1

Iso 27001 Jobs (NOW HIRING)

GRC Compliance Auditor

Dallas, TX

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

This role owns the day-to-day execution of NMC's SOC 2 Type II and ISO 27001 compliance programmes - from readiness assessments and control mapping through to evidence collection and external audit ...

Design a control framework synergistic across ITGC, SOC 2, ISO 27001, and NIST 800-171 / CMMC scopes * Serve as the primary IT liaison to external auditors and readiness advisors * Mature incident ...

NY · On-site

$93.19 - $124.26/hr

Tieto Nexus Indtech söker Security Compliance Manager i Solna. Fokus på GRC, DORA, NIS2, ISO 27001/ISAE 3402, revisioner, RFI/RFP och leverantörssäkerhet Sök nu Ny tjänst: Tieto söker Security ...

Sr IT Analyst - Security

Brentwood, TN · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

ISO 27001 & NIST Control Framework * Serve as a trusted internal subject-matter expert (SME) for the ISO 27001 Information Security Management System (ISMS), providing strategic guidance on ...

Sr IT Analyst - Security

Brentwood, TN

  • Medical

  • Dental

  • Vision

  • Retirement

ISO 27001 & NIST Control Framework * Serve as a trusted internal subject-matter expert (SME) for the ISO 27001 Information Security Management System (ISMS), providing strategic guidance on ...

Sr IT Analyst - Security

Brentwood, TN

  • Medical

  • Dental

  • Vision

  • Retirement

ISO 27001 & NIST Control Framework * Serve as a trusted internal subject-matter expert (SME) for the ISO 27001 Information Security Management System (ISMS), providing strategic guidance on ...

Senior IT Security Engineer

OR · On-site +1

$130K - $155K/yr

  • Medical

  • Dental

  • Retirement

You will drive ISO 27001 certification and SOC 2 Type II attestation initiatives end-to-end - from initial gap analysis and control design through evidence collection, audit coordination, and ...

Sr. Program Manager

$40 - $60/hr

  • Medical

  • Dental

  • Vision

ISO 27001 experience * Excellent writing skills * Ability to work independently. Nice to have: * ISO 27001 Lead Auditor or other ISO training. * Experience working with clients before. * CISA, CISSP ...

Senior IT Security Engineer

$130K - $155K/yr

  • Medical

  • Dental

  • Retirement

You will drive ISO 27001 certification and SOC 2 Type II attestation initiatives end-to-end - from initial gap analysis and control design through evidence collection, audit coordination, and ...

Showing results 41-60

Iso 27001 information

See salary details

$43K

$106.7K

$159.5K

How much do iso 27001 jobs pay per year?

As of Aug 16, 2026, the average yearly pay for iso 27001 in the United States is $106,734.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,000.00 and $124,000.00 per year, depending on experience, location, and employer.

How do you become ISO 27001 certified?

To become ISO 27001 certified, an organization must implement an Information Security Management System (ISMS) aligned with ISO 27001 standards, conduct a thorough internal audit, and then undergo a certification audit by an accredited certification body. For professionals, gaining knowledge through ISO 27001 training and certification can enhance expertise in managing information security compliance.

What are typical responsibilities for someone working in an ISO 27001 role?

Professionals in ISO 27001 roles are often responsible for developing, implementing, and maintaining an organization's information security management system (ISMS) in line with the ISO 27001 standard. This usually involves conducting risk assessments, developing and enforcing security policies and procedures, training staff on security awareness, and leading internal or external audits. Collaboration with IT, compliance, and business units is common to ensure security objectives are aligned with broader organizational goals. Many professionals also document processes and manage corrective actions to address security gaps. These responsibilities help ensure continual compliance and the ongoing effectiveness of the ISMS.

What is an ISO 27001?

An ISO 27001 job typically involves implementing, managing, and maintaining an organization's Information Security Management System (ISMS) based on the ISO/IEC 27001 standard. Professionals in this role ensure compliance with security policies, conduct risk assessments, and implement controls to protect sensitive data. They may work as ISO 27001 auditors, consultants, or compliance managers, focusing on securing information assets and improving cybersecurity practices.

What are the key skills and qualifications needed to thrive in the ISO 27001 position, and why are they important?

To thrive as an ISO 27001 Consultant or Lead Implementer, you need a solid understanding of information security management systems, risk assessment, and compliance best practices, typically backed by ISO 27001 certification. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms and knowledge of IT audit methodologies is highly beneficial. Strong problem-solving, communication, and project management skills help bridge technical requirements and business needs. These abilities are crucial to ensure organizations maintain compliance, manage risks effectively, and build robust information security frameworks.

More about Iso 27001 jobs

What are the most commonly searched types of Iso 27001 jobs?

The most popular types of Iso 27001 jobs are:

What states have the most Iso 27001 jobs?

