1

It Security Auditor Jobs (NOW HIRING)

Title: IT Security Auditor Location: Dimondale, MI Duration: 6 Months Need only locals Top Skill & Years of Experience Required: Senior Full Stack Application Development Security Auditor who is ...

Years of Experience: 10 or more years with IT security and audit experience . Qualifications Duties: 1. Assist the Risk and Compliance Director with risk assessment process re-engineering within the ...

The IT Security Auditor will lead stakeholder engagement and technical delivery for efforts supporting federal agencies with IT controls assessments and program evaluations. This is an ideal role for ...

Experience Required * 7+ years of overall IT / Application Security experience preferred * Minimum ... Auditor with strong expertise in application security testing, secure software development ...

IT Security Auditor #1063766 Short Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static ...

Job Title: IT Security Auditor Duration : 1 year with possible extension Work Mode : Hybrid Interview Process : Virtual interview via MS Teams, with 2nd round interviews held in person. Candidates ...

Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static, and Software Composition Analysis ...

NY ยท On-site

$125 - $150/hr

Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static, and Software Composition Analysis ...

New

Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static, and Software Composition Analysis ...

next page

Showing results 1-20

It Security Auditor information

See salary details

$11K

$90K

$140.5K

How much do it security auditor jobs pay per year?

As of Sep 8, 2026, the average yearly pay for it security auditor in the United States is $89,997.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,000.00 and $130,000.00 per year, depending on experience, location, and employer.

What does an IT Security Auditor do?

An IT Security Auditor is responsible for evaluating and testing an organization's information technology systems, policies, and procedures to ensure they are secure and compliant with industry standards and regulations. They identify vulnerabilities, assess potential risks, and recommend improvements to protect data and maintain cybersecurity. IT Security Auditors may also prepare reports, conduct interviews, and review documentation as part of their assessments.

What are the key skills and qualifications needed to thrive as an IT Security Auditor, and why are they important?

To thrive as an IT Security Auditor, you need a solid understanding of information security principles, risk assessment, and compliance frameworks, often supported by a degree in computer science or related fields and certifications such as CISA, CISSP, or CISM. Familiarity with auditing tools, vulnerability assessment software, and knowledge of regulatory standards like ISO 27001 or NIST is typically required. Strong analytical thinking, attention to detail, and effective communication skills help auditors identify threats and clearly report findings to stakeholders. These abilities are crucial to ensure organizations maintain robust security postures and meet compliance requirements.

What are some typical challenges IT Security Auditors face when working with cross-functional teams?

IT Security Auditors often collaborate with departments such as IT, compliance, and operations to assess and improve security controls. A common challenge is bridging communication gaps between technical and non-technical staff, ensuring audit findings are clearly understood and actionable. Additionally, auditors may encounter resistance to change or difficulties in obtaining timely documentation, requiring strong interpersonal and project management skills. Building trust and maintaining objectivity are essential for facilitating cooperation and driving effective security improvements.

What is the difference between It Security Auditor vs Network Security Analyst?

AspectIt Security AuditorNetwork Security Analyst
CertificationsCISA, CISSPCISSP, CompTIA Security+
Work EnvironmentAudit firms, corporate compliance teamsIT departments, security operations centers
Primary FocusAssessing security policies, compliance, and controlsMonitoring network traffic, identifying vulnerabilities
Employer & Industry UsageFinancial, healthcare, governmentTech companies, ISPs, large enterprises

While both roles focus on cybersecurity, an It Security Auditor primarily evaluates security policies and compliance through audits, whereas a Network Security Analyst actively monitors and protects network infrastructure. Both roles require similar certifications and are vital in maintaining organizational security.

More about It Security Auditor jobs

What cities are hiring for It Security Auditor jobs?

Cities with the most It Security Auditor job openings:

What states have the most It Security Auditor jobs?

States with the most job openings for It Security Auditor jobs include:

What are popular job titles related to It Security Auditor jobs?

For It Security Auditor jobs, the most frequently searched job titles are:

Infographic showing various It Security Auditor job openings in the United States as of September 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $89,997 per year, or $43.3 per hour.

IT Security Auditor

Lansing, MI โ€ข On-site

Global IT Family
Recruiting and Staffing Servicesย โ€ขย 11 - 50 employees

Other

Posted 4 days ago


Job description


Title: IT Security Auditor
Location: Dimondale, MI
Duration: 6 Months

Need only locals

Top Skill & Years of Experience Required:
Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition Analysis assessments. This position is not a member of the Security Operations Center, rather it is dedicated to working with software development teams on secure coding practices. The ideal candidate will feel comfortable working with both front-end, back-end and cloud-based application developers. Partnering with distributed teams to help transform the way systems are built, secured, authorized and securely operated for continuous compliance and risk mitigation. Specifically, this candidate will help lead efforts to implement security patterns and practices with orchestration and automation tools that automate the secure configuration, verification, compliance, and authorization of systems and their development. They will be a key member of a team tasked with maturing the organization's secure software development practices.

Long Job Description:
Functional Knowledge:
Chrome/Firefox/Edge Development tools to see the request/response headers
Experience with Application Security scanning tools (SAST, DAST, SCA, ASOC, Container/Cloud) a must.
Experience with Coverity, BlackDuck, SRM, Fortify a plus
HTTP Request/Response headers for web and Restful API calls
Ability to explain in detail any of the OWASP top 10 vulnerabilities
Cross Site Scripting, Injection attacks, SSRF, CSRF, XML entity, etc.
API Security
JWT
OAUTH/OIDC/PKCE
Web, API replay attacks
High-level understanding of containers
Cloud development experience (Azure, AWS, Google Cloud Platform)
 
Minimum of 5+ years of total IT related experience.
3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.)
3+ years with both compiled and interpreted languages such as Angular, React, Node.js, Java, Spring Boot, IBM WebSphere App server, Oracle JBoss, .NET stacks
3+ years with networking, infrastructure, secure application development and security automation (DevSecOps).
3+ years of hands-on knowledge building and deploying secure complex distributed web and mobile applications.


Thanks & Regards,

Naresh

Global IT Family
Email: