{"id":1539375,"url":"https://alion.io/job/bright-defense-internal-auditor-secops","title":"Internal Auditor – SecOps","company":{"id":1850073,"name":"Bright Defense","domain":"brightdefense.com","url":"https://alion.io/company/brightdefense","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Schema","truth_index":{"grade":"B","score":75,"open_postings":4,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-02T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"remote","remote_scope":"unspecified","remote_scope_basis":null,"remote_working_hours":{"label":"PT","utc_offset_min":-8,"utc_offset_max":-8},"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"NIST CSF","optional":false},{"name":"SOC 2","optional":false},{"name":"Asana","optional":true},{"name":"Google Workspace","optional":true}],"status":"live","first_seen_at":"2025-07-15T03:27:22Z","employer_posted_date":"2026-04-12","last_verified_at":"2026-10-01T07:17:58Z","board_verified":true,"closed_at":null,"days_open":444,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":444},"description":"Bright Defense · SecOps Team · Now Hiring\nInternal Auditor\nSecOps - Audit Readiness & Continuous Control Monitoring\nFull-TimeRemoteSecOpsAudit & GRC Focus\nYou’ll play a vital role in supporting our customers’ ongoing audit readiness and continuous monitoring efforts - reviewing controls, validating evidence, and keeping clients informed with clear, professional written communications every step of the way.\nAbout the role\nAs an Internal Auditor on the Bright Defense SecOps Team, you’ll review security controls, evidence, and documentation to ensure alignment with industry standards and best practices. You’ll collaborate primarily with internal team members across Governance, Security Consulting, Offensive Security, and other SecOps colleagues - while also preparing clear, detailed written reports that keep customers informed of audit progress, findings, and next steps.\nKey responsibilities\nAudit execution\nConduct internal audits of security controls and processes, verifying compliance with ISO 27001, SOC 2, NIST CSF, and applicable frameworks\nReview audit evidence, identify gaps, and coordinate remediation with internal stakeholders\nSupport audit readiness by validating control effectiveness ahead of customer external audits\nMaintain up-to-date records of audit findings, status, and corrective actions\nReporting & communication\nPrepare accurate, well-organized audit reports and status updates for customers\nCommunicate findings and remediation guidance in clear, professional written form\nEnsure customers stay informed of audit progress, open items, and next steps\nContribute to improving internal audit procedures, evidence checklists, and tracking systems\nProgram alignment & collaboration\nWork with Governance, Offensive Security, and SecOps to align audit activities with the overall security program\nParticipate in internal meetings to ensure audit tasks align with risk assessments and SecOps goals\nCoordinate remediation tracking across internal stakeholders and client POCs\nFlag emerging control gaps or compliance risks to the assigned Security Consultant\nCross-functional collaboration\nGovernance\nSecurity Consulting\nOffensive Security\nSecOps Functions\nRequirements\nExperience & frameworks\n3-4 years as a GRC Analyst or Internal Auditor in information security, compliance, or risk management\nFamiliarity with ISO 27001, SOC 2, NIST CSF, and related security frameworks\nStrong understanding of internal controls, audit processes, and evidence management\nExperience supporting regulated sectors (finance, healthcare, SaaS) a plus\nCommunication & organization\nExcellent written communication - clear, concise customer-facing audit reports are mandatory\nStrong organizational skills and attention to detail across multiple simultaneous audits\nProven ability to collaborate across technical and non-technical teams\nMust support US Eastern and Pacific time zones, 8AM-5PM\nNice to have\nISO 27001 Internal Auditor, CISA, CISM, or CISSP (Associate) certification\nFamiliarity with GRC platforms, security auditing tools, or evidence management software\nDrata, Vanta, Thoropass, or equivalent platform experience\nTools & platforms\nGRC platforms - Drata, Vanta, Thoropass, or equivalent\nAsana or similar PM tools for audit task tracking\nGoogle Workspace or Microsoft 365 proficiency\nEvidence management or checklist tooling experience\nWhy you’ll love this role\nPlay a critical part in helping customers maintain a strong, audit-ready security posture across real-world frameworks\nGain hands-on experience with SOC 2, ISO 27001, NIST CSF, and other compliance programs across diverse client verticals\nBe part of a collaborative SecOps team that values clear communication, trust, and continuous improvement\nCompensation & perks\nCompetitive base salary - range shared during screening\nRemote-first with flexible hours within the ET/PT coverage window\nCertification reimbursement (CISA, CISM, ISO 27001 Internal Auditor, and others)\nDirect collaboration with Bright Defense co-founders and SecOps leadership\nBroad client exposure across defense, healthcare, and fintech verticals\nClear path toward ISM or senior GRC roles as you grow\nBright Defense is an equal opportunity employer. We build diverse, high-trust teams. | brightdefense.com","description_format":"text","description_chars":4256,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Certification reimbursement"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Security Compliance"],"lifecycle":[{"event":"open","at":"2026-09-30T20:25:24Z"}],"liveness":{"score":4,"band":"cold","label":"Long shot","p_open":1,"p_active":0.134,"p_room":0.28,"age_days":444,"expected_fill_days":7,"reasons":["conf:22","win:tail","crowd:"],"computed_at":"2026-10-02T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/bright-defense-internal-auditor-secops","json_url":"https://alion.io/job/bright-defense-internal-auditor-secops.json","meta":{"generated_at":"2026-10-03T01:16:45Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1188,"day_limit":5000,"remaining_today":3812,"minute_limit":60,"resets_at":"2026-10-04T00:00:00Z"}}}