1,103,002open jobs
64,065companies
186,136added this week
Browse all
Location
Remote (location not specified, PT hours)
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Jul 15, 2025. Bright Defense scores B on the Alion truth index.

Overview
Company
Impact
Profile match
We provide managed SOC 2, ISO 27001, HIPAA, and CMMC compliance services for small and mid-size businesses through CISSP certified experts.

Bright Defense · SecOps Team · Now Hiring

Internal Auditor

SecOps - Audit Readiness & Continuous Control Monitoring

Full-TimeRemoteSecOpsAudit & GRC Focus

You’ll play a vital role in supporting our customers’ ongoing audit readiness and continuous monitoring efforts - reviewing controls, validating evidence, and keeping clients informed with clear, professional written communications every step of the way.

About the role

As an Internal Auditor on the Bright Defense SecOps Team, you’ll review security controls, evidence, and documentation to ensure alignment with industry standards and best practices. You’ll collaborate primarily with internal team members across Governance, Security Consulting, Offensive Security, and other SecOps colleagues - while also preparing clear, detailed written reports that keep customers informed of audit progress, findings, and next steps.

Key responsibilities

Audit execution

  • Conduct internal audits of security controls and processes, verifying compliance with ISO 27001, SOC 2, NIST CSF, and applicable frameworks
  • Review audit evidence, identify gaps, and coordinate remediation with internal stakeholders
  • Support audit readiness by validating control effectiveness ahead of customer external audits
  • Maintain up-to-date records of audit findings, status, and corrective actions

Reporting & communication

  • Prepare accurate, well-organized audit reports and status updates for customers
  • Communicate findings and remediation guidance in clear, professional written form
  • Ensure customers stay informed of audit progress, open items, and next steps
  • Contribute to improving internal audit procedures, evidence checklists, and tracking systems

Program alignment & collaboration

  • Work with Governance, Offensive Security, and SecOps to align audit activities with the overall security program
  • Participate in internal meetings to ensure audit tasks align with risk assessments and SecOps goals
  • Coordinate remediation tracking across internal stakeholders and client POCs
  • Flag emerging control gaps or compliance risks to the assigned Security Consultant

Cross-functional collaboration

Governance

Security Consulting

Offensive Security

SecOps Functions

Requirements

Experience & frameworks

  • 3-4 years as a GRC Analyst or Internal Auditor in information security, compliance, or risk management
  • Familiarity with ISO 27001, SOC 2, NIST CSF, and related security frameworks
  • Strong understanding of internal controls, audit processes, and evidence management
  • Experience supporting regulated sectors (finance, healthcare, SaaS) a plus

Communication & organization

  • Excellent written communication - clear, concise customer-facing audit reports are mandatory
  • Strong organizational skills and attention to detail across multiple simultaneous audits
  • Proven ability to collaborate across technical and non-technical teams
  • Must support US Eastern and Pacific time zones, 8AM-5PM

Nice to have

  • ISO 27001 Internal Auditor, CISA, CISM, or CISSP (Associate) certification
  • Familiarity with GRC platforms, security auditing tools, or evidence management software
  • Drata, Vanta, Thoropass, or equivalent platform experience

Tools & platforms

  • GRC platforms - Drata, Vanta, Thoropass, or equivalent
  • Asana or similar PM tools for audit task tracking
  • Google Workspace or Microsoft 365 proficiency
  • Evidence management or checklist tooling experience

Why you’ll love this role

Play a critical part in helping customers maintain a strong, audit-ready security posture across real-world frameworks

Gain hands-on experience with SOC 2, ISO 27001, NIST CSF, and other compliance programs across diverse client verticals

Be part of a collaborative SecOps team that values clear communication, trust, and continuous improvement

Compensation & perks

  • Competitive base salary - range shared during screening
  • Remote-first with flexible hours within the ET/PT coverage window
  • Certification reimbursement (CISA, CISM, ISO 27001 Internal Auditor, and others)
  • Direct collaboration with Bright Defense co-founders and SecOps leadership
  • Broad client exposure across defense, healthcare, and fintech verticals
  • Clear path toward ISM or senior GRC roles as you grow

Bright Defense is an equal opportunity employer. We build diverse, high-trust teams. | brightdefense.com

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,103,002 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
≈ $56k – $142k per year (Estimated) • Remote (Spain) • Full-Time • Bachelor's Degree • Seville
Apply
$96k – $181k per year • Remote (United States) • Full-Time • 8+ years exp • Bachelor's Degree • United States
DevOps
Prometheus
Cortex
Incident Management
Cybersecurity
MITRE ATT&CK
NIST CSF
Cortex XSOAR
SIEM
Management
ServiceNow
ITIL
Apply
$160k – $180k per year • Remote (United States) • 6+ years exp
Python
Java
TypeScript
AI/ML
AI Agents
LLM
LLM Guardrails
NIST AI RMF
DevOps
Terraform
CI/CD
Jenkins
AWS
Kubernetes
Amazon EKS
GitHub
Cybersecurity
Burp Suite
Snyk
Semgrep
ISO 27001
NIST CSF
OWASP Top 10
SOC 2
OWASP ASVS
OWASP SAMM
CVE
Threat Modeling
SBOM
SLSA
OWASP
Apply
≈ $37k – $91k per year (Estimated) • Remote (Argentina) • Buenos Aires
Cybersecurity
ISO 27001
Analytics
Informatica
Apply
≈ $68k – $137k per year (Estimated) • Remote (United States) • Secret • 2+ years exp • High School Diploma
DevOps
Terraform
Red Hat
OpenShift
Rancher
CloudFormation
GitLab CI
CI/CD
ArgoCD
Jenkins
AWS
Docker
Kubernetes
Amazon EKS
AWS Fargate
GitLab
Linux
DNS
Cybersecurity
HashiCorp Vault
Management
Agile
Apply
≈ $126k – $248k per year (Estimated) • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Santa Clara
AI/ML
Copilot
ChatGPT
Model Context Protocol
EU AI Act
NIST AI RMF
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Apply
≈ $73k – $168k per year (Estimated) • Hybrid • London
AI/ML
DPO
Cybersecurity
ISO 27001
Microsoft Defender
SOC 2
GDPR
HIPAA
Least Privilege
Microsoft Entra ID
DLP
Apply
$50k – $59k per year • In office • Full-Time • Bachelor's Degree • Lisbon
Cybersecurity
ISO 27001
NIST CSF
Apply
Hybrid • 8+ years exp • Master's Degree
DevOps
TCP/IP
MPLS
Cybersecurity
ISO 27001
GDPR
Apply
≈ $34k – $81k per year (Estimated) • In office • Contractor • Singapore
PowerShell
DevOps
IAM
TCP/IP
DNS
DHCP
VPN
Cybersecurity
Wireshark
Zscaler
SOC 2
GDPR
HIPAA
Zero Trust
Least Privilege
Microsoft Entra ID
Management
Service Desk
Apply
≈ $75k – $161k per year (Estimated) • Remote (United States) • Full-Time • 3+ years exp
DevOps
GCP
Azure
AWS
SLI/SLO/SLA
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
HIPAA
Management
Asana
Slack
Google Workspace
Apply
GRC Analyst – SecOps 6 months ago
≈ $58k – $135k per year (Estimated) • Remote (location not specified, PT hours) • Full-Time • 2+ years exp
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Management
Asana
Google Workspace
Apply
≈ $76k – $165k per year (Estimated) • Remote (likely United States) • Full-Time • 5+ years exp • Bachelor's Degree
DevOps
IAM
Cybersecurity
ISO 27001
PCI DSS
SOC 2
HIPAA
NIST 800-53
NIST 800-171
Apply
≈ $74k – $164k per year (Estimated) • Remote (location not specified) • Full-Time • 5+ years exp
Python
PowerShell
AI/ML
LLM
Red Teaming
LLM Guardrails
Frontend
GraphQL
DevOps
Rest API
GCP
Azure
CI/CD
AWS
Cybersecurity
Burp Suite
Metasploit
Nmap
ISO 27001
OWASP Top 10
PCI DSS
SOC 2
HIPAA
Threat Modeling
MobSF
Frida
Objection
OWASP
Apply
See all jobs
This is one of many
1,103,002 more open roles from verified company boards, updated every day.