Senior Manager ISO/SOC 2

This role is open to USA, EMEA, and Asia-Pacific


At RS Assurance & Advisory, we help businesses navigate complexity with confidence. As a premier risk, audit, and strategic advisory firm, we partner with organizations to protect value, streamline compliance, and unlock growth. We blend technical rigor with a collaborative culture, offering our team members clear career pathways, hands-on client exposure, and the flexibility to do their best work. If you are driven by solving complex challenges and making a tangible impact, you’ll thrive here.

Position Summary

The SOC 2 Senior Manager builds on the Manager role by shifting from managing individual engagements to managing a portfolio of engagements and the people who run them. This role is recognized as a subject matter expert in SOC 2 attestation, with deep command of how SOC 2 engagements are scoped, tested, and reported, and the ability to map multiple compliance frameworks (e.g., ISO 27001, HITRUST, NIST CSF, PCI DSS, HIPAA) to the SOC 2 Trust Services Criteria to support integrated or multi-framework engagements. The Senior Manager carries a personal revenue responsibility, is expected to build a recognized personal brand in the marketplace, and represents RSAA externally through conferences, networking, and community engagement, while continuing to own the firm's highest-complexity client relationships. This is a role for someone who stays with a deal, a client issue, or a difficult engagement until it's actually resolved — not just until the easy part is done.

Essential Duties & Responsibilities

Subject Matter Expertise

      Serve as the firm's go-to expert on SOC 2 engagement mechanics — scoping, Trust Services Criteria selection, testing strategy, and report construction — for complex or unusual engagement scenarios

      Map and reconcile multiple compliance frameworks (e.g., ISO 27001, HITRUST, NIST CSF, PCI DSS, HIPAA) to the SOC 2 Trust Services Criteria to support clients pursuing integrated or multi-framework audits

      Advise Managers and clients on framework overlap and gap analysis, identifying where existing control evidence can be leveraged across frameworks to reduce duplicative testing

      Stay current on AICPA guidance, emerging frameworks, and industry trends, and translate that knowledge into practical guidance for the team and clients

Portfolio & Engagement Oversight

      Oversee a book of engagements led by multiple Managers, reviewing at a portfolio level rather than performing first-level workpaper review

      Personally own the firm's most complex, highest-risk, or highest-profile SOC 2 engagements (e.g., multi-framework audits, first-year Type II conversions, clients with prior qualified opinions)

      Resolve engagement escalations that Managers cannot close independently, including fee disputes, scope disagreements, and exception negotiations

People Leadership

      Directly manage and develop SOC 2 Managers, including performance reviews, promotion recommendations, and compensation input

      Own staffing and capacity planning across an assigned segment of the practice

      Support hiring, interviewing, and training decisions across all levels of the SOC advisory team

Business Development & Sales

      Meet or exceed a minimum annual sales goal of $500,000 in new and/or expanded client business

      Routinely upsell new products and services into the existing client base (e.g., ISO 27001, HITRUST, penetration testing, additional trust services criteria, readiness assessments)

      Originate new business through referrals, proposals, and direct client outreach — not solely supporting partner-led pursuits

      Stay engaged through long sales cycles and setbacks, revising the approach as needed rather than letting a stalled pursuit go cold

      Own pricing strategy and competitive positioning for proposals within area of responsibility

Marketplace Presence & Firm Representation

      Develop and maintain a personal brand in the marketplace as a recognized SOC 2 / IT audit expert (e.g., thought leadership, speaking engagements, published content, professional social presence)

      Attend industry conferences and represent RSAA, including as a speaker or panelist where opportunities arise

      Regularly attend local business and industry events to network and represent RSAA in the community

      Serve as a visible ambassador for the firm's SOC advisory practice within professional associations and referral networks

Methodology & Quality

      Contribute to firm-wide SOC 2 methodology, training curriculum, and quality control standards

      Represent the practice in internal or external quality/peer review matters as needed

Qualifications

      Bachelor's degree in Accounting, Information Systems, or related field

      Active CPA license required; CISA or equivalent certification preferred

      3–5 years of experience as a Manager, with a demonstrated history of performance ratings that exceed expectations

      7–10+ years of overall experience in SOC 2 or IT audit, including experience managing other Managers or leading a portfolio of engagements

      Recognized subject matter expert in SOC 2 attestation, with demonstrated ability to map and reconcile multiple compliance frameworks (e.g., ISO 27001, HITRUST, NIST CSF, PCI DSS, HIPAA) to the SOC 2 Trust Services Criteria

      Demonstrated track record of business development and client relationship growth

      Strong working knowledge of AICPA Trust Services Criteria and SSAE 18 / AT-C 105 and 205

      Established or demonstrable ability to build a professional network and represent a firm publicly

      Comfortable operating with incomplete information and shifting priorities, and known for following through on commitments even when the work gets difficult

 

Service Delivery

Remote (United States)

Remote (Mexico)

Spain

India

Pakistan

Philippines

Partager sur :

Conditions générales d’utilisationConfidentialitéCookiesPropulsé par Rippling