Background:The
Practice Lead, Digital Assurance Services is a rare opportunity to build a new practice from the ground up inside a Top 100 firm. Wiss is launching a new Digital Assurance practice focused on SOC 1 and SOC 2 examinations and emerging AI assurance and certification services, and we are hiring the leader who will build it from the ground up. You will define the methodology, stand up the team, shape the technology stack, own quality, and grow the book of business, with the full backing of firm leadership and WissLabs, our AI innovation arm.
This role demands an uncommon combination: a licensed CPA who can sign attestation reports and hold the line on AICPA professional standards, paired with genuine technology depth across information security, cloud environments, and modern audit tooling. Digital trust certifications are fast becoming table stakes for doing business, and we are building an AI native practice designed to deliver them faster and better than the legacy players. If you have been the technical backbone of someone else's practice and want your name on one you built, this is that opportunity.
Practice Building and Strategy- Build the Digital Assurance Services practice from the ground up: service methodology, engagement workflow, templates, quality control framework, and delivery standards.
- Own the practice growth plan, including service line roadmap (SOC 2 first, expanding into AI assurance and related certifications), pricing strategy, and staffing model.
- Shape the technology stack for an AI native delivery model, evaluating audit platforms (Fieldguide and similar) and partnering with WissLabs on automation across testing, evidence collection, documentation, and reporting.
- Establish and track practice KPIs including utilization, realization, engagement margins, and client satisfaction.
- Serve as the market face of the practice: thought leadership, referral relationships, conference presence, and partnership development.
Engagement Delivery and Quality:- Lead SOC 1 and SOC 2 examinations end to end (Type 1 and Type 2), in accordance with AICPA attestation standards (SSAE 18, AT-C 105, 205, and 320) and the Trust Services Criteria.
- Serve as signing practitioner on attestation reports, with full responsibility for engagement quality, independence, and objectivity.
- Build and maintain the practice's peer review readiness, working with the firm's quality control leadership.
- Advise client executives (CISOs, CIOs, CFOs, compliance leaders) on control design, readiness, and remediation, while maintaining independence in fact and appearance under the AICPA Code of Professional Conduct. Coordinate with firm compliance leadership before accepting or continuing attest engagements for any client that has received control design, implementation, or remediation services from Wiss, including through the Wiss Advisory practice, within the same or a look-back period.
- Quality control leadership retains independent authority to pause, modify, or decline any engagement on quality or independence grounds, including engagements this role would otherwise pursue for growth or pricing reasons. This role does not have override authority on QC or independence determinations.
- Review technical workpapers, assess control environments across cloud and hybrid infrastructures, and ensure timely delivery of high-quality reports.
Technology and AI Native Delivery:- Champion AI assisted delivery: apply LLM tools and agentic workflows to evidence review, documentation, testing, and report generation while maintaining professional skepticism and audit quality.
- Evaluate emerging assurance domains including AI governance frameworks (ISO/IEC 42001, NIST AI RMF) and position the practice for AI certification services.
- Partner with WissLabs to productize repeatable assurance workflows and continuously improve delivery speed and margin.
Team and Talent:- Recruit, train, and mentor the practice team, with a hiring philosophy favoring technical and IT backgrounds developed into assurance professionals.
- Lead internal training on SOC reporting, internal controls, and attestation standards as the practice scales.
- Build a culture of quality, curiosity, and speed consistent with Wiss values.
Qualifications:Required- Active CPA license (non-negotiable; the report signer must be a CPA under AICPA attestation standards).
- 10+ years of audit or assurance experience, with 5+ years performing and managing SOC 1 and SOC 2 examinations at a professional services firm.
- Deep working knowledge of AICPA attestation standards (SSAE 18, AT-C sections), Trust Services Criteria, and peer review expectations for attestation practices.
- Demonstrated technology depth: comfort assessing controls across cloud platforms (AWS, Azure, GCP), identity and access management, change management, and security operations.
- Leadership experience managing engagement teams and developing staff.
- Track record of building, launching, or significantly growing a service line or practice.
- Excellent executive presence and communication skills for client-facing and market-facing work.
Preferred- CISA, CISSP, CISM, CCSK, or comparable security and IT audit credentials.
- Familiarity with AI governance and assurance frameworks (ISO/IEC 42001, NIST AI RMF) and genuine interest in AI certification as an emerging service line.
- Hands-on experience with modern audit delivery platforms (Fieldguide, AuditBoard, or similar) and with applying generative AI tools to assurance work.
- Exposure to adjacent frameworks (HITRUST, ISO 27001, CMMC) sufficient to advise clients on the broader compliance landscape.
#LI-HYBRID