1

Fisma Auditor Jobs (NOW HIRING)

Minimum of 5 years of progressive experience in cybersecurity compliance, IT auditing, or Risk Management Framework (RMF) execution. * Demonstrated experience conducting deep-dive FISMA reviews and ...

Support and facilitate internal and external audits of assigned FISMA systems, including audits conducted by the Inspector General (IG), General Accountability Office (GAO), and internal auditors ...

Support and facilitate internal and external audits of assigned FISMA systems, including audits conducted by the Inspector General (IG), General Accountability Office (GAO), and internal auditors ...

IT Compliance Manager

Quantico, VA · On-site

$91K - $153K/yr

Minimum of 5 years of progressive experience in cybersecurity compliance, IT auditing, or Risk Management Framework (RMF) execution. * Demonstrated experience conducting deep-dive FISMA reviews and ...

IT Compliance Manager

Quantico, VA · On-site

$91K - $153K/yr

Minimum of 5 years of progressive experience in cybersecurity compliance, IT auditing, or Risk Management Framework (RMF) execution. * Demonstrated experience conducting deep-dive FISMA reviews and ...

Support and facilitate internal and external audits of assigned FISMA systems, including audits conducted by the Inspector General (IG), General Accountability Office (GAO), and internal auditors ...

Showing results 41-60

Fisma Auditor information

See salary details

$30.5K

$72.6K

$117.5K

How much do fisma auditor jobs pay per year?

As of Sep 11, 2026, the average yearly pay for fisma auditor in the United States is $72,633.00, according to ZipRecruiter salary data. Most workers in this role earn between $47,000.00 and $98,500.00 per year, depending on experience, location, and employer.

What is a FISMA auditor?

FISMA Auditors are professionals responsible for ensuring that federal agencies and their contractors comply with the Federal Information Security Management Act (FISMA). They assess, audit, and report on the security controls and practices in place to protect sensitive government information. FISMA Auditors review documentation, conduct interviews, perform technical testing, and verify that systems meet federal cybersecurity standards. Their findings help agencies improve their security posture and maintain compliance with federal regulations.

How does a FISMA auditor typically collaborate with IT and compliance teams during an assessment?

A FISMA Auditor works closely with both IT and compliance teams to gather evidence, review security controls, and evaluate risk management practices. Regular meetings are held to clarify documentation, discuss findings, and address any gaps in compliance. Effective communication and teamwork are essential, as auditors rely on subject matter experts within these teams to provide technical insights and ensure that all controls are properly implemented and documented. This collaborative approach helps facilitate a thorough and accurate assessment while also fostering a culture of continuous improvement.

What are the key skills and qualifications needed to thrive as a FISMA auditor, and why are they important?

To thrive as a FISMA Auditor, you need in-depth knowledge of information security principles, risk assessment, and regulatory compliance, typically supported by a degree in cybersecurity or a related field and experience with federal standards. Familiarity with technical tools like vulnerability scanners, compliance management systems, and certifications such as CISSP or CISA are commonly required. Strong analytical thinking, attention to detail, and effective communication skills help auditors interpret regulations and convey findings clearly to stakeholders. These skills ensure thorough evaluations of federal information systems, helping organizations comply with FISMA requirements and protect sensitive data.

What states have the most Fisma Auditor jobs?

States with the most job openings for Fisma Auditor jobs include:

What are popular job titles related to Fisma Auditor jobs?

For Fisma Auditor jobs, the most frequently searched job titles are:

Infographic showing various Fisma Auditor job openings in the United States as of August 2026, with employment types broken down into 86% Full Time, 10% Part Time, 1% Temporary, 2% Contract, and 1% Nights. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $72,633 per year, or $34.9 per hour.

IT Compliance Manager

Quantico, VA • On-site

MANTECH
IT Services • 5 - 10K employees

Full-time

Posted 9 days ago


ManTech rating

8.8

Company rating: 8.8 out of 10

Based on 15 frontline employees who took The Breakroom Quiz


Job description

hackajob is collaborating with MANTECH to connect them with exceptional professionals for this role.

MANTECH seeks a motivated, career and customer-oriented IT Compliance Manager to join our team in Washington, D.C. This is an onsite position.

The IT Compliance Manager will leverage their technical background and compliance expertise to support the Federal Bureau of Investigation (FBI) Enterprise Cybersecurity Section (ECS) with audit preparation and quality reviews for FISMA compliance. You will help conduct deep-dive readiness assessments, evaluate enterprise security artifacts, and ensure system audit readiness across the enterprise. 

Responsibilities include but are not limited to:

  • Serving as a dedicated IT Compliance Manager exclusively assigned to conduct deep-dive audit readiness assessments and FISMA compliance quality reviews for assigned information systems. 

  • Evaluating system documentation, technical security controls, access controls, and Plan of Action and Milestones (POA&M) tracking against FISMA, NIST SP 800-53, and FBI policy standards. 

  • Conducting deep-dive reviews of enterprise-level FISMA artifacts, including security plans, risk assessments, and contingency plans, to ensure control mapping accuracy and completeness. 

  • Preparing defensible, audit-ready response packages, compliance statements, and supporting evidence to minimize findings during federal audit engagements. 

  • Communicating identified gaps, weaknesses, and remediation progress directly to Enterprise Cybersecurity Section leadership. 

  • Developing and tracking corrective action plans and POA&Ms to ensure pre-audit findings are resolved within required timelines. 

Minimum Qualifications:

  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Business Management, or a related discipline, or equivalent work experience. 

  • Minimum of 5 years of progressive experience in cybersecurity compliance, IT auditing, or Risk Management Framework (RMF) execution. 

  • Demonstrated experience conducting deep-dive FISMA reviews and evaluating compliance against NIST SP 800-53, NIST SP 800-53A, and federal cybersecurity standards. 

  • Possess at least one of the following DoD 8140.03 Intermediate proficiency certifications: CCISO, CISA, CISM, CISSP, CISSP-ISSEP, CySA+, GSLC, or GSNA. 

  • Proven experience reviewing enterprise security documentation, preparing audit response packages, and managing POA&M lifecycles. 

  • Strong technical writing skills with experience developing defensible compliance justifications for federal auditors. 

Clearance Requirements:

  • An active Top Secret clearance with SCI eligibility is required. 

Preferred Qualifications:

  • Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or Certified Information Systems Security Professional (CISSP) certification. 

  • Experience supporting Department of Justice (DOJ) or Federal Bureau of Investigation (FBI) FISMA audits, Inspector General (IG) reviews, or OMB Circular A-123 assessments. 

  • Familiarity with government Governance, Risk, and Compliance (GRC) tools such as Joint Cybersecurity Authorization Management (JCAM) or Telos Xacta. 

  • Demonstrated track record of resolving pre-audit findings and achieving minimal or zero audit findings. 

Physical Requirements:

  • Must be able to remain in a stationary position 50% of the time. 

  • Needs to occasionally move about inside the office to access file cabinets, office machinery, etc. 

  • Frequently communicates with co-workers, management, and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations. 


What ManTech employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom