Contract / Fractional IT Security & Compliance Consultant (SOC 2 + HIPAA)
About This Role
About Muddy Gecko:
Muddy Gecko is a global leader in on\-demand marketing, contract staffing, and AI solutions. We specialize in three core service areas:
- Marketing Services – delivering end\-to\-end solutions across Strategy, Branding, Content, Campaigns, Creative, and Digital Execution.
- Contract Staffing – providing flexible short\- and long\-term marketing and AI talent to meet evolving business needs.
- AI Solutions \& Platforms – developing Custom LLMs, Secure AI Chatbots, Intelligent Agents, and offering expert AI Training \& Consulting.
Our team of 135 professionals brings deep expertise in both marketing and artificial intelligence, with a track record of supporting thousands of organizations across more than 200 countries. From Fortune 500 enterprises to innovative startups, Muddy Gecko helps clients drive growth, efficiency, and innovation through tailored, high\-impact solutions. Muddy Gecko is based in Scottsdale, AZ.
Overview:
We are seeking an experienced IT Security \& Compliance Consultant to support our clients in achieving and maintaining SOC 2 compliance and HIPAA compliance. This role will work directly with client leadership, engineering teams, and operations to assess current security posture, define compliance roadmaps, and implement the required controls, policies, and procedures.
This is a hands\-on, advisory \+ execution role ideal for a senior consultant who can both guide strategy and drive implementation.
Key Responsibilities
SOC 2 Compliance
- Lead end\-to\-end SOC 2 readiness and audit preparation (Type I and Type II)
- Perform gap assessments against SOC 2 Trust Services Criteria
- Define and implement security controls aligned with SOC 2 requirements
- Coordinate with third\-party auditors and manage audit process
- Establish ongoing monitoring and evidence collection processes
HIPAA Compliance
- Guide clients through full HIPAA compliance lifecycle
- Conduct HIPAA risk assessments and security risk analyses
- Develop and implement HIPAA\-required administrative, technical, and physical safeguards
- Create and maintain HIPAA Policies \& Procedures documentation
- Support Business Associate Agreements (BAAs) and compliance workflows
Security \& Risk Management
- Assess and improve overall security posture across infrastructure and applications
- Implement best practices for access control, encryption, logging, and monitoring
- Support incident response planning and business continuity strategies
- Advise on vendor risk management and third\-party security reviews
Client Advisory \& Enablement
- Act as a trusted advisor to client stakeholders (technical and non\-technical)
- Translate compliance requirements into practical, scalable solutions
- Train client teams on compliance processes and ongoing responsibilities
- Provide clear documentation and reporting for executive stakeholders
Required Qualifications
- Must be a U.S. Resident (required)
- 5\+ years of experience in IT security, compliance, or risk management
- Proven experience leading SOC 2 (Type I and Type II) compliance initiatives
- Strong hands\-on experience with HIPAA compliance frameworks
- Experience creating security policies and procedures from scratch
- Deep understanding of security controls (IAM, encryption, logging, monitoring, etc.)
- Experience working directly with auditors and managing audit processes
- Strong communication skills with ability to work across technical and business teams
Preferred Qualifications
- Experience with cloud environments, especially Amazon Web Services (AWS)
- Background in application development or DevSecOps environments
- Familiarity with compliance tools (e.g., Vanta, Drata, Secureframe)
- Relevant certifications (one or more preferred):
- CISSP
- CISM
- CISA
- CCSP
- HCISPP
Engagement Details
- Fractional / part\-time availability (flexible hours based on client needs)
- Multiple client engagements possible
- Opportunity for long\-term advisory relationships
- Fully remote (U.S.\-based only)
What Success Looks Like
- Clients successfully achieve SOC 2 certification
- Clients become HIPAA compliant with documented policies and controls
- Security practices are operationalized—not just documented
- Clients are confident managing compliance independently post\-engagement
If you are a motivated individual with a passion for driving successful projects from start to finish, we encourage you to apply. Join our dynamic team and make a significant impact on our organization's success.
Job Types: Full\-time, Contract
Pay: $50\.00 \- $70\.00 per hour
Education:
- Bachelor's (Required)
Experience:
- product marketing: 2 years (Required)
Language:
- English (Required)
Work Location: Remote