1

Cyber Security Auditor Jobs (NOW HIRING)

The CSSP Auditor works across the Protect, Detect, Respond, and Sustain functions to ensure cybersecurity operations align with DoD requirements, NIST guidance, CSSP Evaluator Scoring Metrics (ESM ...

Cybersecurity Engineer

MD · On-site

$90K - $160K/yr

Utilize cybersecurity auditing and scanning tools * Background in IT audit, IT operations assessment, or federal consulting * Familiarity with federal governance and compliance frameworks such as ...

IT Auditor

Madison, SD · On-site +1

Your Mission As an IT Auditor with SBS CyberSecurity, you will evaluate organizations, primarily in the financial services industry, including community banks and credit unions. These evaluations ...

IT Auditor

Madison, SD · On-site +1

$60K - $80K/yr

Your Mission As an IT Auditor with SBS CyberSecurity, you will evaluate organizations, primarily in the financial services industry, including community banks and credit unions. These evaluations ...

Bachelor's degree in Computer Science, Business, or a related discipline preferred * 5+ years of related experience in cybersecurity, auditing, penetration testing, or Microsoft Server OS and SQL ...

Bachelor's degree in Computer Science, Business, or a related discipline preferred * 5+ years of related experience in cybersecurity, auditing, penetration testing, or Microsoft Server OS and SQL ...

Senior Internal Auditor

Manhattan, NY · On-site

$93K - $115K/yr

The Senior Auditor (VP) is responsible for independently leading and executing risk-based internal ... Performs operational, financial, compliance, information technology, cybersecurity, and substantive ...

Cyber Security Compliance Liaison

Boise, ID

$105K - $142K/yr

As a Cyber Security Audit Liaison, you will serve as the primary interface between Governance, Risk & Compliance (GRC), Internal Audit, External Auditors, Regulators, Customers, and Micron's Cyber ...

Showing results 21-40

Cyber Security Auditor information

See salary details

$57K

$133K

$186K

How much do cyber security auditor jobs pay per year?

As of Sep 2, 2026, the average yearly pay for cyber security auditor in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What is a cyber security auditor?

A Cyber Security Auditor is responsible for assessing an organization’s security policies, controls, and practices to ensure they comply with industry regulations and standards. They identify vulnerabilities, evaluate risk management strategies, and recommend improvements to protect sensitive data and systems. Auditors conduct assessments, review compliance frameworks, and generate reports detailing security gaps and remediation steps. Their role is crucial in safeguarding an organization against cyber threats while ensuring regulatory and legal adherence.

What are the typical daily responsibilities of a cyber security auditor?

Cyber Security Auditors spend their days conducting thorough assessments of organizational security policies, examining system configurations, and testing controls to ensure compliance with industry standards and best practices. They often analyze logs, review incident reports, and perform vulnerability scans, followed by interviewing staff to understand security protocols. Auditors also document their findings, prepare detailed reports, and communicate recommendations to IT management and stakeholders. The role requires a balance of technical assessments and clear, concise communication with both technical and non-technical teams.

What are the key skills and qualifications needed to thrive in the cyber security auditor position, and why are they important?

To thrive as a Cyber Security Auditor, you need a comprehensive understanding of information security principles, risk assessment methodologies, and auditing standards, usually backed by a degree in cybersecurity, information technology, or a related field. Familiarity with technical tools such as vulnerability scanners, SIEM solutions, and frameworks like NIST or ISO 27001, along with certifications like CISA or CISSP, is highly valued. Strong analytical thinking, attention to detail, and effective communication are key soft skills essential for collaborating with diverse teams and presenting findings clearly. These skills and qualifications enable Cyber Security Auditors to effectively identify vulnerabilities, ensure compliance, and help organizations safeguard critical assets.

How to become a cyber security auditor?

To become a cyber security auditor, you typically need a bachelor's degree in computer science, information technology, or a related field. Gaining experience in cybersecurity, understanding auditing standards, and obtaining certifications such as Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP) can enhance your qualifications. Strong analytical skills and knowledge of security tools and frameworks are also important for success in this role.

