SOC 2 Type II + ISO 27001 Implementation Lead (Vanta) - AWS/Kubernetes SaaS
Budget: $30.0 - $45.0
HOURLY / PART_TIME
⭐ 5.00 (4)
Isle of Man
assessments-and-testing, iso-27001, compliance, terraform, kubernetes
Gewenste kwalificaties
- Ervaring: Expert
10–12 hrs/week for the first 6–8 weeks, then ~4 hrs/week through the SOC 2 observation window. Approx. 4-5 months.
Start: Immediately.
About Us
We are an AI native infrastructure and data company for the mining and mining finance industry. Our clients include royalty companies, funds, investment banks and miners.
The Project
We have just signed with Vanta and are pursuing SOC 2 Type II and ISO 27001 in parallel. We have already completed an internal ISO 27001 gap assessment: our technical controls are largely in place, but the capacity to execute this is lacking. We need someone to run the programme end-to-end, working alongside our Head of Engineering and dev team.
You will:
Own the Vanta workspace: connect and troubleshoot integrations, reconcile personnel and asset inventories, and drive the control tests to 100% passing.
Build the ISMS: scope, security policy, objectives, risk assessment methodology and live risk register, and a Statement of Applicability with per-control justification.
Author and shepherd our policy set through review, approval and staff acknowledgement, including AI governance and data handling.
Specify technical remediation against our AWS/EKS/Terraform/GitHub environment - IAM least privilege, key rotation, SSO/MFA enforcement, MDM, log retention, vulnerability management SLAs, change management and environment separation. You write the requirement and the PR-level detail; our engineers merge anything touching production.|
Run supplier security reviews across our cloud, LLM and data vendors.
Stand up the operating evidence: access reviews, incident register, security awareness training, BC/DR plan and test log, management review.|
Configure and launch our public Trust Center.
Liaise with the auditors through Stage 1 and Stage 2 (ISO) and the SOC 2 observation window - provisioning read-only access, packaging evidence, prepping our team for interviews, closing nonconformities.
Must Have
At least two SOC 2 and/or ISO 27001 implementations delivered in Vanta specifically, taken through to a passed audit.
Working command of ISO 27001:2022 clauses 4–10, not only
You can write a Statement of Applicability and a risk treatment plan that survives an assessor.
Hands-on AWS security configuration (IAM, KMS, CloudTrail, Secrets Manager) and enough Kubernetes, Terraform and GitHub Actions literacy to read our infrastructure and specify changes precisely.
Experience mapping SOC 2 TSC and ISO Annex A as a single programme.
Clear written English and the discipline to run this without being managed.
Nice to Haves
Experience with AI/LLM-specific security governance (data residency, no-training commitments, model provider terms, MCP/API access controls).
Vanta MCP server or API for automated evidence collection.
GDPR - data-flow mapping, DPA standardisation, retention schedules.
Prior work with financial services or institutional buyers and their security questionnaires.
Overlap with UK/European business hours.
Our stack: Python/Django, React/TypeScript, PostgreSQL (RDS), ClickHouse, Redis, RabbitMQ, on AWS (EKS, ECS, EC2, RDS, IAM, Secrets Manager, CodeArtifact), fully managed as code with Terraform and Helm. CI/CD on GitHub Actions. Observability via Prometheus, Grafana and Loki. Small, senior engineering team.
Openen op Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Inloggen