1

Information Security Auditor Jobs (NOW HIRING)

Title: IT Security Auditor Location: Dimondale, MI Duration: 6 Months Need only locals Top Skill & Years of Experience Required: Senior Full Stack Application Development Security Auditor who is ...

SIMILAR CAREER TITLESInformation Security Auditor, IT Security Auditor, Cybersecurity Auditor, Compliance Analyst, Risk Assessment Specialist, Security Risk Auditor, Internal IT Auditor, Information ...

SFS is looking for a Security Auditor to provide support to CBL Battle Lab Facility located at Fort ... information/network security advanced degrees approved by the IAM/CO. Obtain and Maintain a Top ...

... IT systems and applications • Develop and implement audit plans and checklists • Review and ... auditing tools and techniques • Strong knowledge of security frameworks (e.g., NIST, ISO 27001 ...

... IT systems and applications • Develop and implement audit plans and checklists • Review and ... auditing tools and techniques • Strong knowledge of security frameworks (e.g., NIST, ISO 27001 ...

... IT systems and applications • Develop and implement audit plans and checklists • Review and ... auditing tools and techniques • Strong knowledge of security frameworks (e.g., NIST, ISO 27001 ...

... IT systems and applications • Develop and implement audit plans and checklists • Review and ... auditing tools and techniques • Strong knowledge of security frameworks (e.g., NIST, ISO 27001 ...

Local candidates only: Candidates must be located within 90-100 miles of Dimondale, MI at the time of submission and must be available for an in-person interview. Per Rose International policy, all ...

Showing results 21-40

Information Security Auditor information

See salary details

$41.5K

$78.2K

$125K

How much do information security auditor jobs pay per year?

As of Sep 13, 2026, the average yearly pay for information security auditor in the United States is $78,163.00, according to ZipRecruiter salary data. Most workers in this role earn between $58,500.00 and $89,500.00 per year, depending on experience, location, and employer.

What does an information security auditor do?

An Information Security Auditor evaluates an organization's information systems to ensure they are secure and comply with relevant policies, regulations, and standards. They perform risk assessments, review security controls, and recommend improvements to protect against cyber threats and data breaches. Their work often includes conducting audits, preparing reports, and advising on best practices for safeguarding sensitive information.

What are the key skills and qualifications needed to thrive as an information security auditor, and why are they important?

To thrive as an Information Security Auditor, you need a solid understanding of cybersecurity principles, risk assessment, regulatory compliance, and typically a degree in information technology or a related field. Familiarity with audit frameworks (such as ISO 27001, NIST), vulnerability assessment tools, and certifications like CISA or CISSP are often required. Strong analytical thinking, attention to detail, and effective communication are vital soft skills for interpreting data and conveying findings to stakeholders. These skills and qualifications are crucial for identifying vulnerabilities, ensuring compliance, and protecting organizations from security threats.

What are some common challenges information security auditors face when assessing an organization's security posture?

Information Security Auditors often encounter challenges such as navigating complex IT environments, staying current with rapidly evolving security threats, and addressing resistance to change from internal stakeholders. They must balance thoroughness with efficiency, ensuring that security controls are both effective and practical for the organization's needs. Collaboration with IT, compliance, and management teams is essential to gather accurate information and implement recommended improvements, making strong communication and negotiation skills vital for success.

What is the difference between Information Security Auditor vs Cybersecurity Analyst?

AspectInformation Security AuditorCybersecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, CompTIA Security+, CEH
Work EnvironmentAudit firms, corporate compliance teamsSecurity operations centers, IT departments
Primary FocusAssessing security controls, compliance, and riskMonitoring, detecting, and responding to security threats
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, financial institutions, government agencies

While both roles focus on security, the Information Security Auditor primarily evaluates security controls and compliance through audits, whereas the Cybersecurity Analyst actively monitors and responds to security threats. Understanding these differences helps organizations assign the right professionals to their security needs.

How much does an information security auditor make?

The average salary for an information security auditor in the United States ranges from $70,000 to $120,000 per year, depending on experience, certifications, and location. Entry-level auditors typically earn less, while those with advanced certifications like CISSP or CISA and several years of experience can earn higher salaries.
More about Information Security Auditor jobs

What cities are hiring for Information Security Auditor jobs?

Cities with the most Information Security Auditor job openings:

Who are the top companies hiring for Information Security Auditor jobs?

The top employers for Information Security Auditor jobs are:

What states have the most Information Security Auditor jobs?

States with the most job openings for Information Security Auditor jobs include:

What are popular job titles related to Information Security Auditor jobs?

