Information Security & Compliance Analyst
ANZ Talent Hub · Auckland, Auckland, New Zealand
Apply & track with Apply EdgeAuckland | ASAP start | Contract until 31 December 2026Have you helped an organisation prepare for a SOC 2 audit - working through controls, collecting evidence and getting outstanding actions across the line?ANZ Talent Hub is seeking a hands-on Information Security & Compliance Analyst to support a high-priority SOC 2 Type 2 programme within a technology-led organisation.The organisation has already completed SOC 2 Type 1. Your focus will be on the next stage: helping demonstrate that controls are operating effectively, maintaining audit-ready evidence and supporting delivery ahead of a major product release in February 2027.The OpportunityThis is a practical governance, risk and compliance (GRC) assignment. Working alongside the Project Manager, Information Security team and technical control owners, you will help turn audit requirements into clear actions, reliable evidence and completed remediation.You will:Review existing controls and documentation, identifying gaps against audit requirements.Help implement and document agreed security controls and processes.Collect, organise and review evidence for completeness, relevance and the required audit period.Work with control owners to resolve missing evidence and outstanding actions.Support control walkthroughs, testing and audit preparation.Maintain policies, procedures, control descriptions and evidence records.Track remediation and flag issues that could affect audit readiness.Prepare responses to auditor queries and coordinate supporting information.What you will bringWe’re looking for someone who has contributed directly to a SOC 2 readiness or audit engagement, ideally Type 2.You should be comfortable explaining which controls you worked on, what evidence you prepared and how you helped resolve gaps.You will also bring:Practical experience in information security, IT controls, GRC or technology assurance.An understanding of control design, operating effectiveness and audit evidence.Strong documentation skills and attention to detail.Confidence working with security, engineering, operations and business stakeholders.The ability to prioritise tasks, follow up constructively and deliver against a fixed deadline.Your background could be in an internal security or compliance team, IT audit, risk advisory or assurance consulting. You do not need to have led the entire SOC 2 programme, but you must have contributed hands-on.Experience with Hyperproof or another GRC platform would be valuable. Familiarity with Jira, Confluence, SharePoint, AWS or Bitbucket would also help.ISO 27001 experience and relevant professional certifications are welcome, but practical SOC 2 delivery experience matters more than a long list of qualifications.Please apply with your CV and a brief summary of:Your involvement in a SOC 2 engagement, including whether it was Type 1 or Type 2.The controls, evidence or remediation activities you personally handled.Your earliest available start date.Applicants must have the right to work and contract in New Zealand.