
Senior Security Assurance Engineer
Natick, MA · HybridJob$118–184K/yrSeen 3 days agoSeen in employer's feed 3 days ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Natick, MA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
MathWorks seeks a Senior Security Assurance Engineer to mature its SOC 2 assurance program, manage external audit engagements, and strengthen the organization’s control environment. The role drives certification readiness, leads internal audits and control testing, and partners with technical and business teams to improve compliance and governance. The position follows a hybrid work model, splitting time between the office and home.
Skills & qualifications
Skills
Qualifications
Full job description
Team: Software Process Engineering
Location: US-MA-Natick
Salary Range: USD 183,600 - 118,400
Job Summary
MathWorks has a hybrid work model that enables staff members to split their time between office and home. The hybrid model provides the advantage of having both in-person time with colleagues and flexible at-home life optimizations. Learn More: https://www.mathworks.com/company/jobs/resources/applying-and-interviewing.html#onboarding.
Are you passionate about building trust through robust security compliance programs? We are seeking a highly collaborative and results-driven Senior Security Assurance Engineer to drive and mature our SOC 2 assurance program, manage external audit engagements, drive audit excellence, and partner across the organization to strengthen our control environment.
MathWorks nurtures growth, appreciates inclusivity, encourages initiative, values teamwork, shares success, and rewards excellence.
Responsibilities
Drive External SOC 2 Certification & Audit Readiness
-
Own the external SOC 2 certification effort, including scope management, control readiness, auditor coordination, evidence collection, and successful certification outcomes.
-
Develop and maintain a year-round audit readiness program to ensure continuous compliance with SOC 2 Trust Services Criteria.
-
Build and manage audit evidence repositories, readiness assessments, remediation plans, and certification deliverables.
Plan & Execute Internal Audits
-
Lead internal audits and control testing activities across IT General Controls (ITGCs), application controls, IAM controls, and security processes.
-
Evaluate control design and operating effectiveness using walkthroughs, sampling, re-performance, and evidence inspection techniques.
-
Document clear, defensible audit conclusions and communicate findings to stakeholders and leadership.
-
Validate corrective actions and remediation efforts to ensure sustainable control improvements.
Drive Cross-Functional Collaboration
-
Partner closely with Engineering, IT, Security, Privacy, Legal, and business teams to embed compliance into day-to-day operations.
-
Facilitate control walkthroughs, risk discussions, and audit preparation activities with process owners and control operators.
-
Translate SOC 2 requirements into practical, actionable guidance for technical and non-technical stakeholders.
-
Foster a culture of accountability, audit readiness, and continuous improvement across the organization.
Strengthen Controls & Governance
-
Assess control gaps, identify risks, and drive remediation initiatives to enhance the overall control environment.
-
Review and improve security policies, standards, procedures, and controls to ensure clarity, consistency, and auditability.
-
Monitor control effectiveness through ongoing testing, spot checks, and compliance reviews.
-
Contribute to risk assessments, control mapping, and governance initiatives that support organizational compliance objectives.
-
Identify meaningful ways to improve control and trust service criteria coverage, and influence thoughtful scope additions to external SOC 2 certification.
Minimum Qualifications
- A bachelor's degree and 6 years of professional work experience (or a master's degree and 3 years of professional work experience, or a PhD degree, or equivalent experience) is required.
Additional Qualifications
-
Strong domain expertise and knowledge of security compliance frameworks such as SOC 2, NIST, ISO 27001, ISO 42001, etc.
-
Hands-on experience in cybersecurity compliance, security assurance, GRC, internal audit, or information security.
-
Deep expertise leading SOC 2 internal audits, control testing, and external certification engagements.
-
Strong knowledge of ITGCs, application controls, IAM controls, evidence evaluation, and audit methodologies.
-
Proven ability to assess control design and operating effectiveness and provide practical remediation guidance.
-
Experience preparing organizations for external audits and managing auditor interactions from planning through certification.
-
Exceptional stakeholder management and collaboration skills, with the ability to influence teams at all levels.
-
Strong project management skills with the ability to lead multiple audit and compliance initiatives simultaneously.
-
Experience with GRC platforms or similar tools.
-
Excellent written and verbal communication skills, including executive-ready reporting and presentations.
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Senior Flight Software EngineerAnduril Industries · Boston, MA · $191–253K/yrPosted 1w agoPosted 1w ago
Senior / Staff Behavioral EngineerSuno · New York City, NY · $277–364K/yrPosted 1w agoPosted 1w ago
Senior Systems EngineerRTX Corporation · woburn, MA · $87–165K/yrPosted 2w agoPosted 2w ago
Senior Cybersecurity EngineerRTX Corporation · tewksbury, MA · $87–165K/yrPosted 2w agoPosted 2w ago
Supervisory Quality Assurance SpecialistDefense Contract Management Agency · Salt Lake City, UT · $90–138K/yrPosted 1w agoPosted 1w ago
You've read the whole posting — now see how you match it.