2

Cisa Remote Jobs in Washington (NOW HIRING)

Security Architect - Consultant 9309

Washington, DC · Remote

$66.50 - $86/hr

* Location: 100% Remote. -Security Architect - Consultant 9309 . Employment Type: W2 Only (No ... CISA, CISO or equivalent advanced security certification. Additional relevant certifications ...

Lead ISSO Manager

Washington, DC · Remote

$130K - $162K/yr

This is a remote position. Responsibilities: * Serve as the principal advisor to senior SSD ... Executive Order 14028 and CISA directives * Zero Trust Architecture (NIST 800-207, OMB M-22-09)

... City Remote Country United States Working time Full-time Description & Requirements Maximus is ... CISA, USCIS, FEMA, ICE, and CBP. The Capture Manager serves as the execution lead for assigned ...

Remote Job: Auto / Performance Tester Schedule:Full-time Shift: Day Job Potential for Remote Work ... Optional certifications may includeISTQB, CISA, CEH, or other QA/performance testing credentials ...

Remote Job: Auto / Performance Tester​ Schedule: Full-time Shift: Day Job Potential for Remote ... Optional certifications may include ISTQB, CISA, CEH, or other QA/performance testing credentials ...

next page

Showing results 1-20

Cisa Remote information

What is a CISA remote?

CISA remote jobs refer to positions at the Cybersecurity and Infrastructure Security Agency (CISA) that allow employees to work from locations outside of traditional office environments, often from home. These roles support various cybersecurity, infrastructure protection, and emergency management missions. Remote positions can include cybersecurity analysts, IT specialists, policy advisors, and program managers, among others. Working remotely for CISA provides flexibility while contributing to national security initiatives and critical infrastructure protection.

What jobs can you get with a CISA?

A CISA (Certified Information Systems Auditor) credential qualifies individuals for roles such as IT auditor, information security auditor, compliance analyst, and risk management professional. These jobs typically involve assessing and monitoring an organization’s information systems, ensuring compliance with security standards, and using tools like audit software and frameworks such as COBIT or ISO 27001.

Is CISA still in demand?

The Certified Information Systems Auditor (CISA) certification remains highly in demand for cybersecurity and IT audit roles, as organizations prioritize information security and compliance. Professionals with CISA skills are sought after for their expertise in risk management, control assessment, and audit processes, often leading to strong job stability and competitive salaries.

What are the key skills and qualifications needed to thrive as a CISA remote?

To thrive as a CISA Remote, you need in-depth knowledge of information systems auditing, risk management, and compliance, typically supported by the CISA certification and relevant IT or audit experience. Familiarity with audit management software, data analytics tools, and frameworks like COBIT or ISO 27001 is highly valuable. Strong analytical thinking, self-motivation, and effective remote communication skills set top professionals apart in this role. These skills ensure accurate audits, secure systems, and successful collaboration with clients or teams across locations.

What are some common challenges faced by CISA professionals working remotely, and how can they be addressed?

CISA professionals working remotely often face challenges such as maintaining secure communication channels, ensuring the integrity of audit evidence, and collaborating effectively with onsite teams. To address these, it's important to leverage secure VPNs and encrypted communication tools, establish clear documentation protocols, and schedule regular virtual meetings with stakeholders. Building strong relationships with IT and business units can also help remote CISA professionals stay informed and maintain audit quality despite physical distance.

What is the difference between Cisa Remote vs Cisa Onsite?

AspectCisa RemoteCisa Onsite
Work EnvironmentRemote, flexible locationOn-site at client or company location
Required CredentialsSame certifications, including CISASame certifications, including CISA
Industry UsageCommon in consulting, auditing, cybersecurity firmsUsed in similar industries, often for on-site audits
Work FlexibilityHigh, with remote toolsLimited, based on location and client needs

Both Cisa Remote and Cisa Onsite roles require the CISA certification and involve information systems auditing. The main difference lies in the work environment: Cisa Remote offers flexibility and the ability to work from anywhere, while Cisa Onsite requires presence at specific locations. Your choice depends on your preference for remote work versus on-site engagement in the industry.

What are the most commonly searched types of Cisa jobs in Washington? The most popular types of Cisa jobs in Washington are:
What are popular job titles related to Cisa Remote jobs in Washington? For Cisa Remote jobs in Washington, the most frequently searched job titles are:
What cities in Washington are hiring for Cisa Remote jobs? Cities in Washington with the most Cisa Remote job openings:
Infographic showing various Cisa Remote job openings in Washington as of August 2026, with employment types broken down into 94% Full Time, and 6% Part Time. Highlights an 100% Remote job distribution.

