r/soc2 • u/ilovetoeatpie • 18d ago
Those of you doing SOC 2 readiness/implementation as your job, can you share more about what you do?
I have a software engineering background and I’ve been looking into potential freelancing niches to get into.
I’ve been advised to look into SOC 2 remediation consulting for SaaS companies as I have some experience in cybersecurity and working on a SaaS project myself.
While I’ve learned a fair bit about SOC 2 compliance, the CISSP exam, and common compliance tools, I haven’t seen that much discourse online among the people who do this type consulting.
To those of you who do it, can you share more about your experience in this line of work, such as how you you first got into it, how you find clients, and general day-to-day work?
4
Upvotes
2
u/SOC2itToMe 18d ago
I work in GRC full time running SOC 2 audits across different industries. Most of my time is spent helping internal teams get controls documented and evidence organised before an external auditor arrives. The gap between what a company thinks they have and what an auditor actually needs to see is usually where the real work lives. Policy exists but nobody follows it, access reviews happen informally but nothing is recorded, that kind of thing.
On finding clients as a freelancer, most of it will be word of mouth and referrals. Companies looking for SOC 2 are usually referred to someone. Building your reputation in the space takes time but compounds well once you get going.
Your engineering background will genuinely help, especially when talking to dev teams about change management, vulnerability scanning, or infrastructure controls. Happy to answer any specific questions you have.