Project Overview
Career Equity is a workforce development platform that centralizes the training-to-hiring process by connecting employers, training providers, job seekers, workforce development organizations, universities, and support services through a single, integrated solution.
The platform manages ATS functionality, training workflows, candidate tracking, and program analytics. Because it handles sensitive workforce and education data across public-private partnerships and government-funded initiatives, SOC 2 Type II certification became a critical requirement for customer trust and regulatory compliance. This case study details how Career Equity built and maintains cloud-native security architecture to protect user data and meet enterprise-grade standards.
Industry
Workforce Development / HR Tech
Tech Stack
Team
Composition
Client Background
Career Equity is a U.S.-based workforce development platform purpose-built to modernize equitable employment pathways across sectors. The platform serves a complex, multi-stakeholder ecosystem—employers, training providers, job seekers, workforce development organizations, universities, and public funders—operating across public-private partnerships, education institutions, and clean energy initiatives. As an enterprise-grade SaaS product handling sensitive program and participant data, compliance and security are core to its market positioning.
The Challenge
Career Equity handles sensitive workforce and education data across public-private partnerships, government-funded programs, and clean energy initiatives—spanning multiple user types including job seekers, employers, and institutional funders.
The platform required a security architecture that could meet enterprise and public-sector trust expectations, pass a third-party SOC 2 Type II audit with no exceptions, and maintain compliance as AI integrations and new frameworks were introduced.
Athenaworks built Career Equity on AWS Serverless architecture within a Virtual Private Cloud (VPC), enforcing complete network segmentation and strict access pathways across all services and APIs.
Security Architecture & Data Protection:
– Data encrypted at rest and in transit via TLS 2.0 and AWS Secret Manager
– MFA mandated across all critical systems
– RBAC and least-privilege principles enforced at every layer
– Infrastructure-level network isolation between dev, testing, and production environments
Compliance Monitoring & Incident Response:
– Continuous compliance monitoring via Sprinto
– Documented incident response procedures with S1–S4 severity classification and time-bound SLAs
– Annual third-party penetration testing
– Audit logs configured to trigger alerts on suspicious or anomalous behavior
SOC 2 Type II Certification (2024–2025):
Audited by a third-party assessor against Trust Services Criteria: Security, Availability, and Confidentiality. All areas passed with no exceptions:
– Infrastructure and logical access
– Incident response and vulnerability management
– Risk assessments
– Vendor and subservice evaluations
– Policy enforcement and internal audit
Encryption, access, and retention practices are also consistent with GDPR-aligned expectations.