Internal ISO Auditor

J. J. Keller & AssociatesNeenah, WI
Hybrid

About The Position

The Internal ISO Auditor supports the organization's audit, risk management, compliance, and information security programs. This role coordinates audits across multiple regulatory and industry frameworks, identifies and assesses risks, drives remediation efforts, and helps ensure compliance with customer, contractual, and regulatory requirements. Working cross-functionally with teams throughout the business, this position provides guidance on security and compliance best practices and contributes to the continuous improvement of governance, risk, and compliance processes. This position has the ability to work from home outside of the Fox Valley, WI area and would work hybrid if located within the Fox Valley, WI area.

Requirements

  • Bachelor’s degree in Business or related field required.
  • Minimum of 3 years of related auditing experience required, including exposure to information security controls.
  • Experience in addressing security and compliance terms in commercial contracts.
  • Experience with ISO 27001 and privacy frameworks and auditing to the frameworks.
  • Experience completing security questionnaires and evaluating vendor assessments.
  • Experience using GRC tools, such as Optro.
  • Outstanding interpersonal, written, and verbal communication and presentation skills.
  • Strong analytical, problem-solving, and conflict management skills.
  • A curious and practical mindset that can balance compliance with ethical and business needs.
  • Eager to gain a comprehensive understanding of the business.
  • Ability to work cross-functionally, with many teams, including sales, infrastructure, security, and product teams.
  • Ability to influence and lead business partners and supporting teams.

Responsibilities

  • Coordinates and conducts internal and external audits for SOC 2 Type II, ISO 27001, PCI-DSS, and other standards.
  • Evaluates audit results, recommends improvements, and issues deficiency notices as needed.
  • Evaluates, monitors and consults on resulting corrective action plans and remediation efforts.
  • Coordinates and manages the completion of penetration tests with external consultants and internal resources, and the development, implementation, and monitoring of related corrective action plans, and distribution of resulting reports to interested parties.
  • Reviews policies, guidance and training for information security, and provides consulting services promoting overall achievement of corporate security objectives and compliance with regulatory and customer requirements.
  • Maintains security incident response plans and metrics.
  • Leads evaluation of security incident reports, and execution of incident response efforts, including task management, resource coordination, after action reviews, and incident documentation.
  • Participates in business continuity efforts by assisting with annual security incident tabletop exercises and generating a post-exercise review.
  • Triages security policy exceptions.
  • Evaluates and consults on the business risks and proposed compensating controls.
  • Follows up on approved exceptions expiring.
  • Manages the Optro Governance, Risk & Compliance software platform, including creating audits, deploying audit questions, entering corrective actions, generating reports and monitoring completion status.

Benefits

  • Medical, Dental, and Vision Insurance
  • 401(k) and Profit Sharing Plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service