About Workstreet
At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the Internal Auditor Team
- At Workstreet, our Internal Audit team plays a critical role in helping organizations strengthen their security, compliance, and governance programs through independent and objective assurance services. We partner with clients across a wide range of international frameworks—including ISO 27001, ISO 42001, ISO 27701, SOC 2, HIPAA, GDPR, NIST, and other industry standards—to evaluate the design and effectiveness of their controls. Working in a fast-paced, global environment, our team delivers high-quality, risk-based audits while collaborating closely with customers, Customer Success Managers, and GRC Consultants. If you are passionate about cybersecurity, compliance, and making a meaningful impact by helping organizations improve their security posture, you'll fit right in with our team.
The Opportunity
- We are seeking a detail-oriented and proactive Internal Auditor to join our compliance team. This role is ideal for someone with a strong understanding of information security and compliance frameworks, paired with excellent project management and analytical skills. You will be responsible for reviewing and validating control evidence within any GRC platform to ensure ongoing compliance with standards such as ISO 27001, ISO 42001, HIPAA, and GDPR.
What you'll do
- Validate Compliance Evidence: Review, assess, and verify documentation and control evidence within the GRC platform (Vanta or any platform that the client utilizes) to confirm alignment with ISO 27001, ISO 42001, HIPAA, and GDPR requirements.
- Conduct Internal Audits: Coordinate internal audits and readiness assessments to identify control gaps and recommend effective remediation actions.
- Communicate Audit Insights: Provide clear, timely updates and expectations to internal teams regarding audit timelines, deliverables, and compliance outcomes.
Who you are
- Proven GRC and compliance auditor - Command 2–5 years of active execution in internal auditing, information security compliance, or Governance, Risk, and Compliance (GRC) roles, with a documented history of constructing and defending rigorous compliance programs.
- Framework translation architect - Mastered the execution and structural demands of international standards including ISO 27001, ISO 42001, HIPAA, and GDPR, expertly converting dense regulatory clauses into practical, technical security controls.
- GRC automation driver - Deployed and managed automated evidence collection, continuous control monitoring, and real-time audit readiness directly within modern compliance applications, explicitly leveraging Vanta or equivalent platforms.
- Disciplined audit portfolio manager - Systematically orchestrate and execute multiple fast-moving compliance initiatives simultaneously, balancing competing testing parameters while aggressively crushing strict audit deadlines.
- Cross-functional alignment engine - Deliver authoritative, precision-focused written and verbal English communication that seamlessly bridges the gaps between deep engineering teams, customer success, and corporate leadership.
- Surgical gap analyst - Apply micro-level critical analysis to isolate design flaws in control documentation, expose hidden compliance deficiencies, and construct airtight remediation roadmaps before external audits.
- Credentialed industry professional - Hold or actively pursue technical designations such as CPA, CIA, CISA, or ISO Lead Auditor to validate your command of advanced compliance governance.
What help you succeed
- Tenure scaling within B2B SaaS - Prior success navigating hyper-growth cloud software architectures, subscription environments, and digital compliance automation frameworks.
- Direct mastery of IT risk management - Active exposure to foundational information security protocols, network vulnerability testing parameters, and technical access control schemas.
- Execution of evidence-backed audit programs - Direct experience auditing complex system logs, validating technical evidence parameters, and engineering flawless procedural process documentation.
What we offer
- Career Development: Clear path with mentorship and training opportunities.
- Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What you'll need to thrive
- Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
- A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
- Commitment to working a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners while ensuring timely communication and support.
- Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process
- Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
- Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
- Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
- Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
Workstreet Is An Equal Opportunity Employer
As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.