Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

SOC 2 Cyber Program Lead

$113k - $190k

First Citizens Bank

Overview

Remote eligible. This position provides cybersecurity risk management and expert support at the highest level of cybersecurity governance and oversight, with primary responsibility for leading and managing the company’s Systems and Organization Controls (SOC) 2 program. The role coordinates across business and technology stakeholders to ensure SOC 2 requirements are understood, implemented, and sustained. Serves as a SOC 2 leader, contributes to broader cyber risk oversight, recommending and monitoring enhancements to processes and procedures, performing analysis, and reporting in support of strategic objectives.

Responsibilities
  • SOC 2 Program Leadership - Leads and manages the bank’s SOC 2 readiness and compliance program. Coordinates program activities across business and technology teams, ensuring controls are properly implemented, documented, and maintained in alignment with SOC 2 Trust Services Criteria (TSC). Oversees evidence collection, audit preparedness, and continuous improvement of the SOC 2 program. Serves as the primary liaison with auditors during readiness and examination activities.
  • SOC 2 Readiness - Executes assessments and readiness activities to evaluate compliance with SOC 2 requirements. Performs gap analyses, documents control coverage, and monitors remediation efforts. Collects and validates evidence, ensures accuracy and completeness, and prepares the organization for external audits by driving readiness efforts.
  • Stakeholder Partnership - Partners with control owners, governance teams, and other stakeholders to align on responsibilities, close identified gaps, and monitor remediation progress. Provides guidance and education on SOC 2 requirements, roles, and expectations, ensuring stakeholders understand their role in sustaining compliance.
  • Risk Identification and Monitoring - Identifies and monitors risks related to SOC 2 control requirements and broader cybersecurity domains. Escalates potential areas of concern, facilitates root cause analysis, and tracks corrective actions to resolution. Maintains awareness of changes in SOC 2 requirements, industry trends, and regulatory expectations, translating them into actionable insights for the bank.
  • Reporting - Produces reports and dashboards on SOC 2 readiness, testing results, control maturity, and remediation progress. Conveys root cause analysis, patterns, and trends to leadership. Provides transparency into risk exposure, compliance status, and effectiveness of mitigation measures, with emphasis on SOC 2 Trust Services Criteria coverage.
Qualifications

Bachelor's Degree and 6 years of experience in Financial Services, Risk Management, Operational Risk Management, Compliance, Audit, Finance or Accounting OR High School Diploma or GED and 10 years of experience in Financial Services, Risk Management, Operational Risk Management, Compliance, Audit, Finance or Accounting

  • Direct experience executing or leading SOC 2 audits and programs, including readiness assessments, gap analysis, evidence collection, and audit preparedness
  • Strong knowledge of SOC 2 Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) and demonstrated ability to apply them in a large, complex organization
  • Experience partnering with stakeholders across business and technology to monitor risks, close compliance gaps, and sustain ongoing SOC 2 readiness
  • In-depth practical knowledge of internal controls, risk assessments, and operational and cybersecurity processes, with experience implementing regulatory and compliance frameworks
  • Broad knowledge and understanding of cybersecurity risks and controls, including IT infrastructure, cloud computing, mobile technologies, and cybersecurity technologies
  • Excellent written and oral communication skills, with ability to influence stakeholders and communicate effectively at multiple levels
  • CISSP, CISA, CISM, CRISC, CIA, or equivalent certification
Preferred Qualifications
  • 7-10 years of experience in risk management or compliance, including leadership of SOC 2, ISO, PCI, or similar frameworks
  • 3+ years of experience at a Large Financial Institution or similarly regulated environment
  • Familiarity with NIST frameworks (e.g., CSF, SP 800-53) and their application in strengthening cybersecurity programs
  • Extensive knowledge and subject matter expertise in managing cybersecurity compliance in financial services, including applicable regulations (SOC 2, NIST, CSA, FFIEC, OCC, FRB, state law, and other regulatory guidance)
  • Strong project management and continuous improvement skills

This job posting is expected to remain active for 45 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.

The base pay for this position is generally between $113,000 and $190,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at jobs.firstcitizens.com/benefits.

Job metadata
  • Seniority level: Not Applicable
  • Employment type: Full-time
  • Job function: Consulting, Information Technology, and Sales
  • Industries: Banking and Financial Services

Referrals increase your chances of interviewing at First Citizens Bank by 2x

Get notified about new Program Lead jobs in Raleigh, NC.

