1

Fisma Auditor Jobs (NOW HIRING)

Senior IT Auditor

Mclean, VA ยท On-site

$95K - $124K/yr

Provide FISCAM/FISMA policy and analysis support to client personnel for multiple applications and networks * Establish and implement organization policies in support of establishing efficient FISMA ...

FISMA Support Analyst

Washington, DC ยท On-site

$133K - $1M/yr

Overview We are seeking FISMA Support Analyst(s) to support the Governance, Risk and Compliance ... Generate security metrics and reports for management and auditors * Maintain system security ...

$133K - $1M/yr

Overview We are seeking FISMA Support Analyst(s) to support the Governance, Risk and Compliance ... Generate security metrics and reports for management and auditors * Maintain system security ...

Senior IT Auditor

Mclean, VA ยท On-site

$96K - $126K/yr

Provide FISCAM/FISMA policy and analysis support to client personnel for multiple applications and networks * Establish and implement organization policies in support of establishing efficient FISMA ...

FISMA Support Analyst (Northern)

Eastern, KY ยท On-site

$133K - $1M/yr

Overview We are seeking FISMA Support Analyst(s) to support the Governance, Risk and Compliance ... Generate security metrics and reports for management and auditors * Maintain system security ...

$152K - $264K/yr

... FISMA) audit in accordance with GAGAS, FAM, and the Federal Information System Controls Audit ... Auditing * Technical Expertise/Competence * Oral Communication * Written Communication * Problem ...

next page

Showing results 1-20

Fisma Auditor information

See salary details

$30.5K

$72.6K

$117.5K

How much do fisma auditor jobs pay per year?

As of Sep 10, 2026, the average yearly pay for fisma auditor in the United States is $72,633.00, according to ZipRecruiter salary data. Most workers in this role earn between $47,000.00 and $98,500.00 per year, depending on experience, location, and employer.

What is a FISMA auditor?

FISMA Auditors are professionals responsible for ensuring that federal agencies and their contractors comply with the Federal Information Security Management Act (FISMA). They assess, audit, and report on the security controls and practices in place to protect sensitive government information. FISMA Auditors review documentation, conduct interviews, perform technical testing, and verify that systems meet federal cybersecurity standards. Their findings help agencies improve their security posture and maintain compliance with federal regulations.

How does a FISMA auditor typically collaborate with IT and compliance teams during an assessment?

A FISMA Auditor works closely with both IT and compliance teams to gather evidence, review security controls, and evaluate risk management practices. Regular meetings are held to clarify documentation, discuss findings, and address any gaps in compliance. Effective communication and teamwork are essential, as auditors rely on subject matter experts within these teams to provide technical insights and ensure that all controls are properly implemented and documented. This collaborative approach helps facilitate a thorough and accurate assessment while also fostering a culture of continuous improvement.

What are the key skills and qualifications needed to thrive as a FISMA auditor, and why are they important?

To thrive as a FISMA Auditor, you need in-depth knowledge of information security principles, risk assessment, and regulatory compliance, typically supported by a degree in cybersecurity or a related field and experience with federal standards. Familiarity with technical tools like vulnerability scanners, compliance management systems, and certifications such as CISSP or CISA are commonly required. Strong analytical thinking, attention to detail, and effective communication skills help auditors interpret regulations and convey findings clearly to stakeholders. These skills ensure thorough evaluations of federal information systems, helping organizations comply with FISMA requirements and protect sensitive data.

What states have the most Fisma Auditor jobs?

States with the most job openings for Fisma Auditor jobs include:

What are popular job titles related to Fisma Auditor jobs?

For Fisma Auditor jobs, the most frequently searched job titles are:

Infographic showing various Fisma Auditor job openings in the United States as of August 2026, with employment types broken down into 86% Full Time, 10% Part Time, 1% Temporary, 2% Contract, and 1% Nights. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $72,633 per year, or $34.9 per hour.

External Auditor Consultant

Washington, DC โ€ข On-site

VIVA USA INC
IT Servicesย โ€ขย 51 - 200 employees

Contractor

Re-posted 4 hours ago


Job description

100% Remote or option to periodically work on-site
FISMA Compliance Support
BACKGROUND:
The Information Security & Privacy Branch of the client propose to engage two to three contractors to provide compliance and information security support to in preparation for annual FISMA audits, provide support in conducting an independent verification and validation of current policies and procedures, and assist with remediation of process improvements. This will also include assisting with ongoing IV&V assessments and audit support.
REQUIREMENTS:
In addition, the candidate shall have demonstrated experience in the following:
Experience with cloud and on-premis applications desirable.
Simultaneously works on several complex assignments requiring analysis of intricately related complex variables.
Experience with leading and successfully developing audit and security related system documentation and requirements desired.
Must have at least ten years of progressively responsible experience in the information technology arena as an IT auditor, IT security analyst, IT manager, business analyst, system administrator or a combination of these.
Possess clear, concise, and effective verbal and written communication and project management skills needed for functioning in an unstructured matrix management environment.
Experience with assessing financial systems leveraging NIST 800 series, or FISMA Compliance strongly desired.
CISSP or CISA certification strongly desired.
KEY RESPONSIBILITIES
Participates in the process to evaluate, develop, maintain, and update the technology compliance program. Advises the technology support officer and technology managers on compliance, information security, and internal controls.
Prepares the technology departments for the yearly FISMA audits.
Assist in developing required documents in support of internal FISMA reviews.
Develop solutions with team members to minimize vulnerabilities.
Advises the technology officer of compliance issues and recommends solutions
Provides a weekly status report to the COR documenting concerns, issues, risks, and progress.
Recommends and helps implement automated solutions in the areas of compliance, auditing, and vulnerability detection for the branch.
Designs, tests, and implements audit mechanisms to detect non-compliance and to support evaluations of evidentiary materials. Ensures proper audit trails are recorded.
Creates audit and monitoring reports used by the team, as directed.
The External Auditor Consultant shall deliver, but not limited to, the following:
Thoroughly assess and validate the audit findings for identified systems of record against client policies. Document findings and recommendations.
Crosswalk the evidence and latest client Information Security Program (BISP) against the CISA and FedRamp standards and procedures and document the results.
Provide recommendations, develop action plans, and help implement capabilities to improve compliance and security practices.
Document updates to compliance related policies, processes, procedures, and/or standards as directed.
Notes:
100% Remote or option to periodically work on-site
VIVA is an equal opportunity employer. All qualified applicants have an equal opportunity for placement, and all employees have an equal opportunity to develop on the job. This means that VIVA will not discriminate against any employee or qualified applicant on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status