Compliance Analyst/Internal Auditor

NMR ConsultingHuntsville, AL
$100,000 - $115,000

About The Position

We are seeking an Internal Auditor and Compliance Specialist to manage, evaluate, and improve our corporate compliance frameworks. This role leads internal audits of ISO standards, CMMC requirements, CMMI models, and contractual documentation. The position ensures that internal policies, procedures, and evidence align with client contracts, defense requirements, and applicable quality and cybersecurity standards.

Requirements

  • Bachelor's degree in information technology, cybersecurity, business administration, or a related field.
  • 3-5+ years of experience in internal auditing, compliance management, quality assurance, or a closely related function.
  • Demonstrated experience supporting or managing CMMC or NIST SP 800-171, ISO 9001, ISO 20000, or ISO 27001, and CMMI implementations.
  • Security+ certification.
  • Strong understanding of IT systems and processes, cybersecurity controls, data protection requirements, and supply chain risk management.
  • Exceptional technical writing and communication skills, including the ability to translate complex regulations into clear, practical guidance.
  • The ability to obtain and maintain a U.S. government-issued security clearance is required.
  • Strong interpersonal skills and the ability to work effectively with corporate teams, technical personnel, service providers, customers, and external assessors.
  • Ability to travel occasionally based on business and audit requirements.

Responsibilities

  • Plan and execute internal audits against CMMC Level 2, NIST800-171 ISO standards such as ISO 9001, ISO 20000, and ISO 27001, and CMMI Development and Services models.
  • Identify operational, quality, and security gaps relative to current contractual and regulatory obligations.
  • Develop, coordinate, and monitor corrective action plans to address audit findings and verify closure.
  • Write, revise, and standardize internal policies, processes, and standard operating procedures.
  • Maintain the master documentation library and ensure operational teams use approved, current versions.
  • Map client and contract requirements to corporate policies, controls, and operational workflows.
  • Review contracts to identify regulatory, quality, and cybersecurity requirements.
  • Serve as the primary point of contact for external auditors, registrars, and government assessors.
  • Gather, organize, validate, and present the evidence and artifacts required for certification and formal assessments.
  • Operate, maintain, and continually improve the corporate quality management program and related systems.
  • Prepare and deliver briefings, participate in quality-management meetings, and communicate system status, requirements, risks, and planned actions.
  • Provide quality- and compliance-related training to headquarters staff so employees understand applicable requirements and follow company policies and procedures.
  • Participate in tabletop exercises to gain knowledge and best practices that can be adopted into our current policies and procedures.
  • Research developing standards and regulatory requirements and advise leadership on needed system changes, emerging obligations, and potential competitive differentiators.
  • Provide an objective perspective to IT operations in support of cybersecurity compliance, control effectiveness, and related improvement activities.
  • Coordinate compliance and audit activities with managed service providers.
  • Coordinate recurring surveillance and certification audits with corporate staff and external auditors, including annual ISO activities when required.
  • Maintain current knowledge of relevant standards, regulations, contractual requirements, and industry practices.
  • Perform other duties as assigned in support of corporate compliance, quality, and operational priorities.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service