Own audit evidence collection and validation for SOC 2 and ISO 27001 engagements. Chase down artifacts, verify controls, maintain gap registers, and prepare weekly readiness reports. Requires 1-3 years of hands-on GRC experience with US work authorization.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
Compliance Operations Specialist — SOC 2, ISO 27001, Audit Evidence, GRC (Full-Time, Remote, CPT/OPT Welcome)
Careful Security | Dashr.ai | Remote (United States) | Full-time (W-2)
We're hiring a compliance specialist to own audit evidence and audit readiness for our clients inside Dashr.ai — our AI-powered security compliance platform.
What you'll do
- Evidence collection: Chase down audit artifacts from client stakeholders, upload them against controls in Dashr, and track every open item to closure
- Evidence validation: Verify each artifact actually satisfies the control — right system, right period, timestamps visible, approvals dated before the actions they approve
- Gap tracking: Maintain a live gap register per engagement — which controls lack evidence, who owns it, and how it gets collected
- Audit readiness: Weekly readiness reporting per engagement; support mock audit dry runs and remediate findings before the real auditor shows up
Interested in remote work opportunities in Development & Programming? Discover Development & Programming Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
Who you are
- 1–3 years hands-on in GRC, IT audit, or compliance (internships and co-ops at audit firms count)
- You've prepared evidence for a SOC 2 or ISO 27001 audit — not just written policies
- You know what auditors accept: population samples, config state, system logs, signed attestations
- Detail-obsessed and relentless on follow-through — evidence work rewards consistency
- Pursuing or recently completed a degree in Cybersecurity, MIS, or Information Systems
- Authorized to work in the US (CPT/OPT welcome — STEM OPT friendly, E-Verify employer)
Nice-to-haves
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
- Big 4 / mid-tier audit firm experience, CISA or ISO 27001 coursework, Security+, exposure to Azure/M365/Entra ID evidence, ISO 42001 or NIST AI RMF familiarity
Why this role
- Real audits, real deadlines — SOC 2 Type 2 and ISO 27001 engagements with external audit partners, not classroom scenarios
- Work inside an AI-native compliance platform, not spreadsheets
- Direct CISO mentorship; structured 90-day ramp with clear milestones
- Full-time W-2 with STEM OPT support (I-983 training plan included)
How to apply: Easy Apply, or email your resume to jobs@dashr.ai with subject line "Compliance Operations Specialist." Include your work authorization type and end date. No recruiters or staffing agencies. Direct applicants only.
Similar Jobs
Explore other opportunities that match your interests