VISTA InfoSec
Website:
vistainfosec.com
Job details:
About the Role
VISTA InfoSec is hiring a Registered CPA to join our SOC attestation team in Mumbai. You will work on SOC 1 and SOC 2 engagements — testing controls, reviewing evidence, building workpapers, and helping draft attestation reports for clients across the US and globally. This role is open to freshers and early-career CPAs: if you hold a valid CPA registration and are eager to build a career in IT and controls assurance, we will train, mentor, and grow you into a confident SOC practitioner.
Key Responsibilities
▸ Support and conduct SOC 1 (SSAE 18 / ISAE 3402) and SOC 2 (AICPA Trust Services Criteria) readiness assessments, Type I and Type II audits.
▸ Test the design and operating effectiveness of client controls; gather, examine, and validate audit evidence.
▸ Prepare clean, well-organised workpapers that document testing procedures, results, and conclusions.
▸ Map client controls to applicable Trust Services Criteria and control objectives; identify gaps and exceptions.
▸ Assist in drafting SOC reports — control descriptions, test matrices, and findings — under the review of senior auditors.
▸ Communicate with client teams to request evidence, clarify controls, and walk through testing requirements.
▸ Stay current with AICPA attestation standards, SSAE 18, and evolving SOC reporting practices.
▸ Collaborate with VISTA InfoSec's wider compliance and security specialists on integrated engagements.
What We Are Looking For
We value attitude, attention to detail, and a genuine desire to learn just as much as experience:
▸ CPA Credential: Valid, active Registered CPA standing is mandatory for this role.
▸ Communication: Clear written and verbal English — comfortable communicating with US-based and international clients.
▸ Analytical Rigour: Sharp eye for detail and the ability to read, interpret, and evaluate controls, policies, and evidence accurately.
▸ Diligence: Organised, methodical, and reliable in documenting work to a professional standard.
▸ Growth Mindset: Eagerness to learn SOC methodology, IT controls, and information security fundamentals on the job.
Experience & Eligibility
▸ Registered CPA — fresher to approximately 2 years of experience. New CPAs entering the profession are encouraged to apply.
▸ Any exposure to audit, assurance, internal controls, or SOC / SSAE engagements is a plus, but not required — we will train the right candidate.
▸ Familiarity with IT general controls, cloud environments, or information security concepts is an advantage.
This is a rare opportunity for a CPA to specialise in IT and controls assurance early in their career, with structured mentoring from experienced SOC and cybersecurity professionals.
What We Offernent
Detakls
Basis for Offer - Based on background, CPA standing & demonstrated competency
Freshers - CPAs at the start of their career are warmly welcome to apply
Learning Support - VISTA InfoSec sponsors continued professional education & certifications
▸ Hands-on training and mentoring from QSAs, CISAs, CISMs, and experienced SOC practitioners — a fully in-house, senior-led team.
▸ Direct exposure to a global client base, with a strong concentration of US-based SOC engagements.
▸ Active sponsorship of continued professional education, certifications, and CPE credits.
▸ A clear growth path into senior SOC roles within a stable organisation with 22+ years of track record.
Click on Apply to know more.