SyncEzy Logo

SyncEzy

SOC Analyst

Posted 3 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in AUS
Mid level
Remote
Hiring Remotely in AUS
Mid level
Own day-to-day information security and compliance operations, including SOC 2, ISO 27001, and Cyber Essentials readiness. Responsibilities include evidence collection, control monitoring, policy writing, access reviews, endpoint and software compliance, risk tracking, remediation follow-up, and audit coordination. The analyst will work with Engineering, DevOps, IT, and management to maintain effective controls and audit-ready documentation.
The summary above was generated by AI

This is a remote position.

SyncEzy is a growing Integration Company in the B2B SAAS space, with a strong focus on the Construction, Trades, and Service Industries. We are fiercely independent & bootstrapped, NOT VC Funded. This is A TRUE Remote /work-from-home position. We have staff dispersed across 4 countries and 15 cities. We pride ourselves on running a flat organization, with a friendly, easy-going culture.

We are looking for a hands-on Information Security & Compliance Analyst (GRC)
to take ownership of the day-to-day activities required to maintain our security and compliance posture. The role will support and coordinate compliance activities across SOC 2, ISO 27001 and Cyber Essentials, and will work closely with Engineering, DevOps, IT and management to keep controls operating effectively and evidence audit-ready throughout the year.

This is an execution-focused role. The successful candidate should be comfortable moving between policy work, evidence collection, endpoint/software compliance, risk tracking, access reviews and audit coordination. The Senior Engineering Manager will remain the management and escalation point, while the analyst becomes the primary owner of routine compliance operations and follow-up.

Primary Objectives

·       Maintain year-round readiness for SOC 2, ISO 27001 and Cyber Essentials rather than treating compliance as a once-a-year audit exercise.

·        Own routine compliance administration, evidence collection, control monitoring and follow-up so engineering leadership can remain focused on product delivery and technical management.

·        Translate compliance requirements into practical actions for Engineering, DevOps and IT teams without creating unnecessary operational overhead.

·        Identify gaps early, track remediation to closure and maintain clear documentation showing that controls are designed and operating effectively.



Requirements Required Qualifications & Skills

·        2–4 years of relevant experience in GRC, information security compliance, security assurance, IT audit or a closely related role.

·        Practical exposure to at least one major security/compliance framework such as SOC 2 or ISO 27001; familiarity with Cyber Essentials is strongly preferred.

·        Experience collecting, reviewing and organizing audit evidence and working with technical control owners.

·        Strong documentation and policy-writing skills with attention to consistency and audibility.

·        Working understanding of cloud environments, identity and access management, endpoint security, vulnerability management, logging, backups and change management.

·        Ability to read technical evidence and ask the right questions without needing to be a software engineer or DevOps engineer.

·        Strong ownership, follow-up and organizational skills; comfortable tracking multiple recurring compliance activities simultaneously.

·        Clear written and verbal communication skills and the ability to work with both technical and non-technical stakeholders.

Preferred / Good-to-Have

·        Experience with compliance automation or GRC platforms such as Vanta, Drata, Sprinto or equivalent tools.

·        Experience working in a SaaS, software-development or cloud-first organization.

·        Familiarity with MDM / endpoint-management tooling and software inventory reviews.

·        Exposure to AWS, Azure or other public-cloud security controls.

·        Experience supporting customer security questionnaires or vendor-risk assessments.

·        Relevant certifications such as ISO 27001 Internal Auditor / Lead Implementer, Security+, CISA, CRISC or similar are useful but not mandatory.



Benefits Benefits
  • A TRUE Remote / Work from Home position.  We are a Global Remote company, and have been remote working long before it was made popular by COVID. We have staff dispersed across 4 countries and 15 cities.  We pride ourselves on running a flat organization, with a friendly and going culture.

Competitive Salary  + All the below
           Salary range:7-9 lacs 
            
Allowance for Internet / Phone costs
            Company Hardware provided after completing probation.
            
Continuous development and education allowances.
            Flexible Remote work from anywhere (As long as you have good internet and communication)
            Excellent growth opportunities, growth into leadership for the right candidate
            Generous policies around leave / social and training allowances
            End of year Bonuses based on company + Individual performance.
             Zero Commute, Work while you work, play while you play.  Perfect Work / Life balance.
            Remote job opportunities and other benefits to be discussed during the interview
        Flexible, family friendly & fun work environment


Similar Jobs

One Month Ago
In-Office or Remote
Sydney, New South Wales, AUS
Senior level
Senior level
Security • Cybersecurity • Data Privacy
The SOC 2 Analyst investigates security incidents, reviews threats, leads operations responses, and designs SIEM use cases while collaborating with stakeholders.
Top Skills: CrowdstrikeLinuxmacOSMicrosoft DefenderSIEMSplunkWindows
2 Hours Ago
Remote or Hybrid
Saint Leonards Creek, New South Wales, AUS
Entry level
Entry level
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Supports Mastercard’s Australasia Division through pricing, interchange, customer economics, performance analytics, regulatory monitoring, governance, reporting, and strategic project execution. The role analyzes commercial and operational data, develops dashboards and business cases, prepares executive materials, coordinates stakeholders, and identifies process improvements across Australia, New Zealand, and the Pacific Islands.
Top Skills: ExcelPower BIPythonSQL
7 Hours Ago
Remote or Hybrid
Windsor, Sydney, New South Wales, AUS
Internship
Internship
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Supports Universal Pictures publicity and marketing activities through database management, media and influencer research, screening reports, review-link compilation, event administration, guest-list coordination, merchandise fulfillment, and targeted grassroots promotion pitches. The intern assists with screenings and premieres, updates publicity contacts, monitors industry opportunities, and provides general administrative support. This is a part-time, nine-month internship requiring enrollment throughout the full term and availability for evening events.
Top Skills: ExcelMicrosoft OutlookMicrosoft PowerpointMicrosoft WordSplash

What you need to know about the Sydney Tech Scene

From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account