GRC Compliance Auditor

NorthMark StrategiesDallas, TX
Onsite

About The Position

NorthMark Compute & Cloud (NMC²) is seeking a detail-oriented GRC Compliance Auditor to join its Information Security team. This role is responsible for the day-to-day execution of NMC²’s SOC 2 Type II and ISO 27001 compliance programs, including readiness assessments, control mapping, evidence collection, and external audit coordination. The position serves as the primary administrator of the GRC platform, maintaining the control framework library, driving automated evidence collection, and generating compliance posture reports. The auditor will collaborate with control owners across various departments to translate regulatory requirements into practical controls and integrate audit readiness into daily operations. The ideal candidate possesses extensive experience with SOC 2 and ISO 27001, a keen ability to identify control gaps, and strong communication skills to guide stakeholders through audit processes.

Requirements

  • Bachelor’s degree in Information Systems, Computer Science, Business Administration, or a related field — or equivalent experience.
  • 4–8 years of hands-on experience in GRC, IT audit, or information security compliance.
  • Demonstrated experience conducting or supporting SOC 2 Type II audits, including evidence collection, control testing, and auditor coordination.
  • Working knowledge of ISO 27001 / 27002 requirements, with experience supporting certification or surveillance audits.
  • Hands-on experience administering a GRC or compliance automation platform such as Vanta, Drata, Hyperproof, AuditBoard, or equivalent.
  • Ability to translate complex regulatory requirements into practical, implementable controls and evidence procedures.
  • Familiarity with identity and access management tooling (Entra ID, Okta, or equivalent) in the context of access reviews and compliance evidence.
  • Experience working with control owners across Engineering, IT, Legal, HR, and Operations to define and validate control procedures.
  • Strong written and verbal communication skills; comfortable presenting compliance findings to both technical and non-technical audiences.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Nice To Haves

  • One or more relevant certifications preferred: CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC.

Responsibilities

  • Lead internal audit cycles for SOC 2 Type II and ISO 27001, assessing the design and operating effectiveness of controls and identifying deficiencies for remediation.
  • Coordinate external audits end-to-end — scheduling walkthroughs, preparing evidence packages, managing auditor requests, and tracking findings through to validated closure.
  • Conduct readiness assessments and gap analyses across compliance frameworks, recommending remediation actions prioritized by risk and business impact.
  • Develop and maintain a cross-framework control library mapping SOC 2 TSC, ISO 27001 Annex A, NIST CSF, and other applicable standards to NMC²’s operational controls.
  • Serve as the primary administrator of the GRC and compliance automation platform — configuring control frameworks, evidence integrations, risk registers, and compliance dashboards.
  • Drive adoption of automated evidence collection via integrations with IdP, IGA, HR, and infrastructure systems to reduce manual audit overhead across the business.
  • Produce executive-ready compliance posture reports, control health metrics, and audit-readiness scorecards for leadership and board-level stakeholders.
  • Manage and track remediation of audit findings, exceptions, and risk acceptances, and conduct vendor and third-party risk assessments against SOC 2 and ISO 27001 requirements.
  • Develop audit readiness training, control owner guides, and playbooks to embed compliance awareness into day-to-day operations across Engineering, Product, and Operations teams.
  • Respond to customer security questionnaires and due diligence requests relating to audit certifications and NMC²’s compliance posture.

Benefits

  • Company-Paid Lunch Stipend via GrubHub
  • 100% Employer-Paid Medical in High Deductible Health Plan
  • Dental and Vision benefits for employees and their families
  • 16 weeks of Paid Parental Leave
  • Employee Assistance Program
  • Life insurance
  • Short-Term Disability and Long-Term Disability
  • 401(k) with Company match (100% of contributions up to 6%)
  • Optional Employee-Paid Benefits: Medical insurance in PPO plan, Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub
  • 25 days of Paid Time Off
  • 12 company holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service