1

Nist Csf Audit Jobs (NOW HIRING)

... Framework (CSF), NIST Special Publication 800-53, ISO 27001, and client security policies ... Tracks audit findings, validates corrective actions and reports remediation status and residual ...

... CSF), NIST Special Publication 800-53, ISO 27001, and Commonwealth security policies. Identifies ... Tracks audit findings, validates corrective actions and reports remediation status and residual ...

IT Audit Liaison

Harrisburg, PA · Hybrid

$20 - $24/hr

IT Audit Liaison *This is a hybrid role requiring 3 days/week onsite. *Local to the Harrisburg, PA ... NIST CSF, NIST 800-53, ISO 27001, and related frameworks, Highly desired Preferred Qualifications:

New

About This Role at Momentum What You'll Do SOC 2 & NIST CSF Program * Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline ...

Gather and organize control evidence to support ISO 27001, SOC 2, and NIST CSF audits for the Risk and Compliance team, and support digital forensics requests from Security Operations * Track ...

Gather and organize control evidence to support ISO 27001, SOC 2, and NIST CSF audits for the Risk and Compliance team, and support digital forensics requests from Security Operations * Track ...

About This Role at Momentum What You'll Do SOC 2 & NIST CSF Program * Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline ...

Gather and organize control evidence to support ISO 27001, SOC 2, and NIST CSF audits for the Risk and Compliance team, and support digital forensics requests from Security Operations * Track ...

Gather and organize control evidence to support ISO 27001, SOC 2, and NIST CSF audits for the Risk and Compliance team, and support digital forensics requests from Security Operations * Track ...

next page

Showing results 1-20

Nist Csf Audit information

See salary details

$61K

$115.2K

$151.5K

How much do nist csf audit jobs pay per year?

As of Aug 15, 2026, the average yearly pay for nist csf audit in the United States is $115,198.00, according to ZipRecruiter salary data. Most workers in this role earn between $101,000.00 and $134,000.00 per year, depending on experience, location, and employer.

What is a NIST CSF audit?

A NIST CSF audit is a comprehensive assessment that evaluates an organization's alignment with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). This audit involves reviewing policies, procedures, and technical controls to ensure they meet the best practices outlined in the NIST CSF. The goal is to identify security gaps, measure cybersecurity maturity, and provide recommendations for improvement. Organizations often use the results to enhance their cybersecurity posture and demonstrate compliance to stakeholders.

What are some common challenges faced during a NIST CSF audit, and how can candidates prepare to address them?

One common challenge in a NIST CSF audit is interpreting and applying the framework’s controls to a variety of organizational contexts, especially when existing processes do not perfectly align with NIST’s categories. Auditors often need to work closely with IT, security, and compliance teams to gather evidence and clarify ambiguities in documentation. To prepare, candidates should familiarize themselves with the NIST CSF categories, typical documentation requirements, and best practices for interviewing stakeholders. Building strong communication and analytical skills will help address gaps and ensure a thorough, efficient audit.

What is the difference between Nist Csf Audit vs Cybersecurity Analyst?

AspectNist Csf AuditCybersecurity Analyst
CertificationsISO 27001, CompTIA Security+, CISACompTIA Security+, CISSP, CEH
Work EnvironmentAudit teams, compliance departments, consulting firmsSecurity operations centers, IT departments, corporate offices
Primary FocusAssessing compliance with NIST CSF, identifying gapsMonitoring, analyzing, and responding to security threats
Industry UsageFinance, healthcare, government, regulated industriesAll industries with IT infrastructure

While both roles involve cybersecurity, a Nist Csf Audit focuses on evaluating an organization's adherence to the NIST Cybersecurity Framework, ensuring compliance and identifying gaps. A Cybersecurity Analyst actively monitors and responds to security threats, implementing security measures. The audit role emphasizes assessment and compliance, whereas the analyst role centers on operational security management.

What are the key skills and qualifications needed to thrive as a NIST CSF auditor?

To thrive as a NIST CSF Auditor, you need a strong understanding of cybersecurity frameworks, risk management, and compliance standards, often supported by a degree in information security or related certifications like CISSP or CISA. Familiarity with audit management tools, GRC (governance, risk, and compliance) platforms, and knowledge of NIST Cybersecurity Framework controls are typically required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for evaluating systems and conveying findings to stakeholders. These competencies ensure thorough assessments, help organizations mitigate risks, and support regulatory compliance.
More about Nist Csf Audit jobs

What cities are hiring for Nist Csf Audit jobs?

Cities with the most Nist Csf Audit job openings:

What states have the most Nist Csf Audit jobs?

States with the most job openings for Nist Csf Audit jobs include:

Infographic showing various Nist Csf Audit job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 90% Full Time, 5% Part Time, 1% Temporary, and 3% Contract. Highlights an 86% Physical, 6% Hybrid, and 8% Remote job distribution, with an average salary of $115,198 per year, or $55.4 per hour.

Cybersecurity GRC Consultant - NIST CSF 2.0

Mergen IT LLC

San Francisco, CA • On-site

Other

Posted 4 days ago


Job description

Role: Cybersecurity GRC Consultant – NIST CSF 2.0

Location: San Francisco, CA (Onsite)

Role Purpose

Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk-based gap prioritization, executive reporting, and development of a practical improvement roadmap.

Key Responsibilities

  • Own end to end engagement governance, project planning, milestones, risks, dependencies, status reporting, and stakeholder communications.
  • Conduct NIST CSF 2.0 maturity assessment across functions, categories, subcategories, implementation tiers, and profiles.
  • Review policies, standards, procedures, controls, risk registers, asset inventories, KPIs/KRIs, and supporting evidence.
  • Facilitate interviews and workshops with cybersecurity, risk, compliance, technology, and business stakeholders.
  • Define defensible maturity scoring, identify control gaps, assess business risk, and prioritize remediation actions.
  • Develop executive ready assessment reports, maturity dashboards, prioritized recommendations, and near/mid/long term roadmap.

Required Experience

Area

Requirement

Total Experience

10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment.

NIST CSF Expertise

Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments.

Framework Mapping

Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks.

Assessment Delivery

Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments.

Stakeholder Management

Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders.

Executive Reporting

Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations.

Consulting Delivery

Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables.

Risk Prioritization

Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps.

Required Skills

  • Strong expertise in NIST CSF 2.0, cybersecurity governance, risk management, compliance, control maturity models, and ISO 27001 / ISMS.
  • Ability to map controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, and similar frameworks.
  • Experience in evidence-based assessment, maturity scoring, risk-based gap prioritization, and remediation roadmap development.
  • Excellent consulting delivery, workshop facilitation, stakeholder management, executive reporting, and written/verbal communication skills.

Preferred Certifications

CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor / Lead Implementer, NIST CSF training/certification, PMP / Prince2 / Agile certification preferred.

Tools / Platforms Knowledge Preferred

  • GRC and evidence management platforms such as Archer, ServiceNow GRC, OneTrust, MetricStream, SharePoint, Teams, Excel, PowerPoint, Visio, Power BI, and cybersecurity KPI/KRI dashboarding tools.