1

Isms Lead Auditor Jobs (NOW HIRING)

IT/IS Manager

Eau Claire, WI · On-site

$94K - $115K/yr

... ISMS): you will lead the build-out, maturation, and ongoing governance of our security program ... Preferred Qualifications * ISO 27001 Lead Implementer or Lead Auditor ...

Quality Systems Analyst

San Jose, CA · On-site

$71K - $80K/yr

... System (ISMS), and other applicable management systems. The position works closely with cross ... Lead Auditor certification is an advantage. * Knowledge of quality tools and methodologies ...

IT/IS Manager

Eau Claire, WI · On-site

$95K - $125K/yr

... ISMS): you will lead the build-out, maturation, and ongoing governance of our security program ... ISO 27001 Lead Implementer or Lead Auditor certification strongly preferred. * Relevant ...

Develop and maintain HSE, ISMS, PIMS and compliance management systems. * Identify and mitigate ... Professional certifications such as CSP, CIH, ISO Lead Auditor, Security+, CISSP, CISM, CIPP, or ...

Develop and maintain HSE, ISMS, PIMS and compliance management systems. * Identify and mitigate ... Professional certifications such as CSP, CIH, ISO Lead Auditor, Security+, CISSP, CISM, CIPP, or ...

Develop and maintain HSE, ISMS, PIMS and compliance management systems. * Identify and mitigate ... Professional certifications such as CSP, CIH, ISO Lead Auditor, Security+, CISSP, CISM, CIPP, or ...

We are looking for a GRC professional who is equal parts auditor and builder. Rokt's information ... Maintain and evolve ISMS performance metrics, including new metrics covering AI control ...

We are looking for a GRC professional who is equal parts auditor and builder. Rokt's information ... Maintain and evolve ISMS performance metrics, including new metrics covering AI control ...

We are looking for a GRC professional who is equal parts auditor and builder. Rokt's information ... Maintain and evolve ISMS performance metrics, including new metrics covering AI control ...

NY · On-site

$120 - $160/hr

The role will serve as the primary liaison for both external and internal auditors for ISO 27001 ... Lead and maintain the company's ISO 27001 Information Security Management System (ISMS) and SOC 2 ...

Showing results 21-40

Isms Lead Auditor information

See salary details

$32.5K

$102.9K

$147K

How much do isms lead auditor jobs pay per year?

As of Aug 12, 2026, the average yearly pay for isms lead auditor in the United States is $102,886.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,500.00 and $132,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by ISMS Lead Auditors during internal audits, and how can they be addressed?

ISMS Lead Auditors often encounter challenges such as resistance to change from staff, incomplete documentation, and varying levels of security awareness across departments. Addressing these issues requires strong communication and interpersonal skills to build trust, thorough preparation to understand the organization's processes, and the ability to provide constructive feedback. Proactively engaging stakeholders and offering clear explanations of ISO 27001 requirements can help foster cooperation and ensure a smoother audit process.

What is an ISMS Lead Auditor?

An ISMS Lead Auditor is a professional responsible for assessing and evaluating an organization's Information Security Management System (ISMS) to ensure it meets established standards, such as ISO/IEC 27001. They plan, lead, and report on audits to determine if information security controls are effectively implemented and maintained. ISMS Lead Auditors also provide recommendations for improvement and ensure compliance with regulatory and contractual requirements. Their role is crucial in helping organizations protect sensitive information and manage security risks.

What is the difference between Isms Lead Auditor vs Isms Auditor?

AspectIsms Lead AuditorIsms Auditor
CertificationsISO 27001 Lead Auditor, ISO 45001 Lead AuditorISO 27001 Auditor, ISO 45001 Auditor
Work EnvironmentLeads audit teams, manages audit planning, reportsConducts audits, gathers evidence, reports findings
Employer & IndustryConsulting firms, large organizations, certification bodiesOrganizations seeking certification, internal audit teams

The main difference between an Isms Lead Auditor and an Isms Auditor lies in their responsibilities. The Lead Auditor oversees the entire audit process, manages teams, and ensures compliance, while the Auditor performs the actual audits and reports findings. Both roles require similar certifications but differ in scope and leadership duties.

What are the key skills and qualifications needed to thrive as an ISMS Lead Auditor, and why are they important?

