1

Cyber Security Auditor Jobs in Reston, VA (NOW HIRING)

... auditing, configuration management, and change control. * Professional cybersecurity certifications such as Security+, CISSP, CySA+, CEH, or GCIH. * Education/Experience : Requires MS degree and 15 ...

... auditing, configuration management, and change control. * Professional cybersecurity certifications such as Security+, CISSP, CySA+, CEH, or GCIH. * Education/Experience : Requires MS degree and 15 ...

The Senior Cybersecurity Architect will provide comprehensive subject matter expertise and ... auditors real-time proof instead of point-in-time packages, and an ATO that program teams can ...

The Senior Cybersecurity Architect will provide comprehensive subject matter expertise and ... auditors real-time proof instead of point-in-time packages, and an ATO that program teams can ...

Cybersecurity Engineer 3

Reston, VA · On-site

$130 - $180/hr

The Cybersecurity Engineer 3 will contribute to the design, implementation, and maintenance of ... Experience implementing continuous monitoring and auditing of solutions for compliance with ...

Assists with engineering support and system administration of specialized cybersecurity solutions ... Certified Information Systems Auditor (CISA) Upon Hire Required. Founded in 2010 and headquartered ...

Showing results 21-40

Cyber Security Auditor information

See Reston, VA salary details

$59.3K

$138.3K

$193.5K

How much do cyber security auditor jobs pay per year?

As of Sep 4, 2026, the average yearly pay for cyber security auditor in Reston, VA is $138,328.00, according to ZipRecruiter salary data. Most workers in this role earn between $115,500.00 and $156,100.00 per year, depending on experience, location, and employer.

What is a cyber security auditor?

A Cyber Security Auditor is responsible for assessing an organization’s security policies, controls, and practices to ensure they comply with industry regulations and standards. They identify vulnerabilities, evaluate risk management strategies, and recommend improvements to protect sensitive data and systems. Auditors conduct assessments, review compliance frameworks, and generate reports detailing security gaps and remediation steps. Their role is crucial in safeguarding an organization against cyber threats while ensuring regulatory and legal adherence.

What are the typical daily responsibilities of a cyber security auditor?

Cyber Security Auditors spend their days conducting thorough assessments of organizational security policies, examining system configurations, and testing controls to ensure compliance with industry standards and best practices. They often analyze logs, review incident reports, and perform vulnerability scans, followed by interviewing staff to understand security protocols. Auditors also document their findings, prepare detailed reports, and communicate recommendations to IT management and stakeholders. The role requires a balance of technical assessments and clear, concise communication with both technical and non-technical teams.

What are the key skills and qualifications needed to thrive in the cyber security auditor position, and why are they important?

To thrive as a Cyber Security Auditor, you need a comprehensive understanding of information security principles, risk assessment methodologies, and auditing standards, usually backed by a degree in cybersecurity, information technology, or a related field. Familiarity with technical tools such as vulnerability scanners, SIEM solutions, and frameworks like NIST or ISO 27001, along with certifications like CISA or CISSP, is highly valued. Strong analytical thinking, attention to detail, and effective communication are key soft skills essential for collaborating with diverse teams and presenting findings clearly. These skills and qualifications enable Cyber Security Auditors to effectively identify vulnerabilities, ensure compliance, and help organizations safeguard critical assets.

How to become a cyber security auditor?

To become a cyber security auditor, you typically need a bachelor's degree in computer science, information technology, or a related field. Gaining experience in cybersecurity, understanding auditing standards, and obtaining certifications such as Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP) can enhance your qualifications. Strong analytical skills and knowledge of security tools and frameworks are also important for success in this role.

What do cybersecurity auditors do?

Cybersecurity auditors evaluate an organization's information systems to identify vulnerabilities, ensure compliance with security standards, and recommend improvements. They review security policies, perform risk assessments, and often use tools like vulnerability scanners to protect data and infrastructure.

What are popular job titles related to Cyber Security Auditor jobs in Reston, VA?

For Cyber Security Auditor jobs in Reston, VA, the most frequently searched job titles are:

What cities near Reston, VA are hiring for Cyber Security Auditor jobs?

Cities near Reston, VA with the most Cyber Security Auditor job openings:

Infographic showing various Cyber Security Auditor job openings in Reston, VA as of August 2026, with employment types broken down into 82% Full Time, 15% Part Time, 1% Temporary, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $138,328 per year, or $66.5 per hour.

Information Systems Auditor | All Levels with Security Clearance

Silverthorne Advisory Group, LLC

Arlington, VA • On-site

Other

Medical, Dental, Vision, Retirement, PTO

Re-posted 7 days ago


Key responsibilities

  • Plan, execute, and document risk-based information systems audits.

  • Evaluate IT General Controls (ITGCs), application controls, and cybersecurity controls.

  • Support compliance efforts and collaborate with stakeholders to improve governance and internal controls.