#J-18808-Ljbffr
Vacancy posted 21 hours ago
Similar jobs that could be interesting for youBased on the SOC 2 Cyber Program Lead in Raleigh, NC vacancy
  • $155.6k - $306.8k

     ...Deployed Engineer) in Deloitte Cyber, you will be embedded in...  ...third-party resilience programs• Translating client...  ...to target architecture• Leading the hands-on design,...  ...serverless components• 2+ years of experience delivering...  ...(NIST CSF, ISO 22301, SOC 2) sufficient to model... 
    Suggested
    Local area
    Remote work

    Deloitte

    Raleigh, NC
    1 day ago
  • $148.2k - $292.3k

     ...Engineer Manager in Deloitte Cyber’s Digital Trust & Privacy practice...  ...application programming interfaces (APIs), automations...  ...professional relationshipsAbility to lead projects or workstreamsAbility...  ...Python, Java, or Node.js, and 2+ years of experience delivering... 
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    2 days ago
  • $170k - $230k

     ...expertise.About JLL We’re JLL—a leading professional services and...  ...on JLL's Threat Intelligence Program, working across the full intelligence...  ...in close partnership with Cyber Defense, engineering, and business...  ...teams such as threat hunt, SOC/IR, or detection engineering,... 
    Suggested
    Full time
    Local area
    Remote work
    Shift work

    Jones Lang Lasalle

    Raleigh, NC
    2 days ago
  • $134.5k - $265.1k

    Position Summary Deloitte’s Cyber team helps clients address...  ...projects by applying advanced SOC engineering experience and...  ..., you will be responsible for:Leading the design and implementation...  ...Cloud Feeds, and application programming interfaces (APIs)Collaborating... 
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    1 day ago
  •  ...below. Specific activities may change from time to time.Lead the enterprise vulnerability management program for automated API testing, including identification,...  ...API security protocols and frameworks, including OAuth 2.0, OpenID Connect (OIDC), Mutual TLS (mTLS), and JSON... 
    Suggested
    Full time
    Part time
    Work at office
    Shift work
    Day shift

    Truist

    Raleigh, NC
    a month ago
  • $134.5k - $265.1k

     ...Manager in Deloitte’s Digital Trust & Privacy practice, you will lead the discovery, design, and implementation of privacy technology...  ...and execute basic technology concepts such as Application Programming Interfaces (API’s), system requests methods (GET/POST), etc.Demonstrated... 
    Local area

    Deloitte

    Raleigh, NC
    3 days ago
  • $110k - $140k

     ...identities, as well as the enterprise-wide Data Loss Prevention (DLP) program. This role is pivotal to the establishing control over ALL...  ...embed identity security controls into agent deployment pipelines Lead regular access certification and entitlement review cycles... 
    Local area
    Work from home
    Monday to Friday
    Flexible hours

    Extreme Networks, Inc.

    Raleigh, NC
    7 days ago
  • $134.5k - $265.1k

     ...Join Deloitte’s Cloud Cyber Security practice as a GCP...  ...control-related issues, leading technical workstreams, and...  ...(GCP) environments.2+ years of experience using...  ...Organization Control 2 (SOC 2).Experience delivering...  ...discretionary annual incentive program, subject to the rules... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    4 days ago
  • $163.4k - $322.1k

     ...help clients strengthen physical security programs, align security capabilities to...  ...consulting team, you will be responsible for:Leading client engagements focused on physical security...  ...guidance to othersThe teamDeloitte’s Cyber Defense & Resilience practice helps organizations... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    4 days ago
  • $76 - $76.9 per hour

    A leading consulting firm is seeking an experienced Cyber Security Analyst - Lead for a 4-month contract with potential for extension. This remote position involves managing API security requests, coordinating with development teams, and utilizing DAST/SAST tools for vulnerability... 
    Remote job
    Contract work

    Pyramid Consulting, Inc

    Raleigh, NC
    3 days ago
  • $134.5k - $265.1k

    Position Summary Our Deloitte Cyber Defense & Resilience team recognizes that resilient...  ...team, you will be responsible for:Leading physical security advisory and implementation...  ...metrics, operating procedures, and program updates while managing workplans, milestones... 
    Contract work
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    4 days ago
  •  ...have been providing technically superior solutions to complex and challenging problems in the physical sciences since 1979. ARA has over 2,200 employee-owners and continues to grow rapidly. Together, our offices throughout the U.S. and Canada provide a broad range of... 
    Full time
    Work experience placement

    Applied Research Associates

    Raleigh, NC
    a month ago
  • $163.4k - $322.1k

     ...Join Deloitte’s Cloud Cyber Risk practice and help organizations...  ...implementation, and operations across leading cloud platforms. This role...  ...clients modernize security programs and strengthen cloud environments...  ...and Organization Controls 2, Health Insurance Portability... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    3 days ago
  • $134.5k - $265.1k

    Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity...  ...access requests etc.3+ years of experience with the following programming languages: Java, JavaScript, JSP/Servlets, SQL.Understanding and... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    4 days ago
  • $87.62k - $117k

     ...comprehensive benefits. Employees can participate in health insurance options, standard and supplemental retirement plans, and the NCFlex program (numerous high-quality, low-cost benefits on a pre-tax basis). Employees also receive paid vacation, sick, and community service... 
    Contract work
    Work experience placement
    Work at office
    Night shift

