Project-Based | Ukraine (Remote / Hybrid) About the Role We’re looking for a hands-on SOC 2 Compliance Expert / vCISO to take full ownership of our SOC 2 Type 1 audit and drive it to completion.
This is not a consulting or advisory role. We need a closer — someone who executes, fixes gaps, works directly in the tools, and leads us to a signed SOC 2 report. The Situation We’ve been working on SOC 2 for ~6 months and are close, but progress has stalled. The foundation is there — what’s missing is focused execution and ownership to push through the final stretch. Scope of Work Gap Remediation * Review our current SOC 2 progress in [Vanta / Drata / Manual — specify] * Clearly identify remaining gaps and blockers
Evidence Collection * Personally collect, prepare, and upload required evidence (screenshots, logs, configs, access reviews, etc.) * We will provide all required system access
Policy Management * Finalize, polish, and align all required security policies: * Information Security * Incident Response * Disaster Recovery / BCP * Access Control, etc.
Auditor Liaison * Act as the primary point of contact with the auditing firm * Handle auditor questions, clarifications, and follow-ups end to end
Technical Coordination * Translate compliance gaps into clear, actionable tickets * Work with our dev team on any remaining technical fixes
Who We’re Looking For * Proven experience successfully closing SOC 2 audits (Type 1 required, Type 2 a plus) for SaaS companies * Strong technical background: * AWS or GCP * CI/CD pipelines * Access control & IAM * Highly execution-focused and autonomous * Comfortable owning the process without constant oversight
Engagement Details * Project-based / sprint-focused * Immediate start preferred * Ukraine-based candidates preferred (but open to strong remote profiles)
How to Apply Please DM with: * A short summary of the last 2 SOC 2 projects you personally closed * Your availability to start immediately * Your rate (fixed price for the sprint or hourly)