SOC 2 Cyber Program Lead
$113k - $190kFirst Citizens Bank
Overview
Remote eligible. This position provides cybersecurity risk management and expert support at the highest level of cybersecurity governance and oversight, with primary responsibility for leading and managing the company’s Systems and Organization Controls (SOC) 2 program. The role coordinates across business and technology stakeholders to ensure SOC 2 requirements are understood, implemented, and sustained. Serves as a SOC 2 leader, contributes to broader cyber risk oversight, recommending and monitoring enhancements to processes and procedures, performing analysis, and reporting in support of strategic objectives.
Responsibilities
- SOC 2 Program Leadership - Leads and manages the bank’s SOC 2 readiness and compliance program. Coordinates program activities across business and technology teams, ensuring controls are properly implemented, documented, and maintained in alignment with SOC 2 Trust Services Criteria (TSC). Oversees evidence collection, audit preparedness, and continuous improvement of the SOC 2 program. Serves as the primary liaison with auditors during readiness and examination activities.
- SOC 2 Readiness - Executes assessments and readiness activities to evaluate compliance with SOC 2 requirements. Performs gap analyses, documents control coverage, and monitors remediation efforts. Collects and validates evidence, ensures accuracy and completeness, and prepares the organization for external audits by driving readiness efforts.
- Stakeholder Partnership - Partners with control owners, governance teams, and other stakeholders to align on responsibilities, close identified gaps, and monitor remediation progress. Provides guidance and education on SOC 2 requirements, roles, and expectations, ensuring stakeholders understand their role in sustaining compliance.
- Risk Identification and Monitoring - Identifies and monitors risks related to SOC 2 control requirements and broader cybersecurity domains. Escalates potential areas of concern, facilitates root cause analysis, and tracks corrective actions to resolution. Maintains awareness of changes in SOC 2 requirements, industry trends, and regulatory expectations, translating them into actionable insights for the bank.
- Reporting - Produces reports and dashboards on SOC 2 readiness, testing results, control maturity, and remediation progress. Conveys root cause analysis, patterns, and trends to leadership. Provides transparency into risk exposure, compliance status, and effectiveness of mitigation measures, with emphasis on SOC 2 Trust Services Criteria coverage.
Qualifications
Bachelor's Degree and 6 years of experience in Financial Services, Risk Management, Operational Risk Management, Compliance, Audit, Finance or Accounting OR High School Diploma or GED and 10 years of experience in Financial Services, Risk Management, Operational Risk Management, Compliance, Audit, Finance or Accounting
- Direct experience executing or leading SOC 2 audits and programs, including readiness assessments, gap analysis, evidence collection, and audit preparedness
- Strong knowledge of SOC 2 Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) and demonstrated ability to apply them in a large, complex organization
- Experience partnering with stakeholders across business and technology to monitor risks, close compliance gaps, and sustain ongoing SOC 2 readiness
- In-depth practical knowledge of internal controls, risk assessments, and operational and cybersecurity processes, with experience implementing regulatory and compliance frameworks
- Broad knowledge and understanding of cybersecurity risks and controls, including IT infrastructure, cloud computing, mobile technologies, and cybersecurity technologies
- Excellent written and oral communication skills, with ability to influence stakeholders and communicate effectively at multiple levels
- CISSP, CISA, CISM, CRISC, CIA, or equivalent certification
Preferred Qualifications
- 7-10 years of experience in risk management or compliance, including leadership of SOC 2, ISO, PCI, or similar frameworks
- 3+ years of experience at a Large Financial Institution or similarly regulated environment
- Familiarity with NIST frameworks (e.g., CSF, SP 800-53) and their application in strengthening cybersecurity programs
- Extensive knowledge and subject matter expertise in managing cybersecurity compliance in financial services, including applicable regulations (SOC 2, NIST, CSA, FFIEC, OCC, FRB, state law, and other regulatory guidance)
- Strong project management and continuous improvement skills
This job posting is expected to remain active for 45 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.
The base pay for this position is generally between $113,000 and $190,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.
Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at jobs.firstcitizens.com/benefits.
Job metadata
- Seniority level: Not Applicable
- Employment type: Full-time
- Job function: Consulting, Information Technology, and Sales
- Industries: Banking and Financial Services
Referrals increase your chances of interviewing at First Citizens Bank by 2x
Get notified about new Program Lead jobs in Raleigh, NC.