    North Carolina

    Raleigh, NC
    1 day ago
  •  ...Job Description Job Description Triangle Cyber offers SkillBridge internships for an IT/Cybersecurity Analyst.  As an IT/Cybersecurity...  ...Plans, Success - TGPS) is the redesigned Transition Assistance Program (TAP) curriculum designed to help Service members prepare for... 
    Internship

    Triangle Cyber, LLC

    Raleigh, NC
    18 days ago
  •  ...sick leave, parental leave, and access to an Employee Assistance Program focused on mental and financial wellness, please click here to...  ...with a focus on incident response and security operations within a SOC environment required.Hands-on experience with Microsoft Sentinel... 
    Work at office
    Local area

    American Tower

    Cary, NC
    23 days ago
  • $163.4k - $322.1k

     ...seeking an AWS Cloud Security Senior Manager to lead the design and delivery of cloud security services within our Cyber practice. In this role, you will advise clients...  ...and lead teams through complex transformation programs. The ideal candidate brings deep cloud security... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    3 days ago
  • $134.5k - $265.1k

    Position Summary Cyber Network Security Architecture - Manager / Manager, Strategy...  ...and organizational risk profiles of leading companies? Do you want to be involved in...  ...participate in a discretionary annual incentive program, subject to the rules governing the... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    4 days ago
  • $155.6k - $306.8k

    Position Summary Deloitte Cyber understands the unique challenges and opportunities...  ...Engineer (FDE) Manager, you will lead delivery of cybersecurity and AI-enabled...  ...learning experiences to formal development programs, our professionals have a variety of opportunities... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    1 day ago
  • $134.5k - $265.1k

    Position Summary Join Deloitte’s Cyber team as an AWS Cloud Security Manager and...  ...Security team, you will be responsible for:Lead the design and implementation of Amazon...  ...supporting cloud transformation or migration programs, including application of security... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    3 days ago
  • $171.6k - $338.3k

    Position Summary Deloitte Cyber understands the unique challenges and opportunities...  ...or GCP.Experience with object-oriented programming using languages such as Java, Python, or...  ...junior or mid-level developers, leading code reviews, and providing development... 
    Local area

    Deloitte

    Raleigh, NC
    4 days ago
  • $134.5k - $265.1k

    Position Summary Cyber Security & Risk Strategy ManagerOur Deloitte Cyber team understands...  ...business challenges by shaping strategy, leading transformation initiatives, and driving...  ...offering develops and transforms cyber programs in line with a client's strategic... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    21 hours ago
  •  ...for protecting DLA Piper’s clients, people, data, reputation, and global business operations by leading a mature, business-aligned information security and cyber risk program. This role sets the strategic direction for the firm’s Information Security Management System,... 
    Full time
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Raleigh, NC
    4 days ago
  • $134.5k - $265.1k

    Position Summary Join Deloitte’s Cloud Cyber Risk practice and help organizations...  ...architecture, implementation, and operations across leading cloud platforms. This role offers the...  ...to help clients modernize security programs and strengthen cloud environments.... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    3 days ago
  • $105.4k - $207.8k

    Position Summary Join Deloitte’s Cyber practice as a Cyber SecOps Senior Consultant...  ...Data Security Standard (PCI DSS)Leading deployment of log ingestion pipelines using...  ...data fabric technologies and application programming interface integrations, including Bindplane... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    1 day ago
  • $68k - $133.9k

     ...Build your career as an Analyst in Cyber Strategy, Growth & Transformation, helping...  ...professional relationships • Ability to lead projects or workstreams • Ability to manage...  ...participate in a discretionary annual incentive program, subject to the rules governing the... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    4 days ago
  • $161k - $242k

     ...self-driving cars to learning machines. We lead in chip design, verification, and IP...  ...security, or related disciplines, with at least 2 years in a senior or lead engineering...  ...Strong experience implementing enterprise DLP programs across email, endpoint, network, cloud,... 
    Remote work

    Synopsys Inc

    Morrisville, NC
    a month ago
  •  ...meaningful contributions to worldwide mobility. Our goal is to be the leading provider of exciting technology that improves the quality of...  ..., SQL, IOS, Perl, Python, Bash, PowerShell, and PHP programming languages. Experience with security assessment tools and techniques... 
    Work experience placement
    Worldwide

    Clever Devices Ltd.

    Apex, NC
    18 days ago
  • $105.4k - $207.8k

     ...complex IT architectures to incorporate privacy technology solutions.Lead working sessions with client stakeholders to gather technical,...  ...and execute basic technology concepts such as Application Programming Interfaces (API’s), system requests methods (GET/POST), etc.Demonstrated... 
    Local area

    Deloitte

    Raleigh, NC
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to SOC 2 Cyber Program Lead. Be the first to apply!