1

Cisa Auditor Jobs in Puerto Rico (NOW HIRING)

PR · On-site

If you are dedicated and eager to grow your auditing career, we will provide you with a supportive ... Certification (preferred) includes CISSP, Security+, CISA Castro Puerto Rico is a Professional ...

Certified Information Systems Auditor (CISA) * Certified in Risk and Information Systems Control (CRISC) * Project Management Professional (PMP) * Certified Information Privacy Professional (CIPP ...

Certifications such as CISA, CRISC, or other related certifications are highly valued. 3 to 5 years of work experience in areas such as IT auditing, change management, information systems, or ...

Cisa Auditor information

What does a CISA auditor do?

A CISA (Certified Information Systems Auditor) performs audits of information systems to assess their security, compliance, and controls. They evaluate IT infrastructure, develop audit reports, and ensure organizations adhere to cybersecurity standards using tools like audit software and frameworks. CISA auditors often work in risk management and compliance environments, requiring strong analytical skills and knowledge of IT governance.

How much do CISA auditors make?

CISA auditors typically earn between $70,000 and $120,000 annually, depending on experience, location, and certifications. Senior auditors with specialized skills or in high-demand areas can earn higher salaries, often exceeding $130,000.

What is a CISA Auditor job?

A CISA (Certified Information Systems Auditor) Auditor is a professional responsible for assessing and evaluating an organization's information systems, ensuring they are secure, reliable, and compliant with industry regulations. They conduct audits to identify risks, test controls, and recommend improvements to protect data and IT infrastructure. CISA Auditors often work in IT governance, risk management, and compliance roles, helping organizations safeguard sensitive information. Their expertise is essential in maintaining cybersecurity and operational efficiency.

Is CISA harder than CIA?

The CISA (Certified Information Systems Auditor) certification focuses on IT auditing, controls, and security, while the CIA (Certified Internal Auditor) covers broader internal audit practices. Generally, CISA is considered more technical and specialized, often requiring knowledge of information systems and cybersecurity tools, whereas CIA emphasizes internal controls and governance. The difficulty depends on your background and experience in IT versus internal auditing.

What are the key skills and qualifications needed to thrive in the Cisa Auditor position, and why are they important?

To thrive as a CISA Auditor, you need a solid understanding of information systems auditing, risk assessment, and IT governance, typically backed by a bachelor’s degree in IT, accounting, or a related field and the Certified Information Systems Auditor (CISA) certification. Familiarity with industry frameworks such as COBIT, ISO 27001, and auditing tools like ACL or IDEA is essential for effectively conducting audits. Strong analytical skills, attention to detail, clear communication, and the ability to work collaboratively are vital soft skills in this role. These competencies ensure effective identification of risks, compliance with standards, and clear reporting to stakeholders, supporting the integrity of IT systems.

Is CISA an entry level job?

CISA (Certified Information Systems Auditor) is a certification for experienced IT auditors and cybersecurity professionals, not an entry-level position. Most roles requiring a CISA certification typically require several years of work experience in information systems auditing, control, or security. Entry-level positions in cybersecurity or IT auditing may require foundational certifications or skills but usually do not require a CISA certification itself.

What are some common challenges faced by CISA Auditors in their daily work?

CISA Auditors often face challenges such as keeping up with rapidly evolving technology, balancing multiple audits or projects simultaneously, and effectively communicating complex technical findings to non-technical stakeholders. They must learn to adapt quickly to different organizational environments and varying levels of IT maturity across clients or departments. Successful auditors proactively stay current with industry trends, collaborate closely with IT and business teams, and develop strong organizational skills to manage tight deadlines. Overcoming these challenges not only strengthens audit quality but also contributes to career growth and expertise in the field.

What are popular job titles related to Cisa Auditor jobs in Puerto Rico? For Cisa Auditor jobs in Puerto Rico, the most frequently searched job titles are:
What job categories do people searching Cisa Auditor jobs in Puerto Rico look for? The top searched job categories for Cisa Auditor jobs in Puerto Rico are:
Infographic showing various Cisa Auditor job openings in Puerto Rico as of July 2026, with employment types broken down into 88% Full Time, 9% Part Time, 2% Contract, and 1% Nights. Highlights an 89% Physical, 5% Hybrid, and 6% Remote job distribution.
NIST Security Control Assessor

NIST Security Control Assessor

Castro & Company, LLC

PR • On-site

Full-time

Posted 2 days ago


Job description

Nist Security Control Assessor
We are currently seeking a NIST 800-53 Security Control Assessor interested in starting a rewarding career in public accounting by joining our Information Technology (IT) practice to serve our federal clients. If you are dedicated and eager to grow your auditing career, we will provide you with a supportive team, resources, and training to succeed.
As a Security Control Assessor your responsibilities will include:
  • Perform independent assessments of security controls in accordance with NIST SP 800-53 and NIST SP 800-53A
  • Evaluate the design and operating effectiveness of technical, operational, and management controls across federal information systems
  • Develop and execute Security Assessment Plans (SAPs), including test procedures, sampling approaches, and evidence requirements
  • Conduct control testing activities (interviews, documentation review, and technical validation) in alignment with Risk Management Framework (RMF)
  • Analyze assessment results to identify control deficiencies, gaps, and risk exposures
  • Document findings with clear risk statements, root cause analysis, and recommended remediation actions
  • Prepare Security Assessment Reports (SARs) and present results to Authorizing Officials (AOs), system owners, and stakeholders
  • Support Authorization to Operate (ATO) processes, including control validation and continuous monitoring activities
  • Collaborate with system owners, ISSOs, and engineering teams to validate remediation efforts and perform re-testing
  • Maintain assessment documentation within GRC tools (e.g., ServiceNow)
  • Stay current with evolving federal cybersecurity requirements, including FISMA and OMB/NIST guidance
  • Contribute to audit readiness and compliance initiatives across client environments
Requirements:
  • Must have Bachelor’s Degree in an IT- related degree from an accredited school.
  • Must be able to obtain Security Clearance: Must be able to pass a basic government suitability check (US Citizenship required).
  • Must have 5-8 Years of technical experience NIST 800-53 assessments.
  • Must have strong knowledge and demonstrated understanding of NIST 800-53, security and privacy controls.
  • Must have strong analytical and problem-solving skills
  • Must have experience communicating technical findings to both technical and non-technical stakeholders
  • Must be detail-oriented with strong documentation and reporting skills
  • Must have experience working independently and collaboratively in a team environment
  • Certification (preferred) includes CISSP, Security+, CISA
Castro Puerto Rico is a Professional Services Center headquartered in San Juan, Puerto Rico, delivering advisory, accounting, audit and IT support services to Federal Government clients. We are dedicated to assisting our clients to accomplish their strategic goals while providing our people with a diverse and inclusive environment to thrive and succeed.
Castro Puerto Rico is an Equal Opportunity Employer and considers all qualified applicants without regard to color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability and any other classification protected by law.