DFC - Vulnerability Management Analyst

cFocus Software Incorporated

Washington, DC • Remote

Full-time

Posted 11 days ago


Job description

cFocus Software seeks a Vulnerability Management Analyst to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance.
Qualifications:
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years of cybersecurity experience, including three or more years in vulnerability management, security compliance, POA&M management, or a closely related function.
  • Hands-on experience analyzing authenticated scan results and validating vulnerabilities using Tenable Nessus, Qualys, Microsoft Defender, or comparable enterprise platforms.
  • Demonstrated ability to assess vulnerability risk using CVSS, exploitability, CISA KEV status, asset criticality, exposure, mission impact, threat intelligence, and compensating controls.
  • Experience creating and maintaining POA&M records, tracking remediation milestones, reconciling GRC and ticketing systems, validating closure evidence, and documenting false-positive determinations.
  • Working knowledge of FISMA, the NIST Risk Management Framework, NIST SP 800-53 controls, NIST SP 800-40 vulnerability and patch-management principles, CISA KEV/BOD 22-01 requirements, and federal continuous-monitoring expectations.
  • Ability to communicate technical risk clearly to federal cybersecurity leaders, System Owners, engineers, administrators, auditors, and nontechnical stakeholders.
  • Strong analytical writing, data-quality, documentation, prioritization, and time-management skills in a deadline-driven environment.
  • Active Security+, CySA+, CEH, GCVA, CISSP or other relevant security certifications preferred.

Duties:
  • Coordinate authenticated vulnerability scans with DFC stakeholders at frequencies aligned with policy, system criticality, exposure, threat conditions, and Government direction.
  • Analyze output from Tenable, Qualys, Microsoft Defender, and other Government-approved vulnerability, endpoint, configuration, and posture-management platforms.
  • Validate scanner findings against the operational environment and distinguish valid findings from false positives using documented rationale and supporting evidence.
  • Assess and assign severity using CVSS, DFC policy, exploitability, known-exploitation status, asset criticality, external exposure, mission impact, and relevant threat intelligence.
  • Recommend risk-informed remediation priorities, actions, timelines, evidence requirements, and closure criteria.
  • Coordinate with engineering, operations, application, cloud, endpoint, and system administration teams to establish remediation ownership, dependencies, and target completion dates
  • Provide rapid analysis and coordination for CISA Known Exploited Vulnerabilities (KEV), Binding Operational Directive 22-01 requirements, CISA Emergency Directives, vendor-declared zero-days, and vulnerabilities with active exploitation.
  • Notify the ISSM within four hours of applicable CISA notification, vendor disclosure, Government notification, or Contractor identification.
  • Verify exposure across applicable CSAM authorization boundaries and deliver a written impact assessment within one business day.
  • Document affected systems, boundaries and assets; severity; exposure; exploitability; known exploitation; mission impact; remediation ownership; required timelines; recommended action; and residual-risk considerations.
  • Track emergency remediation against CISA-, DFC-, or Government-directed deadlines and provide written confirmation of remediation status, compliance status, residual risk, and closure evidence.
  • Use CSAM as the authoritative POA&M and compliance ledger and ServiceNow as the operational remediation ticketing record.
  • Create complete POA&M items in CSAM within three business days after finding identification or Government direction, unless the Government establishes another deadline.
  • Populate and maintain required fields, including identifier, weakness description, affected system and control, severity, source, responsible owner, required resources, scheduled completion date, milestones, status, residual risk, and closure evidence.
  • Maintain bidirectional traceability so each applicable ServiceNow remediation ticket links to its CSAM POA&M item and each CSAM POA&M record references the appropriate ServiceNow ticket.
  • Track remediation through closure, monitor milestone integrity and aging, and coordinate scheduled-completion-date changes only after federal authorization.
  • Conduct monthly ServiceNow-to-CSAM reconciliation; identify stale or duplicate records, missing links or evidence, inconsistent status, inaccurate dates, and other data-quality issues; issue a written discrepancy log and track gaps to resolution.
  • Prepare risk-acceptance or exception recommendation packages when remediation cannot be completed within applicable timelines or scheduled-completion-date constraints.
  • Document the affected system and weakness, operational and mission impacts, exploitability, exposure, residual risk, compensating controls, remediation constraints, proposed duration and expiration, review interval, and conditions for continued acceptance.
  • Route recommendation packages to the AODR through the COR and ISSM for federal decision and accurately record approved decisions in CSAM.
  • Clearly preserve federal authority: do not accept risk for DFC, approve exceptions, extend POA&M dates without authorization, or make final closure decisions.

Powered by JazzHR

vNBNiobreH