Security and compliance

10 SOC 2 compliance program experts

These ten security compliance and GRC professionals have run SOC 2 work inside their own companies, from leading audits and collecting evidence to overseeing ongoing SOC 2 programs. They can explain how to prepare for an audit, keep controls and evidence current, and fit SOC 2 alongside other security frameworks.

10 professionals10 companiesData retrieved September 28, 2026

Professionals to explore

01—10
  1. Brian Lareau

    LinkedIn

    Experience: Director Of Compliance · Verint

    Director Of Compliance at Verint since April 2022; he was also Security Compliance Architect at Verint (2017–2022) and at Adtech Global (2015–2017). His profile describes 24+ years in information technology, with his compliance work covering PCI, SOC2, HIPAA, NIST, FedRAMP and ISO, and a background in cloud platforms and change controls.

  2. Dimple Pal

    LinkedIn

    Experience: GRC Lead · dbt Labs

    GRC Lead at dbt Labs since February 2025, after serving as Security and Compliance Lead at SimpleTherapy (2020–2025) and Security & Compliance Manager at Capita (2014–2020). Her profile says she owned the end-to-end audit and certification lifecycle across SOC 2, ISO 42001, ISO 27001, ISO 27701, HIPAA, GDPR and CCPA, leading audits from gap assessment through certification and external attestation.

  3. Jordan Yost

    LinkedIn

    Experience: Director of Audit and Compliance · iPipeline

    Director of Audit and Compliance at iPipeline since January 2019, after serving there as Information Technology Security Manager (2013–2019) and in IT support and data roles from 2008. His profile describes 17+ years in IT security and compliance, specializing in audit management, risk assessment and frameworks like NIST CSF and SOC 2, and cites expanding compliance scopes.

  4. Kimberly DiCredico

    LinkedIn

    Experience: Director of Information Security & Compliance · meQuilibrium

    Director of Information Security & Compliance at meQuilibrium since July 2026, after Senior Project Manager - Operations and Compliance (2024–2026) and Governance, Risk & Compliance Senior Specialist (2026) roles there. Her profile says that on her promotion to Director she inherited ownership of the company's established SOC 2 Type II compliance program, along with its AI Compliance Management and HIPAA Compliance Management programs.

  5. Michelle Allen

    LinkedIn

    Experience: Security Compliance Lead · TRM Labs

    Former Security Compliance Lead at TRM Labs (2023–2024), where her profile says she led the completion of a SOC2 audit, collected evidence and coordinated across all teams, and implemented a GRC tool supporting SOC2, NIST 800-53r5, GDPR and UK Cyber Essentials. Her other roles include Technical Program Manager, FedRAMP SOC2 at Cradlepoint, part of Ericsson (2022) and Sr Compliance Manager Lead at New Relic (2020–2021).

  6. Paige N.

    LinkedIn

    Experience: Security and Compliance Program Manager · BCD Meetings & Events

    Security and Compliance Program Manager at BCD Meetings & Events since October 2022. Her profile describes her as a PMP-certified program manager focused on governance, risk and compliance, leading programs aligned with SOC 2, PCI DSS, GDPR, ISO 27001 and vendor risk management, and building and scaling security, risk and compliance initiatives.

  7. Rebecca Clopton

    LinkedIn

    Experience: Information Security Compliance Analyst · Pluralsight

    Information Security Compliance Analyst at Pluralsight (2021–2025), where her profile describes leading the execution of enterprise-level audits across ISO 27001, SOC 2, TISAX and NHS standards. She moved to an Information Security Operations III role at Pluralsight in December 2025, and her headline describes driving SOC 2, ISO 27001 and audit readiness.

  8. Sara Claerr

    LinkedIn

    Experience: Director, Governance, Audit, and Compliance · Coretek

    Director, Governance, Audit, and Compliance at Coretek since September 2023, after Security Governance Manager (2021–2022) and Security, Privacy, and Governance Manager (2022–2023) roles there. In the current role her profile says she oversees and monitors the ISO 27001, ISO 27701 and SOC 2 programs, ensuring the success of recertification and surveillance audits.

  9. Tina Strakos

    LinkedIn

    Experience: Information Security Compliance Manager · KS2 Technologies

    Information Security Compliance Manager at KS2 Technologies since April 2019. Her profile says she leads information security compliance for a cloud-focused MSP, specializing in SOC 2, GRC and cloud security operations, and describes building and enforcing controls, hardening systems and ensuring continuous audit readiness.

  10. Viktoriya Nikolova

    LinkedIn

    Experience: ISO 27001 and SOC 2 compliance manager · Provectus

    ISO 27001 and SOC 2 compliance manager at Provectus since February 2024, after Technical Translator, Test writer and QA Engineer roles at the same company (2018–2024). Her profile describes her as an information security and compliance manager with experience in ISO 27001 and SOC 2, skilled in risk management, audits and policy development.

Choose the right perspective

If you are preparing for a first audit, look for someone whose note describes leading an audit or building a program; if you already hold a report, someone who oversees recertification and ongoing programs may fit better. Also match company stage and the other frameworks you need, such as ISO 27001 or HIPAA.

Questions to take into the conversation

  1. 01How did you scope your first SOC 2 audit, and what would you include or leave out if you did it again?
  2. 02How did you divide control ownership and evidence collection between security, engineering and other teams to keep the program running between audits?
  3. 03How did you choose an auditor and any compliance automation tooling, and which trade-offs mattered most?

About this directory

This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.

Request a correction or removal

Other perspectives in Security and compliance