#J-18808-Ljbffr$134.5k - $265.1k
Position Summary As a Manager - Cyber Defense and Resilience, you will play a hands... ...team, you will be responsible for: Leading the design and implementation of secure,... ...orchestration workflows using application programming interfaces, connectors, and data...SuggestedLocal areaVisa sponsorship$155.6k - $306.8k
...Deployed Engineer) in Deloitte Cyber, you will be embedded in... ...third-party resilience programs• Translating client... ...to target architecture• Leading the hands-on design,... ...serverless components• 2+ years of experience delivering... ...(NIST CSF, ISO 22301, SOC 2) sufficient to model...SuggestedLocal areaRemote work- ...community-focused credit union in North Carolina is seeking a Cyber Security Analyst II to enhance its cybersecurity posture.... ...will have a HS Diploma, relevant certifications, and 2-4 years of experience in a SOC/SIEM role. This position offers a hybrid work environment...Suggested
$134.5k - $265.1k
Position Summary Deloitte’s Cyber team helps clients address... ...projects by applying advanced SOC engineering experience and... ..., you will be responsible for:Leading the design and implementation... ...Cloud Feeds, and application programming interfaces (APIs)Collaborating...SuggestedLocal areaVisa sponsorship$134.5k - $265.1k
Position Summary Deloitte’s Cyber Services help our clients to be secure, vigilant... ...improving their Cyber Incident Response program to be able to support client’s Readiness,... ...offerings. Responsibilities Experience in leading the full lifecycle of Cyber incident...SuggestedLocal areaVisa sponsorship$82.6k - $162.8k
Position Summary As a Consultant - Cyber Defense and Resilience, you will support... ...and routing workflows using application programming interfaces, connectors, and data pipelinesAssisting... ...professional relationshipsAbility to lead projects or workstreamsAbility to manage...Local areaVisa sponsorship$119.46k - $155.3k
...assigned Job Role of Technology Project Lead 2, your Area Of Responsibility will be as... ...innovationRequired Skill and ExperienceA Senior Program /Project Manager is responsible for... ...Foundational|Cybersecurity Competency Management|Cyber Competency Strategy Planning Technical/...Full timeTemporary workInterim roleRelocation- ...k match, a flexible PTO program, and a generous and inclusive... ...Director of (Cyber) Security Operations is... ...accountable for building and leading a high-performing operations... ...operations center (SOC) capabilities, whether internal... ...7001, CIS Controls, SOC 2, PCI DSS, HIPAA, or...Live inWork at officeWork from homeFlexible hours
$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities... ...professional relationshipsAbility to lead projects or workstreamsAbility to manage... ...offering develops and transforms cyber programs in line with a client's strategic...Local area- ...Role of Infrastructure Project Lead 1, your Area Of Responsibility... ...in the role of managing cyber security operations covering multiple... ...Security Operation Centre (SOC), Identity & Access Management... ...customers as needed.• Experience in program & project management. Ability...Full timeTemporary workRelocation
$120k - $165k
...proficiency in one or more scripting or programming languages such as Python, Java, JavaScript... ...regulatory frameworks such as NIST, ISO 27001, or SOC 2. We prefer experience applying threat... ...More: We are a bank offering a remote Cyber Security Analyst role supporting teams in...Remote work$70.3k
...Job Description: At Regions, the Cyber Security Analyst is responsible... ...with risk management programs, rules and regulations, and cybersecurity... ...Technology Minimum of two (2) relevant certifications in Information... ...a Security Operations Center (SOC) environment Experience...Full timeWork at officeRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift work3 days per week$134.5k - $265.1k
...professional looking to help organizations reduce cyber risk and improve resilience? At Deloitte & Touche LLP, you’ll work with leading organizations to strengthen security,... ...clients to design, implement, and operate programs that help protect critical assets, support...Local area$118.7k - $218.6k
Position Summary Cyber Data Protection and PKI Specialist... ...reduce data risks, developing and leading the implementation of... ...develops and transforms cyber programs in line with a client's strategic... ...BYOK), server-side encryption.2+ years of professional experience...Work experience placementLocal areaVisa sponsorship$134.5k - $265.1k
Position Summary Tech Resilience Manager Lead complex resilience initiatives as a... ..., continuity plans, playbooks, and program documentation for critical business and technology... ..., Computer Science, Information Systems, Cyber Security, or equivalent demonstrated...Local areaVisa sponsorship$155.6k - $306.8k
