Required Experience Area Requirement Total Experience 10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment. NIST CSF Expertise Strong ...
Required Experience Area Requirement Total Experience 10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment. NIST CSF Expertise Strong ...
GRC Lead / Cyber Risk Manager
$125K - $169K/yr
Perform gap assessments and maturity evaluations using NIST CSF Compliance & Audit * Ensure compliance with federal, state, and industry regulations for NIST RMF, and FISMA as applicable. * Lead ...
Quick apply
GRC Lead / Cyber Risk Manager
$125K - $169K/yr
Perform gap assessments and maturity evaluations using NIST CSF Compliance & Audit * Ensure compliance with federal, state, and industry regulations for NIST RMF, and FISMA as applicable. * Lead ...
GRC Lead / Cyber Risk Manager
Washington, DC · On-site
$125K - $169K/yr
NIST Cybersecurity Framework (CSF) NIST Risk Management Framework (RMF) NIST SP 800-53 / 800-171 Experience supporting audits, compliance programs, and regulatory frameworks Proven ability to lead ...
GRC Lead / Cyber Risk Manager
Washington, DC · On-site
$125K - $169K/yr
NIST Cybersecurity Framework (CSF) NIST Risk Management Framework (RMF) NIST SP 800-53 / 800-171 Experience supporting audits, compliance programs, and regulatory frameworks Proven ability to lead ...
Senior Security Auditor
Houston, TX · On-site
$160K - $220K/yr
... audit programs, and translate security frameworks (NIST CSF 2.0, NIST 800-53, PCI DSS, FTC Safeguards) into test procedures. - Assess controls through walkthroughs, configuration reviews, and log ...
Senior Security Auditor
Houston, TX · On-site
$160K - $220K/yr
... audit programs, and translate security frameworks (NIST CSF 2.0, NIST 800-53, PCI DSS, FTC Safeguards) into test procedures. - Assess controls through walkthroughs, configuration reviews, and log ...
GRC Analyst
Dallas, TX · On-site
About This Role at Momentum What You'll Do SOC 2 & NIST CSF Program * Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline ...
GRC Analyst
Dallas, TX · On-site
About This Role at Momentum What You'll Do SOC 2 & NIST CSF Program * Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline ...
Risk Cyber Internal Audit Senior Associate
New York, NY · On-site
$101K - $129K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Risk Cyber Internal Audit Senior Associate
New York, NY · On-site
$101K - $129K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Risk Cyber Internal Audit Senior Associate
New York, NY · On-site
$101K - $129K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Risk Cyber Internal Audit Senior Associate
New York, NY · On-site
$101K - $129K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Risk Cyber Internal Audit Senior Associate
New York, NY · On-site
$101K - $129K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Risk Cyber Internal Audit Senior Associate
New York, NY · On-site
$101K - $129K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
You'll partner with Security Engineering, IT, Audit, and business control owners to streamline ... Model the control framework in OneTrust: map NIST CSF and NIST 800‑53 control families, control ...
Quick apply
You'll partner with Security Engineering, IT, Audit, and business control owners to streamline ... Model the control framework in OneTrust: map NIST CSF and NIST 800‑53 control families, control ...
Information Security Engineer, GRC
Fountain Inn, SC · On-site
$100 - $130/hr
... NIST CSF, NIST SP 800-53, NIST RMF, NIST SP 800-171), CIS 8.1, and ISO 27001. * Hands‑on experience conducting risk assessments, control assessments, and audit responses. * Experience with ...
New
Information Security Engineer, GRC
Fountain Inn, SC · On-site
$100 - $130/hr
... NIST CSF, NIST SP 800-53, NIST RMF, NIST SP 800-171), CIS 8.1, and ISO 27001. * Hands‑on experience conducting risk assessments, control assessments, and audit responses. * Experience with ...
New
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$130 - $180/hr
Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit ... Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$130 - $180/hr
Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit ... Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
Cyber Compliance Analyst
Las Vegas, NV · On-site
$90 - $130/hr
Practical experience participating in and leading SOC 1, SOC 2, and MUSL audits * Familiarity with ISO 27001 and PCI DSS certifications * Familiarity with NIST CSF and NIST 800-53 frameworks
Posted today
Cyber Compliance Analyst
Las Vegas, NV · On-site
$90 - $130/hr
Practical experience participating in and leading SOC 1, SOC 2, and MUSL audits * Familiarity with ISO 27001 and PCI DSS certifications * Familiarity with NIST CSF and NIST 800-53 frameworks
Posted today
Support NIST CSF control assessments, risk identification, and cybersecurity compliance activities * Maintain control documentation, risk-control matrices, procedures, and audit records * Collaborate ...
Support NIST CSF control assessments, risk identification, and cybersecurity compliance activities * Maintain control documentation, risk-control matrices, procedures, and audit records * Collaborate ...
Risk Cyber Internal Audit Manager
New York, NY · On-site
$138K - $172K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Risk Cyber Internal Audit Manager
New York, NY · On-site
$138K - $172K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Risk Cyber Internal Audit Manager
New York, NY · On-site
$138K - $172K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Risk Cyber Internal Audit Manager
New York, NY · On-site
$138K - $172K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Risk Cyber Internal Audit Manager
New York, NY · On-site
$138K - $172K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Risk Cyber Internal Audit Manager
New York, NY · On-site
$138K - $172K/yr
As a member of Grant Thornton's Cybersecurity Internal Audit (IA Cybersecurity) team, you will have ... Conduct Cybersecurity maturity assessments using frameworks such as NIST CSF, CSA CCM, ISO/IEC ...
