About Aegentra
Aegentra is a cybersecurity and governance consultancy with teams based in Melbourne and Sydney, supporting small and growing businesses across Australia. Our work includes SOC 2 readiness, ISO 27001, ISO 42001 and ISO 9001 consulting and internal audits, Microsoft 365 security and IT support.
Through Aegentra Academy, we also offer professional training as a PECB authorised training partner.
The role
We are looking for a senior practitioner who can independently lead SOC 2 implementation and readiness projects for SaaS companies and other service providers.
You will own delivery from discovery and scoping through control implementation, evidence preparation, readiness review, agreed examination support and final handover. You will work with the Aegentra Director, client leadership, engineers, control owners and the appointed independent CPA firm.
You will not stop at identifying gaps. You will drive the agreed work to completion, verify what has changed and make unresolved risks visible.
This is a hands-on delivery role, not a documentation-only or project-coordination position. The client retains responsibility for its controls and management decisions; the independent CPA firm performs the examination and issues the SOC 2 report.
Client service is part of the job
Technical delivery and client service are both essential. We expect clients to understand the work, know what happens next and feel supported throughout the engagement.
Be responsive. Acknowledge client messages within one business day during agreed engagement coverage. Give a realistic timeframe for the substantive response, and arrange coverage for planned absences.
Be clear and reliable. Explain requirements in plain language. Come prepared, keep commitments and provide concise updates on progress, decisions, blockers and next steps.
Take ownership of concerns. Handle questions, complaints and difficult conversations calmly. Follow through, bring practical options and involve the Director early when an issue needs escalation.
Respect the client's time. Make requests specific, avoid asking for the same evidence repeatedly and design processes the client's team can realistically maintain.
Maintain professional judgement. Supporting the client does not mean hiding risks, weakening conclusions or promising a particular examination outcome.
Key responsibilities
Scope and plan the engagement
Lead discovery workshops to understand the service and the assurance its customers require. Define the system boundary, intended report type, relevant Trust Services Categories, service commitments, system requirements and outsourced dependencies.
Address subservice organisations and complementary controls. Agree deliverables, responsibilities, milestones, allocated effort, dependencies and acceptance criteria before implementation begins.
Assess gaps and prioritise remediation
Review systems, policies, processes and operating evidence against the applicable criteria. Assess risk and distinguish gaps in control design from gaps in implementation or operation.
Build a prioritised remediation plan with named owners and clear completion criteria. Explain trade-offs and escalate decisions that require client management approval.
Implement controls that work
Develop practical governance, security and operational processes appropriate to the scope. These may include risk assessment and oversight; identity, privileged access and joiner–mover–leaver processes; access reviews; change management and secure development; vulnerability management, logging and monitoring; incident response; supplier risk; security awareness; data protection; and backup and recovery.
Carry out agreed work within your competence and authority. Coordinate specialist changes with client engineers or other approved specialists, obtain change approvals and verify the results.
A policy alone is not the deliverable. The process must work, have an owner and produce evidence.
Build documentation and evidence workflows
Write tailored policies, procedures, control narratives and risk records. Develop a criterion-to-control-to-evidence matrix and support client management in preparing the system description using the AICPA Description Criteria.
Establish evidence owners, collection frequencies, review workflows and retention arrangements. Use the client's compliance platform or a controlled manual process. Assess evidence quality rather than relying on dashboard completion percentages.
Lead readiness and agreed Type II support
Perform pre-examination readiness reviews, verify remediation and document outstanding issues.
Where Type II reporting-period support is included, maintain the evidence calendar, coach control owners and check that records cover the correct systems, populations and dates. Identify missed activities and exceptions promptly, preserve the historical record and track corrective action.
Coordinate examination support and manage delivery
Coordinate the agreed evidence requests, walkthroughs and follow-up questions with the client and its independent CPA firm. Support accurate management responses without taking over the examiner's responsibilities.
Manage client meetings, actions, dependencies and progress reporting. Track effort against the agreed budget and obtain approval for scope changes before undertaking additional work.
Complete the handover
Deliver the agreed documentation, evidence index, control-owner responsibilities, recurring activity calendar and open-action register. Train client owners to maintain the programme.
Confirm acceptance of the agreed deliverables, make remaining responsibilities explicit and complete secure access and data closeout.