What do cybersecurity auditors do?

Cybersecurity auditors evaluate an organization's information systems to identify vulnerabilities, ensure compliance with security standards, and recommend improvements. They review security policies, perform risk assessments, and often use tools like vulnerability scanners to protect data and infrastructure.
More about Cyber Security Auditor jobs

What cities are hiring for Cyber Security Auditor jobs?

Cities with the most Cyber Security Auditor job openings:

Who are the top companies hiring for Cyber Security Auditor jobs?

The top employers for Cyber Security Auditor jobs are:

What states have the most Cyber Security Auditor jobs?

States with the most job openings for Cyber Security Auditor jobs include:

Infographic showing various Cyber Security Auditor job openings in the United States as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 26 days ago


Job description

Responsibilities and Qualifications

Position Summary

The CSSP Auditor provides independent oversight, compliance validation, and operational quality assurance across the Cybersecurity Service Provider (CSSP) environment. The position is responsible for establishing a continuous audit and inspection-ready posture by validating cybersecurity operations, telemetry quality, evidence traceability, regulatory compliance, and operational performance metrics. The CSSP Auditor works across the Protect, Detect, Respond, and Sustain functions to ensure cybersecurity operations align with DoD requirements, NIST guidance, CSSP Evaluator Scoring Metrics (ESM), and organizational quality standards.

Key Responsibilities:

  • Data Quality Scoring (DQS) & Telemetry Auditing: Establish, govern, and audit the CSSP Data Quality Scoring (DQS) framework to evaluate the trustworthiness of ingested security telemetry. Perform continuous audits of telemetry sources against mandatory DQS metrics, including Parsing Success Rate (PSR), Field Completeness Score (FCS), Schema Adherence Score (SAS), and Timeliness Score (TS). Track, analyze, and manage the remediation of low-DQS sources and data-loss visibility gaps. Validate data collection, normalization, enrichment, and correlation processes to ensure critical security events are accurately represented throughout the detection lifecycle.
  • Evidence Object & Traceability Verification: Manage and validate CSSP Evidence Objects to ensure all defensive cyber actions are fully documented and package-proven. Ensure absolute traceability from ingested telemetry up to cybersecurity risk-reduction decisions. Verify complete traceability from source telemetry through analyst actions, incident response activities, and cybersecurity risk-reduction decisions. Conduct routine audits of evidence packages to ensure compliance with internal policies and external assessment requirements.
  • SOP Lifecycle Management & SharePoint Governance: Lead the full lifecycle of Standard Operating Procedures (SOPs), playbooks, and internal operational workflows. Develop, implement, and track an annual review plan for all CSSP documentation. Manage the SharePoint Master SOP Library, maintaining version control, access permissions, and formal archival processes. Verify that all published SOPs are synchronized with current DED requirements and operational capabilities.
  • NIST SP-800-53 Rev. 5 & 800-53A Compliance: Map CSSP operational controls and evidence logs directly to NIST SP-800-53 Rev. 5 control families, focusing heavily on Audit and Accountability, System and Information Integrity, and Incident Response. Embed NIST SP-800-53A assessment methods (Examine, Interview, and Test) into internal audit procedures to support continuous authorization and federal compliance mandates, including OMB M-26-14. Focus heavily on Audit and Accountability (AU), System and Information Integrity (SI), Incident Response (IR), Configuration Management (CM), and Risk Assessment (RA) controls.
  • Audit Readiness: Lead activities supporting CSSP Evaluator Scoring Metrics (ESM) assessments, Cyber Operational Readiness Assessments (CORA), JFHQ-DODIN evaluations, and other government-directed inspections. Coordinate evidence collection, validation, scoring reviews, and corrective action tracking. Maintain a continuous inspection-ready posture and reduce organizational dependence on pre-audit preparation cycles. Define, monitor, and report on internal performance metrics, enforcing strict alignment with DTM 26-003.
  • Independent Quality Assurance: Conduct recurring audits across Protect, Detect, Respond, and Sustain teams. Assess procedural compliance, documentation quality, operational consistency, analyst performance evidence, and adherence to service delivery requirements. Validate execution against approved processes, operational standards, and organizational objectives.
  • Continuous Improvement and Lessons Learned: Identify recurring compliance deficiencies, operational trends, systemic weaknesses, and process inefficiencies. Develop lessons learned reports and corrective action recommendations. Facilitate continuous process improvement initiatives that strengthen cybersecurity effectiveness, audit readiness, and mission performance.

