1

Nist Csf Audit Jobs (NOW HIRING)

$130 - $170/hr

Successful candidates will have proven experience in leading IT audit teams, applying internal control frameworks like COBIT, ISO 27001, NIST CSF, CIS, ITIL, understanding technology implications for ...

New

Senior IT Security Analyst

Madison, WI · On-site +1

$90K - $115K/yr

Can conduct risk assessments, control evaluations, and gap analyses mapped to NIST CSF to support audit readiness and compliance initiatives. * Like to collaborate with IT, Risk, Compliance, and ...

Senior Director, IT/Technology Audit

New York, NY · On-site

$102K - $135K/yr

The Senior IT Audit Director is a senior leadership role within Internal Audit, responsible for ... Working knowledge of major control frameworks and standards, including NIST CSF, COBIT, ISO 27001 ...

Senior Director, IT/Technology Audit

Newark, NJ · On-site

$98K - $129K/yr

The Senior IT Audit Director is a senior leadership role within Internal Audit, responsible for ... Working knowledge of major control frameworks and standards, including NIST CSF, COBIT, ISO 27001 ...

Senior Security Compliance Analyst

OR · On-site +1

$110K - $140K/yr

Prepare, coordinate, and manage ISO 27001 audits, including evidence collection, control implementation, and auditor engagement. * Ensure ongoing compliance with HIPAA, NIST CSF, and other regulatory ...

Showing results 21-40

Nist Csf Audit information

See salary details

$61K

$115.2K

$151.5K

How much do nist csf audit jobs pay per year?

As of Sep 5, 2026, the average yearly pay for nist csf audit in the United States is $115,198.00, according to ZipRecruiter salary data. Most workers in this role earn between $101,000.00 and $134,000.00 per year, depending on experience, location, and employer.

What is a NIST CSF audit?

A NIST CSF audit is a comprehensive assessment that evaluates an organization's alignment with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). This audit involves reviewing policies, procedures, and technical controls to ensure they meet the best practices outlined in the NIST CSF. The goal is to identify security gaps, measure cybersecurity maturity, and provide recommendations for improvement. Organizations often use the results to enhance their cybersecurity posture and demonstrate compliance to stakeholders.

What are the key skills and qualifications needed to thrive as a NIST CSF auditor?

To thrive as a NIST CSF Auditor, you need a strong understanding of cybersecurity frameworks, risk management, and compliance standards, often supported by a degree in information security or related certifications like CISSP or CISA. Familiarity with audit management tools, GRC (governance, risk, and compliance) platforms, and knowledge of NIST Cybersecurity Framework controls are typically required. Analytical thinking, attention to detail, and effective communication are crucial soft skills for evaluating systems and conveying findings to stakeholders. These competencies ensure thorough assessments, help organizations mitigate risks, and support regulatory compliance.

What are some common challenges faced during a NIST CSF audit, and how can candidates prepare to address them?

One common challenge in a NIST CSF audit is interpreting and applying the framework’s controls to a variety of organizational contexts, especially when existing processes do not perfectly align with NIST’s categories. Auditors often need to work closely with IT, security, and compliance teams to gather evidence and clarify ambiguities in documentation. To prepare, candidates should familiarize themselves with the NIST CSF categories, typical documentation requirements, and best practices for interviewing stakeholders. Building strong communication and analytical skills will help address gaps and ensure a thorough, efficient audit.

What is the difference between Nist Csf Audit vs Cybersecurity Analyst?

AspectNist Csf AuditCybersecurity Analyst
CertificationsISO 27001, CompTIA Security+, CISACompTIA Security+, CISSP, CEH
Work EnvironmentAudit teams, compliance departments, consulting firmsSecurity operations centers, IT departments, corporate offices
Primary FocusAssessing compliance with NIST CSF, identifying gapsMonitoring, analyzing, and responding to security threats
Industry UsageFinance, healthcare, government, regulated industriesAll industries with IT infrastructure

While both roles involve cybersecurity, a Nist Csf Audit focuses on evaluating an organization's adherence to the NIST Cybersecurity Framework, ensuring compliance and identifying gaps. A Cybersecurity Analyst actively monitors and responds to security threats, implementing security measures. The audit role emphasizes assessment and compliance, whereas the analyst role centers on operational security management.

