of security governance, compliance, and reporting...SuggestedFull timeContract workInternshipLocal area- ...vulnerabilities and control gaps. Respond directly to standard vendor security questionnaires and support internal teams (i.e. Sales,... ...prospects. Track and collect evidence for ongoing SOC 2 and ISO 27001 compliance audits. Proactively identify emerging threats and associated...SuggestedRemote work
$65 - $66 per hour
...IT Security Analyst Raleigh, North Carolina, United States $ 65.00 - 66.00 (US Dollar) About the Job IT Security Analyst IT Security Analyst needs 3+ years experience IT Security Analyst requires: IT security Cyber security Banking industry Finance...Suggested$76.4k - $138.6k
...systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950... ...business value. The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role...SuggestedSummer holidayLocal areaFlexible hours$40 per hour
...cybersecurity firm is seeking experienced cybersecurity professionals for a remote position. The role involves evaluating AI-generated security content, solving technical problems, and providing valuable feedback to improve AI systems. Candidates should have 2+ years of...Hourly payRemote workFlexible hours- ...The Security Operations Center (SOC) Analyst II serves as a mid‑level cyber defender responsible for continuous monitoring, investigation, and response... ..., status reporting, and after‑action inputs. Support compliance‑driven operations in a highly regulated government...Contract workWork at office
- ...The Security Operations Center (SOC) Analyst I is a frontline cyber defender responsible for monitoring security tools and dashboards to identify indicators of compromise across networks, endpoints, and cloud‑hosted systems in mission‑critical environments. The role focuses...Contract workWork at officeShift work
- ...Raleigh or Montreal office. What You’ll Do Monitor and triage security alerts using tools like Datadog, SIEM platforms, and other... ...Participate in internal and external audits across multiple compliance frameworks (FedRAMP, SOC2, ISO27001, etc.). Contribute to security...Work at officeImmediate startWorldwide
- ...environment that is respectful and inclusive for everyone. As a security analyst at Lucid you will be helping to protect corporate assets,... ..., legal, and business requirements through a risk and compliance mindset. Our mission is to protect and support the objectives...Remote work
- ...vulnerabilities and control gaps. Respond directly to standard vendor security questionnaires and support internal teams (i.e. Sales,... ...and collecting evidence for ongoing SOC 2 and ISO 27001 compliance audits. Proactively identify emerging threats and associated...
$40 per hour
A cybersecurity company is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. This role can be performed remotely and offers flexible hours, with hourly pay starting at $40+. The ideal candidates will...Remote jobHourly payFlexible hours- ...SAP Security Analyst Salary: Confidential Location: Apex, North Carolina Relocation Assistance: Available Job Description No H-1 candidates // no sponsorship candidates The role is in the Raleigh area, but the client will relocate the right candidate...Work at officeWork from homeRelocationRelocation packageFlexible hours
- ...Computer World Services (CWS) is seeking an experienced Security Analyst to support enterprise cybersecurity operations within a Federal... ..., security monitoring, and Federal cybersecurity compliance. This individual will work closely with infrastructure engineers...Work at officeLocal area
- ...Information Security Specialist Hybrid - 3 days a week onsite. Responsibilities Identify and evaluate potential areas of Information Security threat by assessing the probability and impact, and implementing associated mitigations. Monitor and contribute...3 days per week
- A leading consulting firm located in Cary, North Carolina seeks an IT Business Analyst with over a year of experience. Key responsibilities include running monthly security reports, establishing reporting schedules, and contributing to security vendor relationships. The...Work at office
- ...this application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Security Compliance Specialist Full Time Professional Main Office, Raleigh, NC, US Position Summary The Security Compliance Specialist supports...Full timeWork at officeFlexible hours
- ...remote. Our direct client has a new opening for a Lead Security Analyst 141809 This job is 14 months to start, and the... ..., and cross-functional goal achievement Regulatory compliance & policy implementation Incident response & threat mitigation...Local areaRemote work
- ...UMB Bank is seeking a Fiduciary Compliance Analyst in Raleigh, North Carolina. The role supports ongoing administration and execution of Fiduciary Compliance Management Programs, with responsibilities spanning monitoring, risk assessments, and reviews of complaints and...
- ...Lumen is seeking a CMMC Compliance Analyst to manage security integration for DoD and other security requirements. This remote opportunity allows for contributions towards robust security measures across various applications and environments. Responsibility includes...Remote work
$44.8k
...role, you will help safeguard the integrity, reliability, and security of critical technology systems by planning and executing audits... ...develop risk mitigation strategies or suggestions. Ensures compliance with IS audit standards, guidelines, and best practices....Contract work$105.79k - $141.05k
...our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI... ...AI‑ready connectivity, join us today. The Role The CMMC Compliance Analyst must have advanced practical experience in managing all phases...Temporary workFor contractorsRemote work$50 - $60 per hour
...A leading AI development company is seeking an Investment Operations Analyst to work remotely. The role involves evaluating AI chatbots on financial challenges and providing structured feedback for improvement. Ideal candidates should have a Master's or PhD in a finance...Hourly payContract workRemote workFlexible hours$14.55 - $20.4 per hour
...effectively with peers and supervisors to accomplish tasks Able to work a flexible schedule to support business needs 0-2 years retail or security experience Benefits include: Associate discount; EAP; smoking cessation; bereavement; 401(k) Associate contributions; child care...Hourly payFull timeTemporary workLocal areaHome officeFlexible hours- ...branch network. Responsibilities Sales - Promotes investment and securities products through sales outreach and calling efforts to mass... ...inquiries regarding their investments. Risk Management - Ensures compliance throughout activities with all applicable regulations,...
$50 - $60 per hour
...DataAnnotation is committed to creating high‑quality AI. We are looking for an Investment Strategy Analyst to join our team to help train the next generation of AI while enjoying the flexibility of remote work and the freedom to set your own schedule. This role is designed...Hourly payFull timePart timeWork experience placementRemote workFlexible hours$65k - $75k
...estate planning, tax optimization, and supporting disciplines – into congruency. Eton Advisors is looking for an Investment Operations Analyst to assist in compiling, organizing, and interpreting a broad range of investment‑related data and research to support ongoing...Full timeLocal areaMonday to Friday- ...Loss Prevention Security Guard Position Summary The Loss Prevention Security Guard is responsible for helping maintain a safe and secure shopping environment for customers, team members, and company assets. This role focuses on theft deterrence, observation, reporting...Flexible hoursNight shift
- A state office in North Carolina is seeking a Program Coordinator I to serve as a Driver License Examiner, responsible for administering tests and ensuring adherence to DMV policies. The ideal candidate will have strong customer service skills, a valid North Carolina Driver...Hourly payTemporary workWork at office
- ...performing services as a Lube Technician. Job Responsibilities: Perform multi-point Inspection of automotive vehicles to ensure compliance to emission standards and governmental regulations and maintain detailed records of vehicles inspected. Communicate whether...Full timeTemporary workLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Compliance Analyst. Be the first to apply!
- entry level information security analyst Raleigh, NC
- security analyst Raleigh, NC
- security operations analyst Raleigh, NC
- IT security analyst Raleigh, NC
- bond analyst Raleigh, NC
- junior security analyst Raleigh, NC
- cloud security analyst Raleigh, NC
- rate analyst Raleigh, NC
- information security analyst Raleigh, NC
- security analyst intern Raleigh, NC

