About Haley

Cybersecurity, audit, risk, and compliance experience from several sides of the business.

I've spent my career working across external audit, enterprise internal audit, technology controls, cybersecurity risk, and GRC technology: evaluating how controls are designed, testing whether they actually work, and translating technical or regulatory requirements into something teams can realistically operate day to day.

CISA · Management Information SystemsConnect on LinkedIn
Haley Noel, CISA, founder of Nomixa Global
Haley NoelCISA · St. Petersburg, FL
My Path Here

I've worked on the same problems from very different perspectives.

  1. 01

    External Audit

    Working in external audit gave me my foundation in controls, evidence, testing, documentation, and audit methodology. I worked across client environments and industries, evaluating technology controls, reviewing evidence, identifying gaps, communicating findings, and seeing firsthand what organizations need to demonstrate when an independent auditor is examining their environment.

  2. 02

    Enterprise Internal Audit

    I then moved inside a large global enterprise and saw the other side of the audit relationship. My work covered IT audit, IT general controls, cybersecurity, technology risk, and security-focused areas of the organization. That meant understanding not only whether a control could pass a test, but how it operated within real systems, teams, processes, ownership structures, and competing business priorities.

  3. 03

    GRC Technology

    Working with a GRC software company gave me another perspective: what happens after an organization decides it needs a formal GRC program and has to make the technology support the work. I saw how teams use platforms day to day, where implementations become unnecessarily complicated, and the gap between a technically capable platform and a program people can realistically maintain.

  4. 04

    Independent Advisory

    Nomixa Global brings those perspectives together into independent advisory work. I work directly with organizations on the problems that sit between audit expectations, security requirements, business operations, and the reality of actually maintaining a program, and, through the partnership with Voreli AI, on adopting AI in a way that will pass the next audit.

That progression has given me a practical view of the entire lifecycle. I understand what an external auditor is looking for, how an internal audit team evaluates risk, how controls have to operate inside the business, how evidence and documentation hold up under review, how teams interact with GRC technology, and where theoretically sound programs start to break down in day-to-day operations.

Why Nomixa

Compliance should work inside the business, not just on paper.

I created Nomixa Global because I wanted a way to work directly with organizations on the problems that do not always fit neatly into a job description, an audit request list, or a software implementation.

Across external audit, internal audit, cybersecurity, controls, and GRC technology, I kept seeing versions of the same problem. Knowing what a framework, auditor, customer, or regulator expects is one thing. Turning those expectations into clear ownership, workable controls, useful documentation, reliable evidence, and processes people can actually maintain is much harder.

That is the kind of work I want Nomixa to help with. Sometimes that means preparing for an audit. Sometimes it means untangling a control environment, assessing risk, improving an existing GRC program, helping a team make better use of its technology, or bringing an experienced outside perspective to a problem that has become difficult to solve internally.

Areas of Experience

Experience I bring into advisory work.

Audit & Assurance

Internal AuditExternal AuditCybersecurity AuditAudit ReadinessAudit Remediation

Controls & Risk

IT General Controls (ITGCs)Control DesignControl TestingTechnology RiskRisk AssessmentsThird-Party Risk

GRC & Compliance

Governance, Risk & ComplianceCybersecurity ComplianceSOC 2 ReadinessGRC Program DevelopmentGRC TechnologyEvidence & Documentation Practices

AI & Communication

AI Governance & RiskAI Audit AutomationStakeholder CommunicationExecutive Communication
Outside of Work

Competitive sailboat racer.

It's demanding, occasionally humbling, and about as far from a laptop as I can get, which is exactly the point.

Have a problem worth solving?

I'm available for consulting projects, advisory engagements, fractional support, and situations where a team simply needs additional expertise or capacity.