For Information Security Auditor jobs, the most frequently searched job titles are:

Infographic showing various Information Security Auditor job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 73% Full Time, 23% Part Time, and 3% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $78,163 per year, or $37.6 per hour.

IT Security Auditor - Senior Consultant

Chantilly, VA • On-site

Dovel Technologies, Inc
Software Development • 51 - 200 employees

$96K - $126K/yr

Other

Medical, Dental, Vision, Life, Retirement

Posted 12 days ago


Key responsibilities

  • Lead stakeholder engagement and technical delivery for IT controls assessments and program evaluations supporting federal agencies.

  • Perform assessments of IT controls, review and analyze documents and artifacts, and evaluate the effectiveness of IT controls against federal requirements and industry guidance.

  • Summarize and communicate IT controls assessment results to client stakeholders, identify root causes of weaknesses, and develop remediation plans.


Job description

## IT Security Auditor – Senior ConsultantApplylocations: US - VA, Chantillytime type: Full timeposted on: Posted Todayjob requisition id: 39739**Job Family:**Technology Consulting**Travel Required:**Up to 10%**Clearance Required:**Active Top Secret SCI with Polygraph**What You Will Do:**The Senior IT Security Auditor will lead stakeholder engagement and technical delivery for efforts supporting federal agencies with IT controls assessments and program evaluations. This is an ideal role for someone with an information security and assurance or IT audit background who is looking to utilize their skills to work with the federal government to analyze IT control weaknesses, identify root causes, and develop remediation plans.Responsibilities include some or all of the following:Performing assessments of IT controls using industry-standard guidance and leading best practicesConducting interviews and discussions with a variety of client stakeholders, including IT system personnel such as Information System Security Officers (ISSOs) and system administrators* Reviewing and analyzing documents and artifacts to assist in IT controls testing such as system security plans, SOPs, audit logs, configuration scans, and vulnerability scans* Evaluating the implementation and effectiveness of IT controls using provided artifacts against federal requirements, industry guidance, and leading best practices* Documenting the results of IT controls testing in a consistent and high-quality manner that would allow others to review and understand the results* Summarizing and communicating IT controls assessment results to a variety of client stakeholders, including senior leadership* Understanding and analyzing known IT control weaknesses, identifying root causes, and developing detailed remediation plans* Providing subject matter expertise to client personnel on a wide range of matters relating to IT security and assurance* Responding to ad-hoc IT security-related requests from client personnel* Planning and executing day-to-day activities of IT assessments and evaluations individually and for the team* Mentoring junior team members in day-to-day IT controls testing responsibilities**What You Will Need:*** An ACTIVE and MAINTAINED TS/SCI Federal or DoD security clearance with a COUNTERINTELLIGENCE (CI) polygraph* Bachelor’s Degree in a Technical or Business field* THREE (3) + years' experience providing IT consulting. Experience should include but not be limited to: + Experience in consulting with the federal government to include senior government clients + Understanding and knowledge of federal information security and assurance laws, requirements, and guidance (i.e. FISMA, NIST SP 800, FISCAM)**What Would Be Nice To Have:*** Relevant certification such as the Certified Information Systems Auditor (CISA) or Certified Information Security Manager (CISM)* Demonstrated knowledge and experience in IT risk and controls through IT audits, IT controls assessments, or IT security reviews* Demonstrated ability and working knowledge of: FISMA, NIST SP 800 series, FISCAM, other relevant federal information assurance laws, regulations, and guidance* Experience performing: FISMA, OMB Circular A-123, or similar internal control assessments* Experience implementing or auditing access and account management principles, including authorization, provisioning, recertification, and separation of duties* Experience implementing or auditing contingency planning principles, including backups, testing of backups, and alternate processing sites* Experience implementing or auditing configuration management principles, including configuration baseline concepts, baseline deviations, baseline maintenance, change control, and monitoring, and industry-accepted configuration settings such as DISA STIGs* Experience performing audit logging and monitoring, including generation of audit logs, use of audit log aggregation and analysis tools, and audit log monitoring and review**What We Offer:**Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.Benefits include:* Medical, Rx, Dental & Vision Insurance* Personal and Family Sick Time & Company Paid Holidays* Position may be eligible for a discretionary variable incentive bonus* Parental Leave and Adoption Assistance* 401(k) Retirement Plan* Basic Life & Supplemental Life* Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts* Short-Term & Long-Term Disability* Student Loan PayDown* Tuition Reimbursement, Personal Development & Learning Opportunities* Skills Development & Certifications* Employee Referral Program* Corporate Sponsored Events & Community Outreach* Emergency Back-Up Childcare Program* Mobility Stipend**About Guidehouse**Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.*Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.* #J-18808-Ljbffr