States with the most job openings for Iso 27001 jobs include:

Infographic showing various Iso 27001 job openings in the United States as of August 2026, with employment types broken down into 22% Full Time, 22% Part Time, and 56% Contract. Highlights an 78% In-person, and 22% Remote job distribution, with an average salary of $106,734 per year, or $51.3 per hour.

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 24 days ago


Job description

THE COMPANY

NorthMark Compute & Cloud (NMC) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients' research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.

THE POSITION

NMC is looking for a detail-oriented GRC Compliance Auditor to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons. This role owns the day-to-day execution of NMC's SOC 2 Type II and ISO 27001 compliance programmes - from readiness assessments and control mapping through to evidence collection and external audit coordination.

You will serve as the primary administrator of our GRC platform, maintaining the control framework library, driving automated evidence collection, and producing compliance posture reporting for leadership. You will work closely with control owners across Engineering, IT, HR, Legal, and Operations - translating regulatory requirements into practical controls and embedding audit readiness into how teams operate day to day.

The right candidate brings deep hands-on experience with SOC 2 and ISO 27001, a sharp eye for control gaps, and the communication skills to guide both technical and non-technical stakeholders through audit processes without disrupting the business.

RESPONSIBILITIES

  • Lead internal audit cycles for SOC 2 Type II and ISO 27001, assessing the design and operating effectiveness of controls and identifying deficiencies for remediation.
  • Coordinate external audits end-to-end - scheduling walkthroughs, preparing evidence packages, managing auditor requests, and tracking findings through to validated closure.
  • Conduct readiness assessments and gap analyses across compliance frameworks, recommending remediation actions prioritized by risk and business impact.
  • Develop and maintain a cross-framework control library mapping SOC 2 TSC, ISO 27001 Annex A, NIST CSF, and other applicable standards to NMC's operational controls.
  • Serve as the primary administrator of the GRC and compliance automation platform - configuring control frameworks, evidence integrations, risk registers, and compliance dashboards.
  • Drive adoption of automated evidence collection via integrations with IdP, IGA, HR, and infrastructure systems to reduce manual audit overhead across the business.
  • Produce executive-ready compliance posture reports, control health metrics, and audit-readiness scorecards for leadership and board-level stakeholders.
  • Manage and track remediation of audit findings, exceptions, and risk acceptances, and conduct vendor and third-party risk assessments against SOC 2 and ISO 27001 requirements.
  • Develop audit readiness training, control owner guides, and playbooks to embed compliance awareness into day-to-day operations across Engineering, Product, and Operations teams.
  • Respond to customer security questionnaires and due diligence requests relating to audit certifications and NMC's compliance posture.

REQUIREMENTS

  • Bachelor's degree in Information Systems, Computer Science, Business Administration, or a related field - or equivalent experience.
  • 4-8 years of hands-on experience in GRC, IT audit, or information security compliance.
  • Demonstrated experience conducting or supporting SOC 2 Type II audits, including evidence collection, control testing, and auditor coordination.
  • Working knowledge of ISO 27001 / 27002 requirements, with experience supporting certification or surveillance audits.
  • Hands-on experience administering a GRC or compliance automation platform such as Vanta, Drata, Hyperproof, AuditBoard, or equivalent.
  • Ability to translate complex regulatory requirements into practical, implementable controls and evidence procedures.
  • Familiarity with identity and access management tooling (Entra ID, Okta, or equivalent) in the context of access reviews and compliance evidence.
  • Experience working with control owners across Engineering, IT, Legal, HR, and Operations to define and validate control procedures.
  • Strong written and verbal communication skills; comfortable presenting compliance findings to both technical and non-technical audiences.
  • One or more relevant certifications preferred: CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC.

It is impossible to list every requirement for, or responsibility of, any position. Similarly, we cannot identify all the skills a position may require since job responsibilities and the Company's needs may change over time. Therefore, the above job description is not comprehensive or exhaustive. The Company reserves the right to adjust, add to or eliminate any aspect of the above description. The Company also retains the right to require all employees to undertake additional or different job responsibilities when necessary to meet business needs.

Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Benefits & Perks:

  • Company-Paid Lunch Stipend: Lunch is provided via GrubHub

  • Company-Paid Benefits: 100% Employer-Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families, 16 weeks of Paid Parental Leave, Employee Assistance Program, Life insurance, Short-Term Disability and Long-Term Disability

  • 401(k): Company will match 100% of your contributions up to 6%

  • Optional Employee-Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.

  • Time Off: 25 days of Paid Time Off plus 12 company holidays


EQUAL OPPORTUNITY EMPLOYER

NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER. THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS, MENTAL OR PHYSICAL DISABILITY, AND GENETIC INFORMATION, OR ANY OTHER BASIS PROTECTED BY APPLICABLE LAW. THE FIRM ALSO PROHIBITS HARASSMENT OF APPLICANTS OR EMPLOYEES BASED ON ANY OF THESE PROTECTED CATEGORIES.