1

Cisa Cissp Jobs (NOW HIRING)

Cyber Security Auditor

Albuquerque, NM · On-site

$101K - $137K/yr

CISA, CISSP, CISM, DoD 8140/8570 IAT/M Level III • U.S. citizen willing to undergo background investigation and perform some work at government or customer sites Desired Skills • Linux/Windows ...

Cyber Security Auditor

Albuquerque, NM · On-site

$107K - $145K/yr

CISA, CISSP, CISM, DoD 8140/8570 IAT/M Level III • U.S. citizen willing to undergo background investigation and perform some work at government or customer sites Desired Skills • Linux/Windows ...

IT Risk Management VP

New York, NY

$171K - $215K/yr

CISA/CISSP/CRISC/CISM/FAIR or equivalent experience is preferred and strong bilingual abilities in Chinese and English are required. Additional Information All your information will be kept ...

Showing results 21-40

Cisa Cissp information

See salary details

$10

$50

$69

How much do cisa cissp jobs pay per hour?

As of Aug 7, 2026, the average hourly pay for cisa cissp in the United States is $50.19, according to ZipRecruiter salary data. Most workers in this role earn between $43.27 and $57.69 per hour, depending on experience, location, and employer.

What jobs can you get with a CISA certification?

A CISA certification qualifies professionals for roles such as IT auditor, information security manager, compliance analyst, and cybersecurity consultant. These jobs involve assessing information systems, ensuring regulatory compliance, and managing security controls using tools like audit frameworks and risk management practices.

How do CISA and CISSP professionals typically collaborate with other departments to enhance organizational security?

CISA and CISSP professionals frequently work across departments, partnering with IT, legal, compliance, and business units to assess risks, develop security policies, and ensure regulatory compliance. They often lead or participate in cross-functional meetings to discuss vulnerabilities, implement controls, and respond to incidents. This collaboration helps align security initiatives with business objectives and fosters a culture of shared responsibility for safeguarding information assets.

What is the difference between Cisa Cissp vs Security Analyst?

AspectCisa CisspSecurity Analyst
CertificationsCISA, CISSP, sometimes others like Security+Security+, CISSP, CEH, sometimes CISA
Work EnvironmentAuditing, risk management, compliance, security policy developmentMonitoring, incident response, vulnerability assessment
Employer & Industry UsageAuditing firms, consulting, large corporations' security teamsIT departments, security operations centers, government agencies

The CISA and CISSP certifications are highly relevant for Security Analysts, but Security Analysts focus more on monitoring and incident response, while CISA and CISSP professionals often handle auditing, compliance, and security policy. Both roles require strong security knowledge, but their daily tasks and focus areas differ.

What are the key skills and qualifications needed to thrive as a CISA or CISSP professional?

To thrive as a CISA or CISSP professional, you need a strong understanding of information security principles, risk management, and compliance frameworks, typically supported by obtaining the CISA or CISSP certification. Familiarity with security assessment tools, audit software, and governance platforms is essential for daily responsibilities. Analytical thinking, attention to detail, and effective communication distinguish top performers in these roles. These skills and qualifications are crucial to protect organizational assets, ensure regulatory compliance, and manage evolving cybersecurity threats.

What are CISA and CISSP certifications?

CISA (Certified Information Systems Auditor) and CISSP (Certified Information Systems Security Professional) are globally recognized certifications in the field of information security and IT auditing. CISA focuses on auditing, control, and assurance, making it ideal for professionals involved in assessing and managing IT systems and processes. CISSP, on the other hand, is a broad certification that covers all aspects of information security, including risk management, network security, and security architecture. Both certifications are highly valued by employers and demonstrate expertise and credibility in cybersecurity and IT auditing. Earning these certifications can lead to advanced career opportunities and higher earning potential.

Is CISA still in demand?

The Certified Information Systems Auditor (CISA) certification remains highly in demand for cybersecurity and IT audit roles, as organizations prioritize information security and compliance. Professionals with CISA skills are sought after for roles involving risk management, controls, and audit processes across various industries.
More about Cisa Cissp jobs
What states have the most Cisa Cissp jobs? States with the most job openings for Cisa Cissp jobs include:
Infographic showing various Cisa Cissp job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 4% Part Time, and 7% Contract. Highlights an 77% Physical, 8% Hybrid, and 15% Remote job distribution, with an average salary of $104,397 per year, or $50.2 per hour.

