Remote
Internal Auditor
About this role
Get to know the Internal Auditor Team At Workstreet, our Internal Audit team plays a critical role in helping organizations strengthen their security, compliance, and governance programs through independent and objective assurance services. We partner with clients across a wide range of international frameworks—including ISO 27001, ISO 42001, ISO 27701, SOC 2, HIPAA, GDPR, NIST, and other industry standards—to evaluate the design and effectiveness of their controls.
Working in a fast-paced, global environment, our team delivers high-quality, risk-based audits while collaborating closely with customers, Customer Success Managers, and GRC Consultants. If you are passionate about cybersecurity, compliance, and making a meaningful impact by helping organizations improve their security posture, you'll fit right in with our team. The Opportunity We are seeking a detail-oriented and proactive Internal Auditor to join our compliance team.
This role is ideal for someone with a strong understanding of information security and compliance frameworks, paired with excellent project management and analytical skills. You will be responsible for reviewing and validating control evidence within any GRC platform to ensure ongoing compliance with standards such as ISO 27001, ISO 42001, HIPAA, and GDPR. What you'll do Validate Compliance Evidence: Review, assess, and verify documentation and control evidence within the GRC platform (Vanta or any platform that the client utilizes) to confirm alignment with ISO 27001, ISO 42001, HIPAA, and GDPR requirements.
Conduct Internal Audits: Coordinate internal audits and readiness assessments to identify control gaps and recommend effective remediation actions. Communicate Audit Insights: Provide clear, timely updates and expectations to internal teams regarding audit timelines, deliverables, and compliance outcomes. Who you are Proven GRC and compliance auditor - Command 2–5 years of active execution in internal auditing, information security compliance, or Governance, Risk, and Compliance (GRC) roles, with a documented history of constructing and defending rigorous compliance programs.
Framework translation architect - Mastered the execution and structural demands of international standards including ISO 27001, ISO 42001, HIPAA, and GDPR, expertly converting dense regulatory clauses into practical, technical security controls. GRC automation driver - Deployed and managed automated evidence collection, continuous control monitoring, and real-time audit readiness directly within modern compliance applications, explicitly leveraging Vanta or equivalent platforms.