- Location
- Atlanta, Georgia, United States · Atlanta
- Department
- IT
- Experience
- 2+ years
Description
Join Frazier & Deeter and be a part of a rapidly growing Top 50 accounting & advisory firm that has been repeatedly named a Best Firm to Work For, a Best Firm for Women and a Pacesetter firm among U.S. accounting firms. With several offices across the U.S., UK, and India, there is a spot for you!
We serve clients of all sizes across the United States and the globe, with a suite of services that grow every year. Our growth mindset and entrepreneurial environment translates into variety and opportunity for our people.
At Frazier & Deeter, we’re committed to training, mentoring, and developing our staff members. With our emphasis on Investing in Relationships to Make a Difference and a Firmwide Focus on Inclusion, we help each other grow in every aspect of life.
Job Summary:
Duties & Responsibilities:
- Administer recurring governance, risk, compliance, vendor oversight, audit readiness, and access governance activities.
- Coordinate quarterly user access reviews, certification activities, evidence collection, and follow-up on overdue or unresolved access items.
- Support SOC 2 Type II readiness by organizing control evidence, documentation, policy artifacts, remediation tracking, and audit support materials.
- Review and track vendor compliance documentation, including SOC reports, ISO certifications, security questionnaires, and related due diligence artifacts.
- Maintain vendor risk records, enterprise risk documentation, remediation tracking, governance reporting, and compliance documentation repositories.
- Support acquisition integration by helping ensure retained tools, vendors, access models, and compliance obligations are reviewed and documented.
- Partner with Security Leadership, Technology Operations, Legal, Procurement, Internal Audit / SOQM, and business stakeholders on governance activities.
Education & Experience:
- 2+ years of experience in governance, risk and compliance, information security compliance, risk management, audit, vendor risk management, or IT governance.
- Experience reviewing SOC 1 reports, SOC 2 Type II reports, ISO 27001 certifications, security questionnaires, risk assessments, or compliance frameworks preferred.
- Strong documentation, organization, evidence management, and follow-up skills.
- Understanding of access reviews, vendor oversight, policy governance, compliance reporting, and audit readiness activities.
- Strong written communication skills and ability to coordinate with stakeholders across technology, legal, procurement, audit, and business teams.
- Preferred certifications may include CRISC, CISA, CGRC, Security+, ISO 27001 Lead Auditor / Implementer, or Certified Third-Party Risk Professional.
#LI - hybrid