Internal Auditor – SecOps

Bright Defense, LLC.

United States

On-site

USD 85,000 - 125,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

A leading cybersecurity firm is looking for an Internal Auditor to join their SecOps Team. You will be responsible for conducting internal audits of security controls, ensuring compliance with standards such as ISO 27001 and SOC 2. The ideal candidate will have 3-4 years of experience in information security and strong communication skills for interacting with clients. This role is critical in helping customers maintain an audit-ready security posture and requires collaboration across various internal teams.

Qualifications

  • 3-4 years’ experience as a GRC Analyst or Internal Auditor.
  • Familiarity with ISO 27001, SOC 2, NIST CSF frameworks.
  • Strong understanding of internal controls and audit processes.
  • Ability to manage multiple audits simultaneously.
  • Excellent communication for producing clear, concise reports.

Responsibilities

  • Conduct internal audits verifying compliance with security frameworks.
  • Review audit evidence and identify gaps with internal stakeholders.
  • Maintain records of audit findings and corrective actions.
  • Prepare organized audit reports for customers with clear communication.
  • Support audit readiness initiatives before external audits.
  • Help improve audit procedures and evidence checklists.
  • Align audit activities with risk assessments.
  • Collaborate with Governance and SecOps teams.

Skills

GRC Analysis
Audit Communication
Organizational Skills
Stakeholder Collaboration
NIST CSF
Audit Evidence Management
Written Communication
Stakeholder Collaboration
Time Zone Coverage

Tools

GRC platforms

Job description

About the Role

As an Internal Auditor on our SecOps Team, you’ll play a vital role in supporting our customers’ ongoing audit readiness and continuous monitoring efforts. You’ll review security controls, evidence, and documentation to ensure alignment with industry standards and best practices.

In this role, you’ll primarily collaborate with internal team members across Governance, Security Consultants, Offensive Security, and other SecOps colleagues. You’ll also prepare clear, detailed written communications and reports for customers to keep them informed of audit progress, findings, and next steps.

Key Responsibilities
  • Conduct internal audits of security controls and processes, verifying compliance with frameworks such as ISO 27001, SOC 2, and NIST CSF.
  • Review audit evidence, identify gaps, and coordinate remediation with internal stakeholders.
  • Maintain up-to-date records of audit findings, status, and corrective actions.
  • Work closely with Governance, Offensive Security, and other SecOps functions to align audit activities with the overall security program.
  • Prepare accurate, well-organized audit reports and status updates for customers, with a strong focus on clear, professional written communication.
  • Support audit readiness initiatives by validating control effectiveness ahead of customer external audits.
  • Contribute to improving internal audit procedures, evidence checklists, and tracking systems.
  • Participate in regular internal meetings to ensure audit tasks align with risk assessments and broader security operations goals.
Requirements
  • ✅ 3-4 years’ experience as a GRC Analyst or Internal Auditor in information security, compliance, or risk management.
  • ✅ Familiarity with key security frameworks (ISO 27001, SOC 2, NIST CSF, etc.).
  • ✅ Strong understanding of internal controls, audit processes, and evidence management.
  • ✅ Excellent organizational skills and attention to detail — able to manage multiple customer audits at once.
  • ✅ Strong communication skills are mandatory, especially for producing clear, concise written reports for customers.
  • ✅ Proven ability to work well with internal stakeholders, across technical and non-technical teams.
  • ✅ Support US Eastern and Pacific time zones from 8AM - 5PM
Nice to Have
  • ➕ Relevant certifications such as ISO 27001 Internal Auditor, CISA, CISM, CISSP (Associate), or equivalent.
  • ➕ Experience supporting customers in regulated sectors (finance, healthcare, SaaS).
  • ➕ Familiarity with security auditing tools, GRC platforms, or evidence management software.
Why You’ll Love This Role
  • ✅ You’ll play a critical part in helping our customers maintain a strong, audit-ready security posture.
  • ✅ Gain practical, hands‑on experience with real‑world frameworks and compliance processes.
  • ✅ Be part of a collaborative SecOps Team that values clear communication, trust, and continuous improvement.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Auditor – SecOps | Audit Readiness & Compliance
GRC Auditor – SecOps | Audit Readiness & Compliance

Bright Defense, LLC. • United States

On-site
USD 85,000 - 125,000
GRC Analyst – SecOps
GRC Analyst – SecOps

Bright Defense, LLC. • United States

On-site
USD 70,000 - 90,000
Staff Internal Auditor
Staff Internal Auditor

Community Health Systems • Franklin (TN)

On-site
USD 60,000 - 80,000
Staff Internal Auditor
Staff Internal Auditor

CHS Corporate • Franklin (TN)

On-site
USD 55,000 - 75,000
GRC Compliance Auditor
GRC Compliance Auditor

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 90,000 - 140,000
GRC Compliance Auditor
GRC Compliance Auditor

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Internal Auditor | Grand Rapids, MI or Remote
Internal Auditor | Grand Rapids, MI or Remote

US Signal Company, L.L.C. • Grand Rapids (MI)

Hybrid
USD 65,000 - 90,000
Generous paid time off
Medical, dental, vision benefits
401(k) retirement plan
+3
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
Internal Auditor
Internal Auditor

Verra Mobility • Mesa (AZ)

On-site
USD 52,000 - 72,000
Information Security Analyst - GRC & Operations
Information Security Analyst - GRC & Operations

WHSmith North America • Las Vegas (NV)

Hybrid
USD 70,000 - 110,000