To excel as an ISMS Lead Auditor, you typically need in-depth knowledge of information security management systems, audit methodologies, and relevant standards like ISO/IEC 27001, supported by certifications such as ISO 27001 Lead Auditor. Familiarity with audit management tools, risk assessment software, and compliance tracking systems is commonly required. Strong analytical thinking, attention to detail, and effective communication help auditors identify gaps and convey findings clearly to stakeholders. These skills ensure rigorous, credible audits that protect organizational data and maintain compliance with international security standards.
More about Isms Lead Auditor jobs
What are the most commonly searched types of Isms Lead Auditor jobs? The most popular types of Isms Lead Auditor jobs are:
Infographic showing various Isms Lead Auditor job openings in the United States as of August 2026, with employment types broken down into 75% Full Time, and 25% Contract. Highlights an 75% In-person, and 25% Remote job distribution, with an average salary of $102,886 per year, or $49.5 per hour.

Full-time

Posted 14 days ago


Job description

About Specialized Security Services, Inc.
For over two decades, our expert team has successfully assisted organizations with the implementation and oversight of their information security, privacy, and regulatory compliance programs. Our reputation is our own, built upon our steadfast commitment over the years to do the right thing and go above and beyond for our clients. We pride ourselves on our ability to think outside-the-box, stay nimble and succeed as a team.
About the Senior Assessor role:
The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk Assessment, HIPAA, CCPA, GDPR project initiatives by undertaking risk assessments, advising on implementation of security measures, recommending appropriate risk mitigations, interpreting security policy and standards in the context of projects and business scenarios to help the business operate securely. This role has a significant client consulting and management component in advising, defining client security requirements to industry best practice standards, and ensuring that all projects meet these requirements, or that exceptions and issues are noted and remediated as appropriate.
The ideal candidate combines the technical expertise commonly associated with PCI DSS and cybersecurity assessments with the audit, attestation, and internal control experience often found in SOC and assurance engagements. CPA and/or QSA credentials are highly valued.
As a Senior Assessor, you will:
  • Assess existing controls to determine level of compliance to the PCI DSS standard, SOC 2, ISO, HIPAA, GDPR, NIST, CMMC, etc. inclusive of: their maturity, state of compliance, and the risk associated with any findings.
  • Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and assessments.
  • Conduct SOC 2 Type I and Type II readiness assessments and examinations, including control design review, testing of controls, evidence evaluation, gap analysis, and reporting.
  • Support compliance privacy client engagements and familiarity with GDPR, CCPA, PIPEDA or similar privacy frameworks.
  • Support sites in testing, documentation and issue resolution associated with cyber security programs.
  • Perform comprehensive threat/risk assessments and business impact analysis of current system, data, application and technology environments to determine possible internal and external threats to information assets, and identify security measures required to counter such threats.
  • Supports sites in testing, documentation and issue resolution associated with cyber security programs.
  • Participate in the development and implementation of the enterprise security architecture and supporting security standards to ensure compliance with corporate policies, and relevant legislative and regulatory requirements.
  • Perform technical security reviews or assessments to ensure targeted systems, networks, applications and/or data are in compliance with corporate policies and standards.
  • Understand that, due to the rapidly evolving cybersecurity landscape, maintaining this role will require obtaining additional certifications to keep up with the cybersecurity threat landscape and industry acceptable certifications.

Required Education and Experience:
  • A university degree in Computer Science, Engineering, or a field which relates to the role.
  • Minimum of at least two security certifications from the following (ISC)2 CISSP, ISACA CISM, ISACA CISA, SANS GIAC/GSNA, ISO27001 Certified Lead Implementer/Lead Auditor/Internal Auditor
  • Possession of a PCI QSA certification or the ability to obtain and maintain QSA status is strongly preferred.
  • Five (5) + years of Information Security experience in Security Governance, Risk and Compliance practices and methodologies.

Preferred Experience that drives success in this role:
  • Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials.
  • Certified Public Accountant (CPA) credential preferred.
  • Demonstrated knowledge of the principles, best practices, architectures, and control frameworks applicable to PCI DSS, NIST, SOC 1, SOC 2, CMMC, and ISO standards.
  • Experience conducting cybersecurity assessments and audits, including the use of industry-standard security and compliance tools.
  • Experience with security hardening, policy development, and secure software development practices.
  • Previous experience performing PCI DSS, NIST, CMMC, and ISO assessments, including readiness assessments, gap analyses, remediation validation, and formal audits.
  • Experience leading or supporting SOC 1 and SOC 2 examinations, including scoping, control testing, evidence review, and report development.
  • Experience evaluating internal controls, business processes, governance frameworks, and risk management practices in support of attestation and assurance engagements.