1

Information Security Audit Jobs (NOW HIRING)

Experience performing security risk assessments, audits, control reviews, and compliance ... Strong knowledge of information security policies, risk management, internal controls, and audit ...

IRS, SSA, OCSE, FBI, SBOA) and remediating any findings; assist with creating and submitting reports relevant to security audits • Develop information security policies and standards for protection ...

$204K/yr

Requires 3 years of experience in a position working with Governance Risk and Compliance, Information Security Audit or Information Security Consulting. Experience must include the following ...

Experience establishing continuous audit readiness, automating control monitoring, and automating audit evidence collection. * Experience operating security programs across multiple cloud providers ...

Experience establishing continuous audit readiness, automating control monitoring, and automating audit evidence collection. * Experience operating security programs across multiple cloud providers ...

Partner with cybersecurity, engineering, audit, risk, compliance, legal, and business stakeholders ... Direct effective operation of the enterprise information security domain, including capacity ...

Showing results 21-40

Information Security Audit information

See salary details

$62.5K

$136.1K

$200K

How much do information security audit jobs pay per year?

As of Sep 11, 2026, the average yearly pay for information security audit in the United States is $136,104.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,500.00 and $160,500.00 per year, depending on experience, location, and employer.

What is the difference between Information Security Audit vs Penetration Tester?

AspectInformation Security AuditPenetration Tester
CertificationsISO 27001 Lead Auditor, CISAOSCP, CEH
Work EnvironmentAudit reports, compliance assessments, office settingsSimulated attacks, testing networks and systems
Employer & IndustryOrganizations seeking compliance, consulting firmsSecurity firms, IT departments, consulting

While both roles focus on security, an Information Security Auditor assesses an organization's security policies and compliance, whereas a Penetration Tester actively tests systems for vulnerabilities. The audit provides a broad overview of security posture, while penetration testing identifies specific weaknesses. Both roles require relevant certifications and are vital for comprehensive cybersecurity strategies.

What does an information security audit do?

An information security audit is a process where a professional evaluates an organization's security controls, policies, and procedures to identify vulnerabilities and ensure compliance with standards like ISO 27001 or NIST. It involves reviewing systems, networks, and data protection measures to assess their effectiveness and recommend improvements.

What cities are hiring for Information Security Audit jobs?

Cities with the most Information Security Audit job openings:

What states have the most Information Security Audit jobs?

States with the most job openings for Information Security Audit jobs include:

What are popular job titles related to Information Security Audit jobs?

For Information Security Audit jobs, the most frequently searched job titles are:

Infographic showing various Information Security Audit job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 73% Full Time, 23% Part Time, and 3% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $136,104 per year, or $65.4 per hour.

Information Security Analyst

On-site

Techvilla Solutions
IT Services • 51 - 200 employees

Full-time

Posted 27 days ago


Job description

We are seeking an experienced Information Security Analyst with strong expertise in cybersecurity risk management, security audits, compliance, internal controls, and security governance.

Required Skills
  • Experience performing security risk assessments, audits, control reviews, and compliance assessments.

  • Strong knowledge of NIST SP 800-53 Rev. 5, RMF, IRS Publication 1075, HIPAA/HITECH, HITRUST, CJIS, and MARS-E.

  • Experience with security and privacy control selection, implementation, assessment, and authorization.

  • Strong knowledge of information security policies, risk management, internal controls, and audit practices.

  • Experience identifying security gaps, developing findings, recommendations, POA&Ms, and remediation plans.

  • Ability to investigate suspicious activity and support security incident reporting.

  • Understanding of IT environments including Windows, Unix/Linux, databases, networking, and software development.

  • Strong technical documentation, analytical, written, and verbal communication skills.

Roles & Responsibilities
  • Conduct security assessments, audits, and risk reviews and document findings and recommendations.

  • Prepare audit reports, risk assessments, security plans, incident reports, and POA&Ms.

  • Review and maintain security policies, audit plans, risk documentation, and compliance artifacts.

  • Evaluate security controls and identify areas of non-compliance and improvement.

  • Track remediation activities and report outcomes to management.

  • Research cybersecurity regulations, standards, and industry best practices to support compliance.

  • Identify cybersecurity and privacy risks across internal and external systems and recommend mitigation strategies.

  • Support project teams with security and compliance requirements.

  • Collaborate with IT, security, audit, compliance, and business teams.

  • Provide security guidance and develop training/user-support materials as required.