More about Nist Csf Audit jobs

What cities are hiring for Nist Csf Audit jobs?

Cities with the most Nist Csf Audit job openings:

What states have the most Nist Csf Audit jobs?

States with the most job openings for Nist Csf Audit jobs include:

Infographic showing various Nist Csf Audit job openings in the United States as of August 2026, with employment types broken down into 92% Full Time, 5% Part Time, 1% Temporary, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $115,198 per year, or $55.4 per hour.

Cloud Solutions Architect

AHU Technologies, Inc.

Washington, DC • On-site

$100 - $120/hr

Full-time

Re-posted 25 days ago


Job description

Benefits:
  • SIEM platforms
  • CISM
  • CISSP
  • NIST 800-53
  • NIST CSF
  • Information Security

TITLE: Cloud Solutions Architect
LOCATION: Washington, DC/ Hybrid
MINIMUM EDUCATION: Bachelor's degree in IT, related field, or equivalent experience.
REQUIRED EXPERIENCE: 16 years
INTERVIEWS: Webcam Only
Job Description:
The client is looking for a person who has 16 years of experience in Cloud Solutions Architect. Hybrid position - required to report on-site at least once bi-weekly and as needed depending on project needs
Complete Description:
We are seeking a highly experienced Cybersecurity Architect / Strategic Consultant to lead and guide the development, implementation, and evolution of customer cybersecurity strategy. This role demands a deep understanding of cybersecurity frameworks, risk management, emerging technologies, and technical security controls and architecture. The ideal candidate will be a trusted advisor to senior leadership, aligning cybersecurity initiatives with business objectives to safeguard organizational assets and reputation.
Key Responsibilities:
Strategic Planning and Advisory:
• Develop and refine the organization's cybersecurity strategy, ensuring alignment with overall business goals.
• Provide expert guidance on implementing industry-standard security program frameworks such as NIST CSF, ISO 27001, and CIS Controls.
• Identify emerging threats and recommend proactive technical measures to mitigate risks.
• Design and enablement of cyber controls functions and processes based on CMMC / NIST 800-171, NIST 800-53
Risk Management:
• Familiarity with risk management frameworks like NIST RMF, ISO 27005, and FAIR.
• Conduct comprehensive cybersecurity risk assessments, identifying vulnerabilities and recommending remediation strategies.
• Develop and maintain a robust risk management program to address both IT and operational risks.
• Implement technical solutions to manage and monitor risk effectively, including vulnerability management tools.
Technical Oversight
• Design and validate secure network architectures, focusing on principles such as Zero Trust and least privilege.
• Evaluate and implement advanced security technologies, including EDR, SIEM, DLP, and intrusion detection/prevention systems.
• Provide hands-on technical assessments of infrastructure, applications, and cloud environments to ensure security compliance.
• Oversee penetration testing activities and ensure identified vulnerabilities are remediated.
Skills:
• Experience in Information Security. Required 15 Years
• Proven experience with NIST CSF, NIST 800-53, and NIST 800-171 frameworks. Required
• Proven track record of developing and executing cybersecurity strategies for organizations of varying sizes and industries. Required
• Hands-on experience with risk assessments, compliance audits, and incident response planning. Required
• Proficiency with technical tools such as vulnerability scanners, SIEM platforms, and EDR solutions Required
• Expertise in cloud security, Zero Trust architecture, and emerging technologies. Required
• Relevant certifications (e.g., CISSP, CISM, CISA, CRISC, OSCP, CEH, or GSEC). Required
Bachelor's or Master's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
Flexible work from home options available.
Compensation: $100.00 - $120.00 per hour
About Us
AHU Technologies INCis an IT consulting and permanent staffing firm that meets and exceeds the evolving IT service needs of leading corporations within the United States. We have been providing IT solutions to customers from different industry sectors, helping them control costs and release internal resources to focus on strategic issues.
AHU Technologies INC was co-founded by visionary young techno-commercial entrepreneurs who remain as our principal consultants. Maintaining working relationships with a cadre of other highly skilled independent consultants, we have a growing number of resources available for development projects. We are currently working on Various projects such as media entertainment, ERP Solutions, data warehousing, Web Applications, Telecommunications and medical to our clients all over the world.