1

Cisa Jobs in Spring, TX (NOW HIRING)

CISA Preferred. * Writes sections of audit reports covering portions of the audit made personally. * Conducts closing meetings with Department Heads, along with applicable Division Heads and others ...

Bachelor's degree in Accounting, Finance, Business Administration, or related field. * CPA, CIA, CISA, or CFE certifications strongly preferred. * 8+ years of progressive experience in internal audit ...

Cybersecurity Senior

Houston, TX

$95K - $123K/yr

CISSP, CISA, CISM, CEH, or other relevant certifications Other duties Please note this is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are ...

Sr. IT Auditor

Houston, TX · On-site

$89K - $117K/yr

CISA, CISSP, CPA, CI. * Additional training or degrees preferred * Able to travel up to 30 percent of the time to both domestic and international (limited, but potential) field locations. Additional ...

CISSP, CISA, Microsoft Certified: Identity and Access Administrator Associate. * Vendor certifications from AWS, Microsoft Azure, or Google Cloud Platform preferred. Preferred Attributes:

New

Wastewater Operator

Katy, TX · On-site

$21.77 - $27.22/hr

For purposes of business continuity, employees in this position are considered Essential Critical Infrastructure Workers, as defined by the Cybersecurity & Infrastructure Security Agency (CISA)

Showing results 41-60

Cisa information

See Spring, TX salary details

$55.2K

$97.6K

$133.5K

How much do cisa jobs pay per year?

As of Aug 9, 2026, the average yearly pay for cisa in Spring, TX is $97,633.00, according to ZipRecruiter salary data. Most workers in this role earn between $83,600.00 and $109,900.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the CISA position, and why are they important?

To thrive as a CISA (Certified Information Systems Auditor), you need a strong understanding of IT auditing, risk assessment, and information systems governance, typically validated by the CISA certification. Proficiency with audit management software, data analytics tools, and familiarity with regulatory compliance frameworks (such as COBIT or ISO 27001) are essential. Strong analytical thinking, effective communication, and attention to detail are key soft skills that help in collaborating with stakeholders and presenting findings clearly. These skills and qualities are crucial for ensuring information systems are secure, reliable, and compliant with industry standards.

What jobs can you get with CISA?

A CISA (Certified Information Systems Auditor) credential qualifies professionals for roles such as IT auditor, information security manager, compliance analyst, and cybersecurity consultant. These jobs involve assessing and managing information systems, ensuring compliance with security standards, and conducting audits using tools like audit software and risk assessment frameworks.

What are common challenges faced by CISAs in their daily work?

CISAs often encounter challenges such as staying current with rapidly evolving technology threats and ensuring compliance with complex regulatory requirements. They must regularly interface with various departments to collect the necessary information for audits, which can require strong interpersonal and negotiation skills. Balancing thoroughness and efficiency while conducting audits is essential, as is providing actionable recommendations that are practical within the business context. Overcoming these challenges helps CISAs add significant value to their organizations by improving IT controls and mitigating risk.

Is CISA still in demand?

The Certified Information Systems Auditor (CISA) certification remains highly in demand for cybersecurity and IT audit roles, as organizations prioritize information security and compliance. Professionals with CISA skills in risk management, control assessment, and audit processes are sought after across various industries, especially as cybersecurity threats increase.

Are CISA professionals in demand?

CISA (Certified Information Systems Auditor) professionals are in high demand due to the increasing need for cybersecurity, IT audit, and risk management expertise across various industries. Organizations seek CISA-certified individuals to ensure compliance, security controls, and effective IT governance, often leading to strong job prospects and competitive salaries.

What is a CISA?

A Certified Information Systems Auditor (CISA) job involves assessing, auditing, and ensuring the security and integrity of an organization's information systems. Professionals in this role evaluate IT controls, identify risks, and ensure compliance with industry standards and regulations. They often work in governance, risk management, and compliance to help organizations protect sensitive data and maintain operational efficiency. CISA-certified professionals can work in various industries, including finance, healthcare, and government.

What are popular job titles related to Cisa jobs in Spring, TX? For Cisa jobs in Spring, TX, the most frequently searched job titles are:
What job categories do people searching Cisa jobs in Spring, TX look for? The top searched job categories for Cisa jobs in Spring, TX are:
What cities near Spring, TX are hiring for Cisa jobs? Cities near Spring, TX with the most Cisa job openings:
Infographic showing various Cisa job openings in Spring, TX as of August 2026, with employment types broken down into 100% Full Time. Highlights an 90% In-person, and 10% Remote job distribution, with an average salary of $97,633 per year, or $46.9 per hour.

Client & Vendor Risk Manager

Baker Botts Llp

Houston, TX • On-site

Full-time

Re-posted yesterday


Job description

ABOUT BAKER BOTTS

Baker Botts is a leading international law firm recognized for its deep understanding of the industries it serves. With offices across major global markets, the firm delivers sophisticated legal services while cultivating a collaborative, inclusive culture where both attorneys and professional staff contribute to client success and organizational excellence.

