1

Nist Jobsexternal in California (NOW HIRING)

Sr. RMF Security Engineer

San Diego, CA ยท On-site

$120 - $180/hr

Deep knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-171, FedRAMP, and DoD Instruction 8510.01. * Experience preparing SSP, SAR, and POA&M documents. * Proficiency with eMASS, SCAP tools (e ...

AI Architect

Poway, CA ยท On-site

Damco Solutions is seeking an AI Architect to design air-gapped AI pipelines that comply with NIST SP 800-171 and CMMC Level 3. The role involves managing a bi-modal pod that includes US classified ...

NIST SP 800-171 Rev 2, NIST 800-53 Rev 5). This will be a full-time , exempt position located in our Long Beach location. Responsibilities: * Maintain compliance documentation across NIST 800-171r2 ...

GRC Analyst

San Francisco, CA ยท On-site

$110 - $160/hr

About the Role As a Cybersecurity Analyst will work closely with customers to help them implement and fully leverage Atomus' cybersecurity products, maintain compliance with NIST 800-171 and CMMC ...

Sr. RMF Security Engineer

San Diego, CA ยท On-site

$131K - $237K/yr

Deep knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-171, FedRAMP, and DoD Instruction 8510.01 (DIARMF). * Security Assessment & Authorization (SA&A): * Experience preparing System Security ...

Sr. RMF Security Engineer

San Diego, CA ยท On-site

$131K - $237K/yr

Deep knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-171, FedRAMP, and DoD Instruction 8510.01 (DIARMF). * Security Assessment & Authorization (SA&A): * Experience preparing System Security ...

next page

Showing results 1-20

Nist information

See California salary details

$42.4K

$98.1K

$148K

How much do nist jobs pay per year?

As of Sep 5, 2026, the average yearly pay for nist in California is $98,098.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,500.00 and $114,000.00 per year, depending on experience, location, and employer.

What is a NIST professional?

NIST professionals are experts who work for the National Institute of Standards and Technology, a U.S. federal agency that develops technology, metrics, and standards to promote innovation and industrial competitiveness. Their work covers a wide range of fields including cybersecurity, engineering, physical sciences, and information technology. NIST professionals conduct research, create standards, and provide guidance to improve the security, quality, and efficiency of products and services in both the public and private sectors.

What are the key skills and qualifications needed to thrive as a NIST professional?

To excel as a professional at NIST, you need a strong background in science or engineering, often supported by an advanced degree in a relevant technical field. Familiarity with specialized laboratory equipment, data analysis software, and quality management systems such as ISO/IEC standards is typically required. Critical thinking, attention to detail, and effective teamwork are important soft skills that help drive research accuracy and collaborative innovation. These skills are crucial for advancing measurement science, ensuring rigorous standards, and supporting technological progress across industries.

What are some common challenges faced by NIST cybersecurity professionals when implementing new security frameworks in an organization?

NIST cybersecurity professionals often encounter challenges such as gaining organizational buy-in for new security frameworks, ensuring that existing systems are compatible with the latest NIST standards, and managing the complexities of compliance across multiple departments. Additionally, balancing thorough risk assessments with tight project timelines can be demanding. Collaborating closely with IT, compliance, and executive teams is essential to address these challenges and to ensure successful framework implementation.

What is the difference between Nist vs Cybersecurity Analyst?

AspectNistCybersecurity Analyst
CertificationsTypically no specific certifications required, but familiarity with NIST frameworks is essentialOften requires certifications like CompTIA Security+, CISSP, or CEH
Work EnvironmentDevelops and maintains cybersecurity standards and frameworks for organizationsMonitors, analyzes, and responds to security threats within organizations
Industry UsageUsed across industries for cybersecurity best practices and complianceEmployed in various sectors to protect information systems
Primary FocusCreating and implementing cybersecurity standards based on NIST guidelinesDetecting and mitigating security incidents and vulnerabilities

While NIST focuses on developing cybersecurity standards and frameworks, a Cybersecurity Analyst applies these standards in practical security operations. Both roles are essential in maintaining organizational cybersecurity, with NIST providing the foundational guidelines and the analyst executing security measures based on those guidelines.

What cities in California are hiring for Nist jobs?

Cities in California with the most Nist job openings:

Infographic showing various Nist job openings in California as of August 2026, with employment types broken down into 87% Full Time, and 13% Contract. Highlights an 100% In-person job distribution, with an average salary of $98,098 per year, or $47.2 per hour.

Cybersecurity GRC Consultant - NIST CSF 2.0

Mergen IT LLC

San Francisco, CA โ€ข On-site

Other

Posted 24 days ago


Job description

Role: Cybersecurity GRC Consultant โ€“ NIST CSF 2.0

Location: San Francisco, CA (Onsite)

Role Purpose

Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk-based gap prioritization, executive reporting, and development of a practical improvement roadmap.

Key Responsibilities

  • Own end to end engagement governance, project planning, milestones, risks, dependencies, status reporting, and stakeholder communications.
  • Conduct NIST CSF 2.0 maturity assessment across functions, categories, subcategories, implementation tiers, and profiles.
  • Review policies, standards, procedures, controls, risk registers, asset inventories, KPIs/KRIs, and supporting evidence.
  • Facilitate interviews and workshops with cybersecurity, risk, compliance, technology, and business stakeholders.
  • Define defensible maturity scoring, identify control gaps, assess business risk, and prioritize remediation actions.
  • Develop executive ready assessment reports, maturity dashboards, prioritized recommendations, and near/mid/long term roadmap.

Required Experience

Area

Requirement

Total Experience

10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment.

NIST CSF Expertise

Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments.

Framework Mapping

Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks.

Assessment Delivery

Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments.

Stakeholder Management

Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders.

Executive Reporting

Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations.

Consulting Delivery

Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables.

Risk Prioritization

Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps.

Required Skills

  • Strong expertise in NIST CSF 2.0, cybersecurity governance, risk management, compliance, control maturity models, and ISO 27001 / ISMS.
  • Ability to map controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, and similar frameworks.
  • Experience in evidence-based assessment, maturity scoring, risk-based gap prioritization, and remediation roadmap development.
  • Excellent consulting delivery, workshop facilitation, stakeholder management, executive reporting, and written/verbal communication skills.

Preferred Certifications

CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor / Lead Implementer, NIST CSF training/certification, PMP / Prince2 / Agile certification preferred.

Tools / Platforms Knowledge Preferred

  • GRC and evidence management platforms such as Archer, ServiceNow GRC, OneTrust, MetricStream, SharePoint, Teams, Excel, PowerPoint, Visio, Power BI, and cybersecurity KPI/KRI dashboarding tools.