Job description

Silverthorne Advisory Group is seeking an Information Systems Auditor to join an exciting and growing opportunity supporting clients across the Defense sector. This role is responsible for evaluating the effectiveness of information technology controls, cybersecurity safeguards, governance processes, and enterprise risk management programs while supporting federal financial management, audit readiness, and digital modernization initiatives. The successful candidate will perform risk-based IT audits, assess the design and operating effectiveness of IT General Controls (ITGCs), application controls, and cybersecurity controls, and provide recommendations to strengthen security, compliance, and operational efficiency. Day-to-day responsibilities will emphasize foundational knowledge of federal financial management while expanding expertise beyond traditional system audit disciplines through the use of modern data, analytics, and artificial intelligence technologies. The role partners closely with business leaders, information technology teams, cybersecurity professionals, finance organizations, and external auditors to identify and mitigate technology risks while ensuring compliance with federal regulations, industry standards, and evolving cybersecurity frameworks. This position offers an exceptional opportunity to combine information systems auditing, cybersecurity, data analytics, and emerging AI capabilities in support of high-impact defense and federal missions. Responsibilities: - Plan, execute, and document risk-based information systems audits. - Evaluate IT General Controls (ITGCs), application controls, and automated business processes. - Assess the effectiveness of cybersecurity, identity and access management, and data protection controls. - Perform technology risk assessments and identify control gaps, vulnerabilities, and compliance risks. - Conduct testing of security, operational, and financial system controls. - Develop audit workpapers, findings, recommendations, and executive-level reports. - Validate corrective actions and monitor remediation efforts through completion. - Support compliance with NIST, COBIT, ISO 27001, FISMA, CMMC, SOX, FedRAMP, and other regulatory frameworks. - Participate in internal and external audits, assessments, and regulatory examinations. - Evaluate cloud environments, enterprise applications, databases, and infrastructure security controls. - Assess change management, configuration management, backup, disaster recovery, and business continuity processes. - Review logging, monitoring, incident response, vulnerability management, and privileged access management practices. - Analyze technology risks associated with emerging technologies, cloud computing, automation, and artificial intelligence. - Collaborate with cybersecurity, engineering, finance, and business stakeholders to improve governance and internal controls. - Identify opportunities to improve audit methodologies, automate testing procedures, and enhance operational efficiency. - Stay current on evolving cybersecurity threats, regulatory requirements, and industry best practices. Required Skills: Required Skills - Certified Information Systems Auditor (CISA) certification. - 3+ years of experience in IT audit, information security, cybersecurity, risk management, internal audit, or technology consulting. - At least one (1) year of experience in federal audit or federal audit readiness. - Bachelor's degree in Information Systems, Computer Science, Cybersecurity, Accounting, Information Technology, or a related discipline. - U.S. citizenship with an active Secret clearance (we can sponsor). - Experience performing IT General Controls (ITGC) testing and technology risk assessments. - Knowledge of NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-171, COBIT, COSO, and FISCAM. - Experience evaluating identity and access management, change management, logical access, backup and recovery, and configuration management controls. - Strong understanding of cybersecurity principles, security controls, and enterprise risk management. - Experience developing audit reports, documenting findings, and communicating recommendations to stakeholders. - Excellent analytical, problem-solving, organizational, and written communication skills. - Ability to manage multiple projects and work independently in a fast-paced environment. Desired Skills - Experience supporting federal civilian, Department of War, or Intelligence Community clients. - Knowledge of FISMA, FedRAMP, RMF, CMMC 2.0, GAO Green Book, and OMB Circular A-123. - Experience with cloud platforms including Microsoft Azure, Amazon Web Services (AWS), or Google Cloud Platform (GCP). - Familiarity with Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, Microsoft Intune, ServiceNow, SAP, Oracle, or Workday. - Experience with data analytics, SQL, Power BI, Python, PowerShell, or audit automation tools. - Professional certifications such as CISSP, CISM, CRISC, CIA, CPA, CGFM, Security+, or PMP. - Experience supporting SOC 1, SOC 2, ISO 27001, PCI DSS, HIPAA, or SOX compliance initiatives. - Experience leading audit engagements, mentoring junior staff, and presenting to executive leadership. - Strong consulting, stakeholder management, and client relationship skills. Additional Details - Compensation - We carefully consider a wide range of compensation factors, including but not limited to prior experience, skills, expertise, location, and other considerations permitted by law. - Healthcare - We offer Health, Vision, and Dental Plans for our employees and their families. - Retirement Plan - We invest in your future with a competitive 401(k) plan, where we match 100% of your contributions up to your first 6% and give you access to Vanguard Admiral funds. - Paid Time Off - Based on length of service, we offer a generous amount of paid leave. - Bonus System - As you invest in us, we invest in you. We offer bonuses to all employees who meet and exceed goals throughout the year. - Professional Development - Support for career growth through training programs and certifications. - Company Retreats & Team Events - Sponsored trips, team-building activities, and annual conferences related to your skillset.