GRC Compliance Auditor

NorthMark Strategies

Dallas (TX)

On-site

USD 90,000 - 130,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Company-Paid Lunch Stipend
100% Employer-Paid Medical
Dental and Vision benefits
Paid Parental Leave (16 weeks)
401(k) match up to 6%
PPO and HSA options
25 days PTO + 12 holidays

Job summary

NorthMark Strategies is seeking a detail-oriented GRC Compliance Auditor to join the Information Security team in Dallas, TX. You will own SOC 2 Type II and ISO 27001 programs, drive readiness, evidence collection, and external audit coordination while partnering with Engineering, IT, HR, Legal, and Operations.

The right candidate has hands-on SOC 2/ISO 27001 experience, strong control discipline, and the ability to guide both technical and non-technical stakeholders through audits without

Qualifications

  • Bachelor’s degree in Information Systems, CS, Business Administration, or equivalent.
  • 4–8 years of hands-on GRC, IT audit, or information security compliance.
  • Experience conducting or supporting SOC 2 Type II audits.
  • Knowledge of ISO 27001/27002 and related audits.
  • Experience administering a GRC platform such as Vanta, Drata, Hyperproof, AuditBoard.
  • Ability to translate regulatory requirements into practical controls.
  • Familiarity with IAM tooling in access reviews and compliance evidence.
  • Strong written and verbal communication across Engineering, IT, Legal, HR, and Operations.

Responsibilities

  • Lead internal audit cycles for SOC 2 Type II and ISO 27001, assessing control design and effectiveness.
  • Coordinate external audits end-to-end—evidence packages, auditor requests, and findings closure.
  • Conduct readiness assessments and gap analyses across frameworks to guide remediation.
  • Develop and maintain a cross-framework control library mapping SOC 2/ISO 27001/NIST.
  • Administer the GRC automation platform, configuring frameworks, evidence integrations, dashboards.
  • Drive automated evidence collection via IdP, IGA, HR, and infrastructure integrations.
  • Produce executive-ready compliance posture reports and risk scorecards for leadership.
  • Manage remediation of audit findings and conduct third-party risk assessments.
  • Develop audit readiness training, control owner guides, and playbooks for teams.
  • Respond to customer security questionnaires and due-diligence requests.

Skills

SOC 2 Type II
ISO 27001
GRC platform administration
Audit coordination
Regulatory compliance
Vendor risk assessment
Identity & access management

Education

Bachelor’s degree in Information Systems / CS / Business / related field

Tools

Vanta
Drata
Hyperproof
AuditBoard

Job description

The Company

NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients’ research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.


NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients’ research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.


THE POSITION

NMC² is looking for a detail-oriented GRC Compliance Auditor to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons. This role owns the day-to-day execution of NMC²’s SOC 2 Type II and ISO 27001 compliance programmes — from readiness assessments and control mapping through to evidence collection and external audit coordination.



You will serve as the primary administrator of our GRC platform, maintaining the control framework library, driving automated evidence collection, and producing compliance posture reporting for leadership. You will work closely with control owners across Engineering, IT, HR, Legal, and Operations — translating regulatory requirements into practical controls and embedding audit readiness into how teams operate day to day.



The right candidate brings deep hands-on experience with SOC 2 and ISO 27001, a sharp eye for control gaps, and the communication skills to guide both technical and non-technical stakeholders through audit processes without disrupting the business.


Responsibilities


  • Lead internal audit cycles for SOC 2 Type II and ISO 27001, assessing the design and operating effectiveness of controls and identifying deficiencies for remediation.

  • Coordinate external audits end-to-end — scheduling walkthroughs, preparing evidence packages, managing auditor requests, and tracking findings through to validated closure.

  • Conduct readiness assessments and gap analyses across compliance frameworks, recommending remediation actions prioritized by risk and business impact.

  • Develop and maintain a cross-framework control library mapping SOC 2 TSC, ISO 27001 Annex A, NIST CSF, and other applicable standards to NMC²’s operational controls.

  • Serve as the primary administrator of the GRC and compliance automation platform — configuring control frameworks, evidence integrations, risk registers, and compliance dashboards.

  • Drive adoption of automated evidence collection via integrations with IdP, IGA, HR, and infrastructure systems to reduce manual audit overhead across the business.

  • Produce executive-ready compliance posture reports, control health metrics, and audit-readiness scorecards for leadership and board-level stakeholders.

  • Manage and track remediation of audit findings, exceptions, and risk acceptances, and conduct vendor and third-party risk assessments against SOC 2 and ISO 27001 requirements.

