Bachelor's degree with 6 years of experience or Master's/PhD with relevant experience.
Strong knowledge of security compliance frameworks (SOC 2, NIST, ISO 27001).
Hands-on experience in cybersecurity compliance and internal audit.
Deep expertise in leading SOC 2 audits and external certification engagements.
Proven ability to assess control design and provide remediation guidance.
Exceptional stakeholder management and collaboration skills.
Strong project management skills for multiple initiatives.
Responsibilities
Own the external SOC 2 certification effort and manage auditor coordination.
Develop a year-round audit readiness program for continuous compliance.
Lead internal audits and control testing across various security processes.
Document audit conclusions and communicate findings to stakeholders.
Partner with cross-functional teams to embed compliance into operations.
Assess control gaps and drive remediation initiatives for control enhancement.
Contribute to risk assessments and governance initiatives supporting compliance objectives.
Benefits
Collaborative work environment fostering cross-functional partnerships.
Opportunities for professional development and continuous improvement.
Access to advanced GRC tools and resources.
Engagement in meaningful compliance initiatives that impact the organization.
Full Job Description
Job Summary
Are you passionate about building trust through robust security compliance programs? We are seeking a highly collaborative and results-driven Senior Security Assurance Engineer to drive and mature our SOC 2 assurance program, manage external audit engagements, drive audit excellence, and partner across the organization to strengthen our control environment.
Own the external SOC 2 certification effort, including scope management, control readiness, auditor coordination, evidence collection, and successful certification outcomes.
Develop and maintain a year-round audit readiness program to ensure continuous compliance with SOC 2 Trust Services Criteria.
Build and manage audit evidence repositories, readiness assessments, remediation plans, and certification deliverables.
Plan & Execute Internal Audits
Lead internal audits and control testing activities across IT General Controls (ITGCs), application controls, IAM controls, and security processes.
Evaluate control design and operating effectiveness using walkthroughs, sampling, re-performance, and evidence inspection techniques.
Document clear, defensible audit conclusions and communicate findings to stakeholders and leadership.
Validate corrective actions and remediation efforts to ensure sustainable control improvements.
Drive Cross-Functional Collaboration
Partner closely with Engineering, IT, Security, Privacy, Legal, and business teams to embed compliance into day-to-day operations.
Facilitate control walkthroughs, risk discussions, and audit preparation activities with process owners and control operators.
Translate SOC 2 requirements into practical, actionable guidance for technical and non-technical stakeholders.
Foster a culture of accountability, audit readiness, and continuous improvement across the organization.
Strengthen Controls & Governance
Assess control gaps, identify risks, and drive remediation initiatives to enhance the overall control environment.
Review and improve security policies, standards, procedures, and controls to ensure clarity, consistency, and auditability.
Monitor control effectiveness through ongoing testing, spot checks, and compliance reviews.
Contribute to risk assessments, control mapping, and governance initiatives that support organizational compliance objectives.
Identify meaningful ways to improve control and trust service criteria coverage, and influence thoughtful scope additions to external SOC 2 certification.
Minimum Qualifications
A bachelor's degree and 6 years of professional work experience (or a master's degree and 3 years of professional work experience, or a PhD degree, or equivalent experience) is required.
Additional Qualifications
Strong domain expertise and knowledge of security compliance frameworks such as SOC 2, NIST, ISO 27001, ISO 42001, etc.
Hands-on experience in cybersecurity compliance, security assurance, GRC, internal audit, or information security.
Deep expertise leading SOC 2 internal audits, control testing, and external certification engagements.
Strong knowledge of ITGCs, application controls, IAM controls, evidence evaluation, and audit methodologies.
Proven ability to assess control design and operating effectiveness and provide practical remediation guidance.
Experience preparing organizations for external audits and managing auditor interactions from planning through certification.
Exceptional stakeholder management and collaboration skills, with the ability to influence teams at all levels.
Strong project management skills with the ability to lead multiple audit and compliance initiatives simultaneously.
Experience with GRC platforms or similar tools.
Excellent written and verbal communication skills, including executive-ready reporting and presentations.
About The Mathworks
The MathWorks, Inc. is an American software company that specializes in mathematical computing software. The company was founded in 1984 and is headquartered in Natick, Massachusetts. The MathWorks offers a range of products, including MATLAB, Simulink, and Stateflow, which are used in engineering, science, and mathematics. The company serves customers in over 100 countries and has partnerships with major technology companies such as Microsoft and Intel. In 2019, The MathWorks was named one of the best places to work by Glassdoor.