Nomixa GlobalHaley Noel, CISA

About Haley

Cybersecurity, audit, risk, and compliance experience from several sides of the business.

I've spent my career working across external audit, enterprise internal audit, technology controls, cybersecurity risk, and GRC technology. That experience has meant evaluating how controls are designed, testing whether they actually work, understanding where risk exists, working with stakeholders across a business, and helping translate technical or regulatory requirements into something teams can realistically operate day to day.

CISA · Management Information Systems

Nomixa Global is the independent practice I created to bring that experience directly to organizations that need practical support with audit, controls, risk, compliance, and GRC. Connect on LinkedIn.

My Path Here

I've worked on the same problems from very different perspectives.

  1. External Audit

    360 Advanced

    Working in external audit gave me my foundation in controls, evidence, testing, documentation, and audit methodology. I worked across client environments and industries, evaluating technology controls, reviewing evidence, identifying gaps, communicating findings, and seeing firsthand what organizations need to demonstrate when an independent auditor is examining their environment.

  2. Enterprise Internal Audit

    FIS

    At FIS, I moved inside a large global enterprise and saw the other side of the audit relationship. My work covered IT audit, IT general controls, cybersecurity, technology risk, and security-focused areas of the organization. That meant understanding not only whether a control could pass a test, but how it operated within real systems, teams, processes, ownership structures, and competing business priorities. I worked with stakeholders across technology and the business, evaluated control design and operating effectiveness, documented and communicated findings, and developed a much stronger understanding of how risk and controls function inside a complex organization.

  3. GRC Technology

    eramba

    Working with a GRC software company gave me another perspective: what happens after an organization decides it needs a formal GRC program and has to make the technology support the work. I gained exposure to how organizations structure GRC processes, how teams use platforms day to day, where implementations become unnecessarily complicated, what customers actually need from GRC technology, and the gap that can exist between a technically capable platform and a program people can realistically maintain.

  4. Independent Advisory

    Nomixa Global

    Nomixa Global brings those perspectives together into independent advisory work. I can work directly with organizations on the problems that sit between audit expectations, security requirements, business operations, and the reality of actually maintaining a program. That can include assessing current controls, preparing for an audit, identifying gaps, improving documentation and evidence practices, strengthening ITGCs, evaluating risk, supporting GRC program development, helping make better use of GRC technology, or providing experienced support when a team needs additional capacity.

That progression has given me a practical view of the entire lifecycle. I understand what an external auditor is looking for, how an internal audit team evaluates risk, how controls have to operate inside the business, how evidence and documentation hold up under review, how teams interact with GRC technology, and where theoretically sound programs start to break down in day-to-day operations.

Why Nomixa

I created Nomixa Global because I wanted a way to work directly with organizations on the problems that do not always fit neatly into a job description, an audit request list, or a software implementation.

Across external audit, internal audit, cybersecurity, controls, and GRC technology, I kept seeing versions of the same problem. Knowing what a framework, auditor, customer, or regulator expects is one thing. Turning those expectations into clear ownership, workable controls, useful documentation, reliable evidence, and processes people can actually maintain is much harder.

That is the kind of work I want Nomixa to help with. Sometimes that means preparing for an audit. Sometimes it means untangling a control environment, assessing risk, improving an existing GRC program, helping a team make better use of its technology, or simply bringing an experienced outside perspective to a problem that has become difficult to solve internally.

Compliance should work inside the business, not just on paper.

Areas of Experience

Experience I bring into advisory work.

Audit & Assurance

Internal AuditExternal AuditCybersecurity AuditAudit ReadinessAudit Remediation

Controls & Risk

IT General Controls (ITGCs)Control DesignControl TestingTechnology RiskRisk AssessmentsThird-Party Risk

GRC & Compliance

Governance, Risk & ComplianceCybersecurity ComplianceSOC 2 ReadinessGRC Program DevelopmentGRC TechnologyEvidence & Documentation Practices

Communication

Stakeholder CommunicationExecutive Communication

Outside of Work

I'm a competitive sailboat racer. It's demanding, occasionally humbling, and about as far from a laptop as I can get, which is exactly the point.

Have a problem worth solving?

If you're working through an audit, control, cybersecurity, risk, compliance, or GRC challenge and could use an experienced outside perspective, I'd be happy to talk. I'm available for consulting projects, advisory engagements, fractional support, and situations where a team simply needs additional expertise or capacity.