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$140 - $180/hr
Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit ... Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$140 - $180/hr
Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit ... Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
Senior Cyber Security & GRC Engineer
Houston, TX · On-site
$120 - $160/hr
Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit ... Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
Senior Cyber Security & GRC Engineer
Houston, TX · On-site
$120 - $160/hr
Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit ... Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$150K - $170K/yr
Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit ... Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
Senior Cyber Security & GRC Engineer
Hartford, CT · On-site
$150K - $170K/yr
Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit ... Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
Cloud Solutions Architect
Washington, DC · On-site
$140 - $160/hr
Proven experience with NIST CSF, NIST 800-53, and NIST 800-171 frameworks. * Proven track record of ... Hands-on experience with risk assessments, compliance audits, and incident response planning.
Cloud Solutions Architect
Washington, DC · On-site
$140 - $160/hr
Proven experience with NIST CSF, NIST 800-53, and NIST 800-171 frameworks. * Proven track record of ... Hands-on experience with risk assessments, compliance audits, and incident response planning.
Nist Csf Audit information
See salary details
$61K - $69.2K
3% of jobs
$69.2K - $77.5K
9% of jobs
$77.5K - $85.7K
3% of jobs
$85.7K - $93.9K
3% of jobs
$101.8K is the 25th percentile. Wages below this are outliers.
$93.9K - $102.1K
6% of jobs
$102.1K - $110.4K
13% of jobs
The median wage is $115.6K / yr.
$110.4K - $118.6K
19% of jobs
$118.6K - $126.8K
13% of jobs
$131.6K is the 75th percentile. Wages above this are outliers.
$126.8K - $135K
9% of jobs
$135K - $143.3K
16% of jobs
$143.3K - $151.5K
5% of jobs
$61K
$115.2K
$151.5K
How much do nist csf audit jobs pay per year?
What is a NIST CSF audit?
What are the key skills and qualifications needed to thrive as a NIST CSF auditor?
What are some common challenges faced during a NIST CSF audit, and how can candidates prepare to address them?
What is the difference between Nist Csf Audit vs Cybersecurity Analyst?
| Aspect | Nist Csf Audit | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CompTIA Security+, CISA | CompTIA Security+, CISSP, CEH |
| Work Environment | Audit teams, compliance departments, consulting firms | Security operations centers, IT departments, corporate offices |
| Primary Focus | Assessing compliance with NIST CSF, identifying gaps | Monitoring, analyzing, and responding to security threats |
| Industry Usage | Finance, healthcare, government, regulated industries | All industries with IT infrastructure |
While both roles involve cybersecurity, a Nist Csf Audit focuses on evaluating an organization's adherence to the NIST Cybersecurity Framework, ensuring compliance and identifying gaps. A Cybersecurity Analyst actively monitors and responds to security threats, implementing security measures. The audit role emphasizes assessment and compliance, whereas the analyst role centers on operational security management.
What cities are hiring for Nist Csf Audit jobs?
Cities with the most Nist Csf Audit job openings:
What states have the most Nist Csf Audit jobs?
States with the most job openings for Nist Csf Audit jobs include:
What job categories do people searching Nist Csf Audit jobs look for?
The top searched job categories for Nist Csf Audit jobs are:

Other
Posted 24 days ago
Job description
Role: Cybersecurity GRC Consultant – NIST CSF 2.0
Location: San Francisco, CA (Onsite)
Role Purpose
Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk-based gap prioritization, executive reporting, and development of a practical improvement roadmap.
Key Responsibilities
- Own end to end engagement governance, project planning, milestones, risks, dependencies, status reporting, and stakeholder communications.
- Conduct NIST CSF 2.0 maturity assessment across functions, categories, subcategories, implementation tiers, and profiles.
- Review policies, standards, procedures, controls, risk registers, asset inventories, KPIs/KRIs, and supporting evidence.
- Facilitate interviews and workshops with cybersecurity, risk, compliance, technology, and business stakeholders.
- Define defensible maturity scoring, identify control gaps, assess business risk, and prioritize remediation actions.
- Develop executive ready assessment reports, maturity dashboards, prioritized recommendations, and near/mid/long term roadmap.
Required Experience
Area
Requirement
Total Experience
10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment.
NIST CSF Expertise
Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments.
Framework Mapping
Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks.
Assessment Delivery
Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments.
Stakeholder Management
Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders.
Executive Reporting
Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations.
Consulting Delivery
Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables.
Risk Prioritization
Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps.
Required Skills
- Strong expertise in NIST CSF 2.0, cybersecurity governance, risk management, compliance, control maturity models, and ISO 27001 / ISMS.
- Ability to map controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, and similar frameworks.
- Experience in evidence-based assessment, maturity scoring, risk-based gap prioritization, and remediation roadmap development.
- Excellent consulting delivery, workshop facilitation, stakeholder management, executive reporting, and written/verbal communication skills.
Preferred Certifications
CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor / Lead Implementer, NIST CSF training/certification, PMP / Prince2 / Agile certification preferred.
Tools / Platforms Knowledge Preferred
- GRC and evidence management platforms such as Archer, ServiceNow GRC, OneTrust, MetricStream, SharePoint, Teams, Excel, PowerPoint, Visio, Power BI, and cybersecurity KPI/KRI dashboarding tools.
About Mergen IT
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Houston, TX, US
Year founded
2014