Open role
Security Compliance Consultant (SOC 2, PCI DSS, HIPAA, NYDFS 500), Contract
Turn penetration test results into audit evidence. Map findings and retest results to SOC 2 criteria, PCI DSS v4.0 Requirement 11, HIPAA safeguards, ISO 27001 controls, NYDFS 23 NYCRR 500 and CMMC Level 2, and support clients through the auditor’s questions.
- Engagement
- Contract, paid per engagement
- Location
- Remote, United States
- Pay range
- $130,000 to $210,000 per year
- Posted
- September 14, 2026
The engagement
Contract, remote within the United States, paid per engagement. Work is typically one to three days per client engagement, attached to a penetration test, plus occasional readiness reviews.
What you will do
- Produce the framework mapping section of each report and the attestation letter clients hand to auditors and customers.
- Review client scope against the requirement that drives the test (for example PCI DSS 11.4 segmentation testing or NYDFS 500.5) and flag gaps before testing starts.
- Answer auditor and customer security questionnaire follow-ups about the test with the client.
- Run readiness reviews for clients preparing for a first SOC 2 Type II or PCI DSS assessment.
- Keep the compliance mapping templates current as frameworks change.
What we need
- Four or more years in security compliance, audit or GRC with direct experience of SOC 2 and at least one of PCI DSS, HIPAA, ISO 27001, NYDFS 500 or CMMC.
- Enough technical grounding to read a penetration test finding and explain what it means for a control.
- Clear writing for auditors, executives and engineers.
- Based in the United States with authorization to work here; engagements run on US time and clients are US companies.
- Comfortable working to a fixed, written scope and saying early when something in it is wrong.
- Two professional references from people who have seen your work on a live engagement.
Nice to have
- Time on the assessor side (QSA, SOC 2 audit team, C3PAO) or inside a compliance automation platform.
- Experience with New York financial services or healthcare clients.