Job Description
End Client: New York City Department of Social Services
Job Title: SVVP Compliance and Audit Consultant
Duration: 36 - 60 Months
Start Date: ASAP
Location: 505 Clermont Ave, 3rd Floor, Brooklyn NY 11238
Position Type: Contract
Interview Type: Webcam
PROJECT NAME: The Data Center Colocation and Migration
Project Overview : NYC DSS is undertaking a large-scale Data Center Co-location and Migration Project to modernize its IT infrastructure. Approximately 90% of current data center infrastructure is reaching End-of-Life (EOL) / End-of-Support (EOS)Migration from 15 MetroTech Center to 11 MetroTech (Brooklyn, NY) Consolidation of multiple data centers into a single co-location facility
Objective:
- Ensures SVVP activities comply with internal policies and external regulations and manages SOC 2 audit readiness. Focuses on compliance, auditing, and reporting, ensuring that security standards and SOC 2 criteria are met and documented throughout the migration process.
Scope:
- Acts as the compliance oversight function for SVVP, ensuring traceability, evidence collection, and audit preparation meet regulatory and organizational standards.
Audit Readiness Preparation and Compliance Check:
- Prepare for audits by ensuring all relevant data and documentation is in place for SOC 2 compliance, focusing on network security, data protection, and privacy.
- Ensure compliance with City-wide, State, and Federal policies and regulatory requirements for all data center migration phases.
Configuration of Auditing Tools:
- Configure auditing tools to track security control implementation, incidents, and compliance status during migration.
- Ensure tools are set up to generate reports on control maturity, SOC 2 criteria adherence, and risk management.
Rollout of Compliance Auditing:
- Rollout audit activities at critical stages of the migration process, focusing on compliance with security standards and SOC 2 readiness.
- Ensure continuous monitoring of compliance through auditing mechanisms in place during migration.
Post-Migration Reporting and Recommendations:
- Provide reports documenting compliance with SOC 2 readiness and other security standards, highlighting any gaps identified during the migration.
- Develop and deliver post-migration recommendations for maintaining ongoing security and compliance in the new data center environment.
Required Skills :
- 8+ years of Compliance and IT audit experience
- 7+ years of direct SOC 2 audit support
- 7+ years of experience participating in infrastructure or data center migration
- 7+ years of experience managing audit evidence repositories
- 7+ years of experience coordinating with external auditors
- 7+ years of experience overseeing compliance during infrastructure transformation