ABOUT THE ROLE

The Information Security Client & Vendor Risk Manager leads the firm’s client due diligence program and oversees all information security vetting for third party vendors across the firm. This role requires deep expertise in security frameworks, strong riskassessment judgment, and the ability to influence senior stakeholders, including internal stakeholders, and client security teams. The Manager acts as a key liaison between the firm’s clients, internal leadership, IT Security, Procurement, and Risk Management, ensuring the firm meets the heightened expectations of our clients.

WHAT YOU'LL DO

Primary Responsibilities

  • Own and mature the firmwide client and vendor duediligence program, ensuring consistency, accuracy, and alignment with the firm’s security posture and regulatory obligations.
  • Serve as the firm’s subjectmatter expert on informationsecurity controls, certifications, and risk posture during client audits, RFPs, and reviews or client engagement terms.
  • Lead complex vendorrisk assessments for highimpact technology and service providers, including review of SOC 2 reports, ISO 27001 certifications, penetrationtest results, cloudsecurity controls, dataprotection, privacy, and retention practices.
  • Develop and maintain the firm’s vendorrisk management framework, including riskscoring methodologies, onboarding workflows, and continuousmonitoring processes.
  • Partner with Procurement, IT, and Office of General Counsel to evaluate vendor contracts, negotiate security requirements, and recommend riskmitigation strategies.
  • Prepare the firm for client audits and regulatory reviews, coordinating evidence collection, documentation, and SME participation across multiple departments.
  • Represent the firm in clientfacing security discussions, including responding to escalated inquiries from corporate counsel, privacy officers, and client security teams.
  • Monitor emerging risks and regulatory developments relevant to the legal industry (e.g., SEC cybersecurity rules, state privacy laws, international datatransfer requirements).
  • Mentor junior analysts and contribute to the professional development of the broader Risk and Compliance team.
  • Drive continuous improvement, identifying opportunities to streamline duediligence workflows, enhance tracking and remediation of client-identified risks, and strengthen the firm’s security posture.

Additional Responsibilities

  • Provide management with periodic reports & briefings on evolving topics within their area of responsibility.
  • Other related projects and duties as assigned by the Director of Information Security.

WHAT YOU'LL BRING

Required

  • 6+ years of experience in information security, vendor risk management, compliance, or legalindustry operations, ideally within an Am Law 200 firm or similarly regulated environment.
  • Deep understanding of security frameworks and standards (SOC 2, ISO 27001, NIST CSF, HIPAA, GLBA, state privacy laws).
  • Experience conducting or leading vendorrisk assessments for enterpriselevel technology providers.
  • Strong communication skills, including the ability to brief partners, respond to client security teams, and translate technical concepts for nontechnical audiences.
  • Demonstrated ability to work independently, manage sensitive information, and lead crossfunctional initiatives in a highpressure environment.
  • Professional certifications such as CTPRA, ISO 27001 Lead Implementer or Lead Auditor and CISSP, CISM, CRISC, or CISA required.
  • Experience with legalindustry technologies (DMS, ediscovery platforms, cloudbased practicemanagement tools) is a plus.

HOW YOU'LL WORK

Extent of Contact

This position requires contact with individuals within the firms as follows:

  • Daily contact with staff from the Firm’s Information Technology, Client Development and Office of the General Counsel teams.
  • Moderate contact with Firm’s attorneys and client representatives.
  • Occasional contact with Firm Management.

This position requires contact with individuals outside the firm as follows:

  • Moderate contact with Firm vendors or potential vendors.
  • Moderate contact with Firm clients

Physical Requirements

  • Must be able to routinely lift and carry event materials and other items up to 10 pounds.
  • Must be able to work at a computer for extensive periods of time.
  • Position requires extensive telephone use.
  • Must be able to lift, squat, kneel and bend.
  • Position requires the ability to visit face-to-face and on the phone with firm lawyers.

Working Conditions and Environment

  • Position is full-time and requires a five-day work week and standard hours as outlined in the Firm policy manual. Additional hours, including weekend and evening hours may be required to perform the essential functions of the job.
  • Must be able to perform essential duties of the position with time constraints and frequent interruptions. 
  • Ability to work well in high pressure environments.
  • 24x7 communication access is required.
  • This position is fully remote. You will be required to come to the office periodically for team meetings or when there is a business or client need.
  • There is potential for travel when needed for team meetings, onsite assessments etc. when there is a business or client need.
  • When working remotely, you must have secure and reliable internet service and a safe, private workspace from which to work.

Baker Botts L.L.P. is an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, gender, sex, age, religion, creed, national origin, citizenship, marital status, sexual orientation, disability, medical condition, military and veteran status, gender identity or expression, genetic information, or any other basis protected by federal, state, or local law.