What you need to bring
Proven SOC 2 delivery. You have personally led multiple implementation or readiness engagements and supported at least one completed Type II reporting period and independent examination. You can distinguish your own contribution from the wider team's work.
Framework knowledge. You can apply the AICPA Trust Services Criteria and Description Criteria to a real organisation. You understand Type I and Type II engagements, the Common Criteria, relevant additional criteria, subservice organisations, and complementary user entity and subservice organisation controls.
Technical credibility. Practical experience with at least one of AWS, Azure or Google Cloud, together with an understanding of identity, source control, CI/CD, logging, vulnerability management, data protection and recovery. You can work effectively with engineers and recognise when specialist expertise is needed.
Evidence judgement. You distinguish documented intentions from operating controls, identify unreliable evidence and incomplete populations, and handle exceptions honestly. You never fabricate evidence, backdate activities or conceal control failures.
Client leadership and commercial discipline. You can lead workshops, write clear documentation, manage difficult conversations, estimate work and deliver within an agreed allocation of days without daily supervision.
Typically, you will bring five or more years in cybersecurity, GRC, technology risk or IT audit, or equivalent demonstrated senior delivery capability. Relevant delivery experience matters more than a particular career path.
Client data and confidentiality
Protecting client information is a condition of engagement, not just an NDA requirement.
Use information only for the engagement. Follow Aegentra's and the client's agreed confidentiality and security requirements, together with applicable privacy law, including the Privacy Act 1988 (Cth) and Australian Privacy Principles where applicable. Protect business-confidential information as well as personal information.
Minimise access and collection. Use named, least-privilege accounts and MFA. Access only what is authorised and necessary. Minimise downloads, redact unnecessary personal information and keep each client's information separate. Do not share accounts or reuse client materials for another engagement without written authorisation.
Use approved systems and tools. Store and share information only through systems approved for the engagement. Do not use personal email, personal cloud storage or unapproved file-sharing services. Do not enter client information into AI tools, meeting transcription tools or other third-party services unless the specific tool and use have written approval from Aegentra and, where required, the client. Do not engage another person or subprocessor to handle client information without approval.
Work securely. Use an approved device with full-disk encryption, current security patches, appropriate endpoint protection and automatic screen locking. Protect screens, conversations and documents in remote workspaces, and follow the agreed secure-access arrangements.
Report concerns immediately. Notify the Director immediately upon becoming aware of a suspected loss, unauthorised disclosure, account compromise or other security incident. Follow the incident-response process and preserve relevant evidence; do not alter or delete records to conceal a problem.
Close out securely. Return or securely delete client information as instructed under the agreed retention and disposal arrangements, subject to lawful retention requirements and notified legal holds. Confirm completion in writing and identify any authorised retained records. Assist with access removal. Confidentiality continues after the engagement ends.
Useful, but not mandatory
Experience with Vanta, Drata, Secureframe or similar platforms; ISO 27001 implementation; Microsoft 365 and Entra ID; or work within or alongside a CPA examination practice.
Relevant credentials may include CISA, CISM, CISSP, CRISC, ISO 27001 Lead Implementer or Lead Auditor, and SOC 2-specific professional training.
Credentials support your application. They do not replace evidence that you can deliver.
Engagement terms
This is a remote, project-based opportunity, not a permanent full-time position. Applicants must be based in Australia and have the right to undertake the engagement.
The indicative rate is A$1,200–A$1,300 per day, inclusive of superannuation where applicable. Any applicable GST is additional. The engagement structure and payment breakdown will be agreed before commencement.
Each project will have a written agreement covering scope, deliverables, day length, allocated days, milestones, availability, client-response coverage, payment terms and approved expenses. Client communications, preparation and agreed follow-up form part of the scoped work.
Availability for agreed client meetings during Australian business hours is required. This is not an on-call role. Ongoing work or a minimum allocation between projects is not guaranteed.
Before starting client work, the successful applicant will complete identity, work-rights and reference checks; a National Police Check with consent, assessed for relevance to the role; a confidentiality agreement; and a conflict-of-interest declaration. Additional client-specific requirements will be disclosed before accepting an assignment.
For business-to-business contractors, a valid ABN and suitable professional indemnity and public liability insurance are required, with cover requirements agreed before commencement. These documents are not required with the initial application.