Position Summary Help clients reduce cyber risk by leading forward deployed engineering work focused on patching, remediation, and continuous... ...team works with clients to design, implement, and operate programs that help protect critical assets, support digital...Local area- ...information security projects, programs, and processes aligned with organizational... ...for area of responsibility.2. Manages large information... ..., and reconstruction.5. Leads incident response efforts to effectively... ...access, data breaches, and cyber threats.8. Integrates advanced...Full timePart timeShift workDay shift
$97.61k - $188.38k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities... ..., or architecting information systems.2+ years of experience with technical... ...+ years of experience with the following programming languages: Java, JavaScript, JSP/Servlets...Local areaVisa sponsorship$76 - $76.9 per hour
...with your recruiter to learn more. Base pay range $76.00/hr - $76.90/hr Job Description Immediate need for a talented Cyber Security Analyst - Lead. This is a 04 months contract opportunity with long-term potential and is located in NC, GA, FL, VA, TX, SC (Remote). Please...Contract workLocal areaImmediate startRemote work$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities... ...Cyber team, you will be responsible for:Leading the design and delivery of Customer... ...in a discretionary annual incentive program, subject to the rules governing the program...Local areaVisa sponsorship$155.6k - $306.8k
...As an Engineering Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you will... ...deploy production-grade solutions. You will lead teams, shape technical solutions during... ...and Administration, Web and Application Programming Interface Access Management, Privileged Access...Local areaVisa sponsorship$134.5k - $265.1k
Position Summary Join Deloitte’s Cyber team as an AWS Cloud Security Manager and... ...Security team, you will be responsible for:Lead the design and implementation of Amazon... ...supporting cloud transformation or migration programs, including application of security...Local areaVisa sponsorship$163.4k - $322.1k
...seeking an AWS Cloud Security Senior Manager to lead the design and delivery of cloud security services within our Cyber practice. In this role, you will advise clients... ...and lead teams through complex transformation programs. The ideal candidate brings deep cloud security...Local areaVisa sponsorship$155.6k - $306.8k
Position Summary Deloitte Cyber understands the unique challenges and opportunities... ...Engineer (FDE) Manager, you will lead delivery of cybersecurity and AI-enabled... ...learning experiences to formal development programs, our professionals have a variety of opportunities...Local areaVisa sponsorship$163.4k - $322.1k
Position Summary Cyber Security Architecture Senior Manager - Strategy, Growth and Transformation Deloitte is... ...application security, and operating model decisions while leading teams that deliver complex programs. The ideal candidate brings consulting, cyber, and...Local areaVisa sponsorship$76 - $76.9 per hour
A leading consulting firm is seeking an experienced Cyber Security Analyst - Lead for a 4-month contract with potential for extension. This remote position involves managing API security requests, coordinating with development teams, and utilizing DAST/SAST tools for vulnerability...Remote jobContract work- ...assigned Job Role of Infrastructure Consultant 2, your Area Of Responsibility will be as... ...with the Security Operations Center (SOC) and Incident Response teams. • During active... ...Relevant certifications such as SANS GIAC Cyber Threat Intelligence (GCTI), Recorded Future...Full timeTemporary workRelocation
$40k - $55k
...Description Job Description: Title: Cyber Security Analyst – Enterprise Systems (IT)... .../Supporting: Longwood, FL | Experience: 2+ years of Cyber Security experience... ...security awareness initiatives and training programs to promote a strong security culture throughout...Work at officeRemote work$155.6k - $306.8k
...protect the firm’s assets and reputation. Work you’ll do Deloitte’s Cyber QRM team is seeking a Quality & Risk Manager who will be... ...be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if...Contract workFor subcontractorWork at officeLocal area$82.6k - $162.8k
...Summary Join our Deloitte Cyber team to deliver powerful... ...professional relationshipsAbility to lead projects or workstreamsAbility... ....QualificationsRequired:2+ years of experience in identity... ...discretionary annual incentive program, subject to the rules governing...Local areaVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to SOC 2 Cyber Program Lead. Be the first to apply!


