Security Compliance Consultant (SOC 2, PCI DSS, HIPAA, NYDFS 500), Contract

Invadelhimalayaspublished 09/15/2026
This job is no longer listed
The source has removed this listing — applying via the original link is no longer possible.
Must-have:Security
Nice-to-have:HealthTechRemote

Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; work is typically one to three days per client engagement, attached to a penetration test, plus occasional readiness reviews.

What you will do:

  • produce the framework mapping section of each report and the attestation letter clients hand to auditors and customers;
  • review client scope against the requirement that drives the test (for example PCI DSS 11.4 segmentation testing or NYDFS 500.5) and flag gaps before testing starts;
  • answer auditor and customer security questionnaire follow-ups with the client;
  • run readiness reviews for clients preparing for a first SOC 2 Type II or PCI DSS assessment;
  • keep the compliance mapping templates current.

What we need:

  • four or more years in security compliance, audit or GRC with direct experience of SOC 2 and at least one of PCI DSS, HIPAA, ISO 27001, NYDFS 500 or CMMC;
  • enough technical grounding to read a penetration test finding and explain what it means for a control;
  • clear writing for auditors, executives and engineers;
  • based in the United States with authorization to work here;
  • two professional references.

Nice to have:

  • time on the assessor side (QSA, SOC 2 audit team, C3PAO) or inside a compliance automation platform;
  • experience with New York financial services or healthcare clients.

Full description, pay range and application:

Originally posted on Himalayas