SOC Analyst

Posted 21 Days Ago
Be an Early Applicant
Hiring Remotely in AUS
Remote
700K-900K Annually
Mid level
Enterprise Web • Information Technology • Software • Automation
The Role
Own day-to-day information security and compliance operations, including SOC 2, ISO 27001, and Cyber Essentials readiness. Responsibilities include evidence collection, control monitoring, policy writing, access reviews, endpoint and software compliance, risk tracking, remediation follow-up, and audit coordination. The analyst will work with Engineering, DevOps, IT, and management to maintain effective controls and audit-ready documentation.
Summary Generated by Built In

This is a remote position.

SyncEzy is a growing Integration Company in the B2B SAAS space, with a strong focus on the Construction, Trades, and Service Industries. We are fiercely independent & bootstrapped, NOT VC Funded. This is A TRUE Remote /work-from-home position. We have staff dispersed across 4 countries and 15 cities. We pride ourselves on running a flat organization, with a friendly, easy-going culture.

We are looking for a hands-on Information Security & Compliance Analyst (GRC)
to take ownership of the day-to-day activities required to maintain our security and compliance posture. The role will support and coordinate compliance activities across SOC 2, ISO 27001 and Cyber Essentials, and will work closely with Engineering, DevOps, IT and management to keep controls operating effectively and evidence audit-ready throughout the year.

This is an execution-focused role. The successful candidate should be comfortable moving between policy work, evidence collection, endpoint/software compliance, risk tracking, access reviews and audit coordination. The Senior Engineering Manager will remain the management and escalation point, while the analyst becomes the primary owner of routine compliance operations and follow-up.

Primary Objectives

·       Maintain year-round readiness for SOC 2, ISO 27001 and Cyber Essentials rather than treating compliance as a once-a-year audit exercise.

·        Own routine compliance administration, evidence collection, control monitoring and follow-up so engineering leadership can remain focused on product delivery and technical management.

·        Translate compliance requirements into practical actions for Engineering, DevOps and IT teams without creating unnecessary operational overhead.

·        Identify gaps early, track remediation to closure and maintain clear documentation showing that controls are designed and operating effectively.



Requirements Required Qualifications & Skills

·        2–4 years of relevant experience in GRC, information security compliance, security assurance, IT audit or a closely related role.

·        Practical exposure to at least one major security/compliance framework such as SOC 2 or ISO 27001; familiarity with Cyber Essentials is strongly preferred.

·        Experience collecting, reviewing and organizing audit evidence and working with technical control owners.

·        Strong documentation and policy-writing skills with attention to consistency and audibility.

·        Working understanding of cloud environments, identity and access management, endpoint security, vulnerability management, logging, backups and change management.

·        Ability to read technical evidence and ask the right questions without needing to be a software engineer or DevOps engineer.

·        Strong ownership, follow-up and organizational skills; comfortable tracking multiple recurring compliance activities simultaneously.

·        Clear written and verbal communication skills and the ability to work with both technical and non-technical stakeholders.

Preferred / Good-to-Have

·        Experience with compliance automation or GRC platforms such as Vanta, Drata, Sprinto or equivalent tools.

·        Experience working in a SaaS, software-development or cloud-first organization.

·        Familiarity with MDM / endpoint-management tooling and software inventory reviews.

·        Exposure to AWS, Azure or other public-cloud security controls.

·        Experience supporting customer security questionnaires or vendor-risk assessments.

·        Relevant certifications such as ISO 27001 Internal Auditor / Lead Implementer, Security+, CISA, CRISC or similar are useful but not mandatory.



Benefits Benefits
  • A TRUE Remote / Work from Home position.  We are a Global Remote company, and have been remote working long before it was made popular by COVID. We have staff dispersed across 4 countries and 15 cities.  We pride ourselves on running a flat organization, with a friendly and going culture.

Competitive Salary  + All the below
           Salary range:7-9 lacs 
            
Allowance for Internet / Phone costs
            Company Hardware provided after completing probation.
            
Continuous development and education allowances.
            Flexible Remote work from anywhere (As long as you have good internet and communication)
            Excellent growth opportunities, growth into leadership for the right candidate
            Generous policies around leave / social and training allowances
            End of year Bonuses based on company + Individual performance.
             Zero Commute, Work while you work, play while you play.  Perfect Work / Life balance.
            Remote job opportunities and other benefits to be discussed during the interview
        Flexible, family friendly & fun work environment
​

Skills Required

  • 2-4 years of relevant experience in GRC, information security compliance, security assurance, IT audit, or a closely related role
  • Practical exposure to at least one major security or compliance framework, such as SOC 2 or ISO 27001
  • Experience collecting, reviewing, and organizing audit evidence
  • Experience working with technical control owners
  • Strong documentation and policy-writing skills
  • Working understanding of cloud environments, identity and access management, endpoint security, vulnerability management, logging, backups, and change management
  • Ability to read technical evidence and ask appropriate questions without being a software or DevOps engineer
  • Strong ownership, follow-up, and organizational skills
  • Clear written and verbal communication skills
  • Familiarity with Cyber Essentials
  • Experience with compliance automation or GRC platforms such as Vanta, Drata, Sprinto, or equivalent tools
  • Experience working in a SaaS, software-development, or cloud-first organization
  • Familiarity with MDM or endpoint-management tooling and software inventory reviews
  • Exposure to AWS, Azure, or other public-cloud security controls
  • Experience supporting customer security questionnaires or vendor-risk assessments
  • Relevant certification such as ISO 27001 Internal Auditor, ISO 27001 Lead Implementer, Security+, CISA, CRISC, or similar
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
27 Employees
Year Founded: 2012

What We Do

SyncEzy is a two-way integration platform that connects B2B SaaS applications such as QuickBooks Time, Simpro, Salesforce, and Zoho. Instead of using generic connectors, SyncEzy builds deep, point-to-point integrations to streamline business workflows, reduce manual data entry, and automate processes. They provide continuous maintenance and updates to ensure business functions remain uninterrupted as APIs evolve.

Similar Jobs

Plurilock Logo Plurilock

SOC 2 Analyst

Security • Cybersecurity • Data Privacy
In-Office or Remote
Sydney, New South Wales, AUS
200 Employees

Boeing Logo Boeing

Electrical Engineer

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Remote
Queensland, AUS
170000 Employees

Boeing Logo Boeing

Electrical Engineer

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Remote
Queensland, AUS
170000 Employees

Mastercard Logo Mastercard

Director, Services Business Development

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Remote or Hybrid
Saint Leonards Creek, New South Wales, AUS
38800 Employees

Similar Companies Hiring

Ford Energy Thumbnail
Automotive • Software • Energy • Utilities • Manufacturing • Renewable Energy
US
55 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
70 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account