1

Information Security Auditor Jobs (NOW HIRING)

Information Security Auditor

San Francisco, CA ยท On-site

$166K - $170K/yr

Information Security Auditor DUTIES: Lead a team that provides comprehensive vendor assessments to evaluate security risks and compliance with standards and regulations; Serve as the main point of ...

Information Security Auditor

San Francisco, CA ยท On-site

$166K - $170K/yr

Information Security Auditor DUTIES: Lead a team that provides comprehensive vendor assessments to evaluate security risks and compliance with standards and regulations; Serve as the main point of ...

SIMILAR CAREER TITLES Information Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

SIMILAR CAREER TITLES Information Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

SIMILAR CAREER TITLES Information Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

SIMILAR CAREER TITLES Information Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

SIMILAR CAREER TITLES Information Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

SIMILAR CAREER TITLES Information Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

SIMILAR CAREER TITLES Information Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

SFS is looking for a Security Auditor to provide support to CBL Battle Lab Facility located at Fort ... information/network security advanced degrees approved by the IAM/CO. Obtain and Maintain a Top ...

next page

Showing results 1-20

Information Security Auditor information

See salary details

$41.5K

$78.2K

$125K

How much do information security auditor jobs pay per year?

As of Aug 15, 2026, the average yearly pay for information security auditor in the United States is $78,163.00, according to ZipRecruiter salary data. Most workers in this role earn between $58,500.00 and $89,500.00 per year, depending on experience, location, and employer.

What does an information security auditor do?

An Information Security Auditor evaluates an organization's information systems to ensure they are secure and comply with relevant policies, regulations, and standards. They perform risk assessments, review security controls, and recommend improvements to protect against cyber threats and data breaches. Their work often includes conducting audits, preparing reports, and advising on best practices for safeguarding sensitive information.

What are some common challenges information security auditors face when assessing an organization's security posture?

Information Security Auditors often encounter challenges such as navigating complex IT environments, staying current with rapidly evolving security threats, and addressing resistance to change from internal stakeholders. They must balance thoroughness with efficiency, ensuring that security controls are both effective and practical for the organization's needs. Collaboration with IT, compliance, and management teams is essential to gather accurate information and implement recommended improvements, making strong communication and negotiation skills vital for success.

How much do information security auditors make?

Information security auditors typically earn a median annual salary of around $75,000 to $100,000, depending on experience, certifications, and location. Senior auditors or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $120,000 annually.

What is the difference between Information Security Auditor vs Cybersecurity Analyst?

AspectInformation Security AuditorCybersecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, CompTIA Security+, CEH
Work EnvironmentAudit firms, corporate compliance teamsSecurity operations centers, IT departments
Primary FocusAssessing security controls, compliance, and riskMonitoring, detecting, and responding to security threats
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, financial institutions, government agencies

While both roles focus on security, the Information Security Auditor primarily evaluates security controls and compliance through audits, whereas the Cybersecurity Analyst actively monitors and responds to security threats. Understanding these differences helps organizations assign the right professionals to their security needs.

What are the key skills and qualifications needed to thrive as an information security auditor, and why are they important?

To thrive as an Information Security Auditor, you need a solid understanding of cybersecurity principles, risk assessment, regulatory compliance, and typically a degree in information technology or a related field. Familiarity with audit frameworks (such as ISO 27001, NIST), vulnerability assessment tools, and certifications like CISA or CISSP are often required. Strong analytical thinking, attention to detail, and effective communication are vital soft skills for interpreting data and conveying findings to stakeholders. These skills and qualifications are crucial for identifying vulnerabilities, ensuring compliance, and protecting organizations from security threats.
More about Information Security Auditor jobs

What cities are hiring for Information Security Auditor jobs?

Cities with the most Information Security Auditor job openings:

Who are the top companies hiring for Information Security Auditor jobs?

The top employers for Information Security Auditor jobs are:

What states have the most Information Security Auditor jobs?

States with the most job openings for Information Security Auditor jobs include:

What job categories do people searching Information Security Auditor jobs look for?

The top searched job categories for Information Security Auditor jobs are:

Infographic showing various Information Security Auditor job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 22% Part Time, and 3% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $78,163 per year, or $37.6 per hour.

Information Security Auditor

8848M LLC

San Francisco, CA โ€ข On-site

$166K - $170K/yr

Full-time

Re-posted 17 days ago


Job description

SecurityPal, Inc.
San Francisco, CA
TITLE: Information Security Auditor
DUTIES:
Lead a team that provides comprehensive vendor assessments to evaluate security risks and compliance with standards and regulations; Serve as the main point of contact for clients, ensuring clear communication, understanding of requirements, and satisfaction with services provided; Develop and implement assessment methodologies tailored to client needs and industry best practices; Collaborate with clients to identify their security needs and customize assessment approaches accordingly; and Analyze assessment findings and provide strategic security recommendations to clients to mitigate risks effectively; Generate detailed assessment reports outlining findings, risk levels, and recommendations for remediation. Present findings to clients in a clear, concise, and actionable manner; Foster strong client relationships by proactively addressing concerns, anticipating needs, and providing exceptional service. Act as a trusted advisor on security matters; Collaborate with clients during security incidents to provide technical guidance and support incident response efforts; Perform comprehensive risk assessments beyond vendor assessments, such as enterprise-wide risk assessments, to identify and prioritize risks across different business units or systems; Collaborate with other teams within the organization (e.g., IT, legal, compliance) on security-related initiatives such as policy development, security awareness programs, or incident response exercises; and Conduct readiness assessments for ISO, SOC 2, Fedramp Compliance, evaluating current processes, controls, and documentation to identify gaps and areas needing improvement to achieve compliance and certification. **Telecommuting Allowed for this position**
Minimum Requirements: Master's Degree in Cyber Security and Information Assurance or a substantially related field; thirty (30) months of Work experience in a Cyber Security role; Experience conducting Information Security (IS) Audits compliant with ISO 27001:2013 and SOC 2 Type 2 standards. Telecommuting Allowed for this position.
SALARY: $166,000-$170,000 per year, depending upon experience
HOURS: 9:00 A.M. - 6:00 P.M