  • Develop audit readiness training, control owner guides, and playbooks to embed compliance awareness into day-to-day operations across Engineering, Product, and Operations teams.

  • Respond to customer security questionnaires and due diligence requests relating to audit certifications and NMC²’s compliance posture.


Requirements


  • Bachelor’s degree in Information Systems, Computer Science, Business Administration, or a related field — or equivalent experience.

  • 4–8 years of hands-on experience in GRC, IT audit, or information security compliance.

  • Demonstrated experience conducting or supporting SOC 2 Type II audits, including evidence collection, control testing, and auditor coordination.

  • Working knowledge of ISO 27001 / 27002 requirements, with experience supporting certification or surveillance audits.

  • Hands-on experience administering a GRC or compliance automation platform such as Vanta, Drata, Hyperproof, AuditBoard, or equivalent.

  • Ability to translate complex regulatory requirements into practical, implementable controls and evidence procedures.

  • Familiarity with identity and access management tooling (Entra ID, Okta, or equivalent) in the context of access reviews and compliance evidence.

  • Experience working with control owners across Engineering, IT, Legal, HR, and Operations to define and validate control procedures.

  • Strong written and verbal communication skills; comfortable presenting compliance findings to both technical and non-technical audiences.

  • One or more relevant certifications preferred: CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC.


It is impossible to list every requirement for, or responsibility of, any position. Similarly, we cannot identify all the skills a position may require since job responsibilities and the Company’s needs may change over time. Therefore, the above job description is not comprehensive or exhaustive. The Company reserves the right to adjust, add to or eliminate any aspect of the above description. The Company also retains the right to require all employees to undertake additional or different job responsibilities when necessary to meet business needs.


Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.


Benefits & Perks


  • Company-Paid Lunch Stipend: Lunch is provided via GrubHub

  • Company-Paid Benefits: 100% Employer-Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families, 16 weeks of Paid Parental Leave, Employee Assistance Program, Life insurance, Short-Term Disability and Long-Term Disability

  • 401(k): Company will match 100% of your contributions up to 6%

  • Optional Employee-Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.

  • Time Off: 25 days of Paid Time Off plus 12 company holidays


EQUAL OPPORTUNITY EMPLOYER

NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER. THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS, MENTAL OR PHYSICAL DISABILITY, AND GENETIC INFORMATION, OR ANY OTHER BASIS PROTECTED BY APPLICABLE LAW. THE FIRM ALSO PROHIBITS HARASSMENT OF APPLICANTS OR EMPLOYEES BASED ON ANY OF THESE PROTECTED CATEGORIES.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

NorthMark Strategies • Dallas (TX)

On-site
USD 110,000 - 140,000
Lunch stipend
Medical benefits
Paid time off
GRC Compliance Auditor
GRC Compliance Auditor

NorthMark Strategies LLC • Dallas (TX)

On-site
USD 90,000 - 140,000
Company-Paid Lunch Stipend
Employer-Paid Medical Insurance
Dental and Vision Benefits
+5
VP of Security Operations
VP of Security Operations

NorthMark Strategies • Dallas (TX)

On-site
USD 180,000 - 280,000
Company‑Paid Lunch Stipend
Company‑Paid Benefits
401(k) match
+2
VP of Security Operations
VP of Security Operations

NorthMark Strategies LLC • Dallas (TX), Northern (KY)

Hybrid
USD 180,000 - 280,000
Health insurance
401(k) match
Paid parental leave
+3
VP of Security Operations
VP of Security Operations

NorthMark Compute and Cloud LLC • Town of Texas (WI), Fort Worth (TX)

On-site
USD 180,000 - 240,000
Company-Paid Benefits: Medical, Dental
Life insurance
401(k) company match
+2
GRC Analyst
GRC Analyst

NorthMark Strategies LLC • Dallas (TX)

On-site
USD 95,000 - 125,000
Company-Paid Lunch Stipend
Employer-Paid Medical (HDHP) including
Dental and Vision benefits
+4
VP of Security Operations
VP of Security Operations

NorthMark Strategies • Town of Texas (WI)

On-site
USD 180,000 - 260,000
Lunch stipend
Employer-paid medical (HDHP)
Dental coverage
+8
GRC Compliance Auditor
GRC Compliance Auditor

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
GRC Compliance Auditor
GRC Compliance Auditor

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 90,000 - 140,000
Senior HPC Hardware Engineer
Senior HPC Hardware Engineer

NorthMark Strategies • Town of Texas (WI)

On-site
USD 140,000 - 190,000
Lunch stipend
Medical benefits (employer-paid)
Parental leave 16 weeks
+2