Senior Security Governance & Compliance Lead

Jobtailor

London, TX • On-site

$140 - $190/hr

Other

Posted 2 days ago

New


Job description

• Own the end-to-end lifecycle of Commerce's core audit programs — PCI DSS 4.0, SOC 2 Type 2, ISO 27001, and SOX — across Commerce, Feedonomics, and Makeswift, including scoping, evidence strategy, auditor management, and final report outcomes.
• Partner with control owners across all three business units to ensure they understand their compliance obligations, maintain audit-ready evidence, and operate effectively within the BC Secure Controls Framework on an ongoing basis.
• Serve as the primary point of contact for QSAs, external auditors, and certification bodies. Defend the control environment, manage audit timelines, and minimize disruption to technical teams.
• Drive the operationalization of audit requirements into BAU workflows across all business units, reducing reliance on point-in-time evidence collection and eliminating audit fatigue organization-wide.
• Own the tracking and closure of audit findings and control gaps across Commerce, Feedonomics, and Makeswift. Partner with control owners to deliver pragmatic, risk-informed remediation plans within defined timelines.
• Direct the ongoing maturity of Commerce's PCI DSS 4.0 program, including Targeted Risk Analyses (TRAs), customized approach applicability, and annual assessment planning.
• Partner with Cloud Engineering to validate and maintain PCI scope across Commerce's global footprint, ensuring effective network segmentation and data flow isolation.
• Manage and support ISA-designated personnel; ensure the ISA function operates with rigor and consistency aligned to PCI Council standards.
• Oversee Commerce's Secure Controls Framework (SCF), built from NIST, ISO 27001, and PCI DSS, ensuring controls are designed, tested, and documented to satisfy multiple regulatory obligations simultaneously across all business units.
• Provide GRC leadership on architectural reviews, product launches, and infrastructure changes across Commerce, Feedonomics, and Makeswift to ensure regulatory requirements are addressed upstream — not as an afterthought.
• Stay ahead of emerging requirements across PCI, SOC, and ISO 27001:2022, translating regulatory changes into actionable program updates.

Requirements

  • 6–10 years in Information Security, IT Audit, or GRC, with demonstrated ownership of enterprise-level audit programs (PCI, SOC 2, ISO 27001, or SOX).
  • Proven track record managing Level 1 Service Provider assessments and navigating complex, multi-framework audit environments spanning multiple business units or legal entities.
  • Demonstrated ability to work cross-functionally with control owners and operational teams, holding stakeholders accountable to their compliance obligations while maintaining strong working relationships.
  • Deep working knowledge of PCI DSS 4.0, ISO 27001:2022, SOC 2 Trust Service Criteria, and SOX IT general controls.
  • Ability to influence and manage cross-functional stakeholders at all levels — from engineers to executives — with clarity, diplomacy, and conviction.
  • Skilled at translating compliance requirements into business-relevant language that drives enablement rather than friction.
  • PCI ISA, CISA, CISSP, or equivalent audit/security certification strongly preferred.
  • Prior experience at a Big 4 advisory or audit firm (Deloitte, PwC, EY, KPMG) in an IT audit, risk advisory, or security compliance capacity is a strong plus.
  • Experience applying GRC frameworks in cloud-native environments and familiarity with modern cloud security tooling.

🔍 ATS Optimization Keywords
Below are skills and terms extracted directly from this job posting to improve Applicant Tracking System (ATS) visibility. This unique feature helps candidates tailor their applications more effectively — a feature exclusive to JobTailor job listings.

Hard Skills

  • Information Security
  • IT Audit
  • Compliance Management
  • Risk Assessment
  • Control Gap Remediation
  • Evidence Strategy
  • Audit Findings Tracking
  • Network Segmentation
  • Data Flow Isolation
  • Regulatory Requirements

Soft Skills

  • Stakeholder Management
  • Cross-Functional Collaboration
  • Influencing Skills
  • Communication Skills
  • Relationship Building

Certifications & Qualifications

  • PCI ISA
  • CISA
  • CISSP
#J-18808-Ljbffr