About this role
Information Security Associate - Senior Associate System and Organization Controls (SOC 1 / SOC 2) Compliance
at Tevora
Irvine, CA or Fairfax, VA
If you haven't heard of Tevora, it's because we've done our job!
Tevora is a tight-knit community of professionals with a shared passion for our craft. Every day, we combine in-depth knowledge of cybersecurity, technology, and compliance to help create more secure digital environments. To Tevorans, every problem is a puzzle in need of solving. We strongly believe that if we put smart, driven people in a room together, they will accomplish great things. We maintain a supportive culture that celebrates continuous learning, diverse perspectives, and sharing the wins. That's why we have our eyes on you.
What's the role?
Tevora is seeking an Information Security Associate -Senior Associate to join the SOC Compliance team.
This role on the SOC Compliance team is looking for a passionate individual who can apply solid Cyber Security fundamentals, who has a solid professional demeanor, and who knows how to learn by doing.
This role will be responsible for supporting assessments of AICPA’s System and Organization Controls (SOC) compliance, for SOC 1 and SOC 2, on a wide variety of client projects for some of the world's largest organizations. Other compliance frameworks this role will work on may include ISO 27001, HITRUST, C5, and PCI as well as GRC support for clients. This role will also provide internal content to improve practice processes and participate in ongoing training opportunities.
The successful candidate for this role will be detail-oriented, have a solution-focused attitude, and possess strong written and verbal communication skills.
A day in the life could include:
- Participating in IT and Compliance assessments, audits, gap analyses, and remediation.
- Actively contributing to projects in the areas of System and Organization Controls (SOC 1 & SOC 2) Compliance assessments.
- Communicating with Tevora project leads and project stakeholders to effectively convey questions, updates, and the needs of a project.
- Supporting various information security compliance projects, such as HITRUST, C5, PCI, or ISO gap assessments.
- Assisting in the development of customized policies, procedures, controls, disaster recovery plans, and other documentation for applications, systems, and infrastructure for our clients.
- Identifying policy or compliance exceptions for Clients, including working directly with the teams to document exceptions, and identifying compensating controls and remediation action plans.
- Additional duties as assigned.
Necessary skills and qualifications:
- Have knowledge of security policy frameworks and control design.
- Have knowledge of security architecture, network, and systems design.
- Completed a minimum of 1 year of experience in information security, information technology, business consulting, enterprise risk, or compliance field.
- Possess knowledge of common IT and security concepts such as firewall management, server management, access control, and authentication.
- Ability to connect easily with clients and colleagues to communicate effectively across business and technical boundaries- to translate between technical and business communities.
- Ability to work independently with minimal guidance.
- Proficient in writing executive-level reports and technical documentation.
- Commitment to continued learning.
- Proficient in MS Office tools and basic professional acumen.
- At least One Professional Certification completed or in progress (Sec +, CCNA, ISO Lead Implementer, etc.).
Bonus Points:
- Hold a bachelor’s degree from an accredited 4-year university
- Demonstrated experience in at least 1 year of SOC 2 Compliance assessments
- Demonstrated experience in at least one other information security compliance assessment (ISO 27001, PCI Level 1, HITRUST)
- Hold at least one Auditing, Risk, or IT certification from the following list: CISSP, CISA, CISM, CRISC, ISO Lead Auditor.
- Prior or current CPA license
We've got you covered!
- Comprehensive benefits offering
- Paid time off and holidays
- 401K with Company discretionary match
- Vibrant work culture
Additinal Requirments:
- Eligibility to work in the United States.
EEOC Statement
Tevora is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, disability status, or other applicable legally protected characteristics.