Required Qualifications:

  • Clearance: Active Top-Secret Clearance with SCI eligibility required.
  • Compliance & Certifications:
    • DoD 8140/8570 CSSP Auditor or equivalent certifications is required
    • Certified Information Systems Auditor (CISA) is required
  • Experience: Minimum of 7+ years of progressive experience in cybersecurity auditing, continuous monitoring, or compliance assessment (or 5+ years with a Master's degree), with a minimum of three (3) years supporting DoD or Federal cybersecurity programs. Experience supporting audit, inspection, or accreditation activities within a Security Operations Center (SOC), Cybersecurity Service Provider (CSSP), Cyber Defense Program, or related environment.
  • Education: BA/BS College degree required.
  • Technical Auditing Capabilities: Proven experience auditing database/SIEM logs, data ingestion schemas, and validating compliance data flows. Familiarity with data dictionaries, data validation rules, and automated log analysis is highly preferred.

Preferred Technical Experience/Knowledge (3 or more areas desired):

  • DoD Cybersecurity Service Provider (CSSP) operations
  • Risk Management Framework (RMF)
  • NIST SP 800-53 Rev. 5 and NIST SP 800-53A
  • DoDI 8530.01 and applicable CSSP guidance
  • CNSSI 1253
  • Security Technical Implementation Guides (STIGs)
  • Continuous Monitoring programs
  • Incident Response processes
  • Vulnerability Management programs
  • Audit, compliance, and inspection readiness activities
  • MITRE ATT&CK Framework
Overview

We are seeking a CSSP Auditor to join our Prime Contract with the Defense Threat Reduction Agency.

TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers.

We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays.

Visit us at www.TekSynap.com. 

Apply now to explore jobs with us! 

The safety and health of our employees is of the utmost importance. Employees are required to comply with any vaccination requirements mandated by contract, applicable law or regulation.

By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status.  If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration.

Additional Job Information

WORK ENVIRONMENT AND PHYSICAL DEMANDS

The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

  • Location: Fort Belvoir, VA
  • Type of environment: Office
  • Noise level: Low
  • Work schedule: Schedule is Monday - Friday (0800 - 1600). May be requested to work evenings and weekends to meet program and contract needs.
  • Amount of Travel: Less than 10%

PHYSICAL DEMANDS

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus.

WORK AUTHORIZATION/SECURITY CLEARANCE

  • U.S Citizenship Required
  • Top Secret Clearance with SCI Eligibility.

WAGE INFORMATION

Target salary range: $120,000.00 - $170,000.00.  The salary range displayed is an estimate only and is not a guarantee of compensation or salary and will be determined on several factors regarding the individual's particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements.  The displayed salary is one component of the total compensation package for employees. 

OTHER DUTIES

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment.

Many positions require specific certifications and/or the ability to obtain a security clearance.  Security clearances may only be granted to U.S. citizens.  Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements. 

EQUAL EMPLOYMENT OPPORTUNITYIn order to provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, sexual orientation, gender identity, protected veteran status, national origin, disability, age, genetic information or any other characteristic protected by law (referred to as "protected status"). This nondiscrimination policy extends to all terms, conditions, and privileges of employment as well as the use of all company facilities, participation in all company-sponsored activities, and all employment actions such as promotions, compensation, benefits, and termination of employment. TekSynap is committed to ensuring that our online application process provides an equal employment opportunity to all job seekers, including individuals with disabilities. If you believe you need a reasonable accommodation in order to search for a job opening or to submit an application, please contact hr@teksynap.com for assistance. Employment Type: FULL_TIME