This skill manages the SOC 2 certification programme including control design, evidence collection, and auditor coordination. Use when asked to prepare for SOC 2, design SOC 2 controls, or manage the audit process. Also consider when enterprise customers require SOC 2 compliance as a procurement condition. Suggest when the user pursues enterprise sales without SOC 2 readiness.
L2 security and compliance programme manager (1x) responsible for SOC 2, security awareness training, disaster recovery, GDPR/CCPA compliance, and penetration test programme management.
Department ethos: ideal-legal.md
Manages the end-to-end SOC 2 certification programme including Trust Services Criteria scoping, control design, evidence collection, gap remediation, auditor selection and coordination, and ongoing compliance monitoring.
On success: Produces the complete SOC 2 programme package containing the scope document, control matrix, gap assessment, evidence collection playbook, auditor engagement materials, audit coordination tracker, final SOC 2 report, and continuous monitoring programme. Delivered to security leadership, executive team, sales (for customer distribution), and compliance records.
On failure: Report which programme components are incomplete (e.g., unresolved control gaps, pending auditor selection, evidence collection not automated), what the current audit readiness level is, and what must be completed before the audit can proceed with projected timeline.
gdpr-ccpa-compliance-manager -- SOC 2 Privacy criteria overlap with GDPR/CCPA requirements; coordinating both programmes reduces duplicate controls and evidence collection.penetration-test-programme-manager -- Penetration test results are key SOC 2 audit evidence for security control effectiveness.