1

Security Auditor Jobs (NOW HIRING)

Senior Full Stack Application Development Security Auditor Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications ...

Senior Full Stack Application Development Security Auditor Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications ...

TMPC is seeking a Security Auditor to join our growing team of diverse professionals. Background: * Graduated from an accredited Security/Law Enforcement/Counterintelligence course * Background and ...

TMPC is seeking a Security Auditor to join our growing team of diverse professionals. Background: * Graduated from an accredited Security/Law Enforcement/Counterintelligence course * Background and ...

System Security Auditor LOCATION Honolulu, HI 96815 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and analytical System ...

TMPC is seeking a Security Auditor to join our growing team of diverse professionals. Background: * Graduated from an accredited Security/Law Enforcement/Counterintelligence course * Background and ...

TMPC is seeking a Security Auditor to join our growing team of diverse professionals. Background: * Graduated from an accredited Security/Law Enforcement/Counterintelligence course * Background and ...

System Security Auditor LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and analytical System ...

System Security Auditor LOCATION Aurora, CO 80014 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and analytical System ...

System Security Auditor LOCATION San Antonio, TX 78208 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a meticulous and analytical ...

TMPC is seeking a Security Auditor to join our growing team of diverse professionals. Background: * Graduated from an accredited Security/Law Enforcement/Counterintelligence course * Background and ...

Short Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition ...

System Security Auditor LOCATIONChantilly, VA 20151 CLEARANCETS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARYWe are seeking a meticulous and analytical System ...

System Security Auditor LOCATIONAurora, CO 80014 CLEARANCETS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARYWe are seeking a meticulous and analytical System ...

System Security Auditor LOCATIONHonolulu, HI 96815 CLEARANCETS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARYWe are seeking a meticulous and analytical System ...

System Security Auditor LOCATIONTysons, VA 22182 CLEARANCETS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARYWe are seeking a meticulous and analytical System ...

System Security Auditor LOCATIONReston, VA 20190 CLEARANCETS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARYWe are seeking a meticulous and analytical System ...

next page

Showing results 1-20

Security Auditor information

See salary details

$11K

$90K

$140.5K

How much do security auditor jobs pay per year?

As of Jun 21, 2026, the average yearly pay for security auditor in the United States is $89,997.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,000.00 and $130,000.00 per year, depending on experience, location, and employer.

How to become a security auditor?

To become a security auditor, individuals typically need a bachelor's degree in cybersecurity, information technology, or a related field, along with experience in IT security. Earning certifications such as Certified Information Systems Auditor (CISA) or Certified Information Security Manager (CISM) can enhance job prospects. Strong analytical skills, knowledge of security frameworks, and familiarity with auditing tools are also important for success in this role.

Can you make $500,000 a year in cyber security?

Security auditors and senior cybersecurity professionals with extensive experience, advanced certifications, and specialized skills can potentially earn $500,000 or more annually, especially in high-demand industries or senior leadership roles. Achieving this level often requires years of experience, a strong track record, and expertise in areas like risk management, compliance, or security architecture.

What are the key skills and qualifications needed to thrive as a Security Auditor, and why are they important?

To thrive as a Security Auditor, you need a thorough understanding of information security principles, risk assessment methodologies, and compliance frameworks, often supported by a degree in cybersecurity or related fields. Familiarity with audit tools, vulnerability scanners, and certifications such as CISA or CISSP is typically expected. Analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying security gaps and conveying findings. These skills ensure that organizations maintain robust security postures and meet regulatory requirements.

What are some common challenges Security Auditors face when evaluating an organization's security controls?

Security Auditors often encounter challenges such as incomplete documentation, resistance to change from staff, and rapidly evolving technology environments. They must navigate complex IT infrastructures and ensure compliance with multiple regulatory frameworks, which can require juggling competing priorities and tight deadlines. Effective auditors use strong communication and analytical skills to identify vulnerabilities, explain risks, and collaborate with both technical teams and management to drive continual improvement.

What are Security Auditors?

Security Auditors are professionals who assess and evaluate an organization's information systems and security policies to ensure compliance with regulations and best practices. They identify vulnerabilities, review controls, and recommend improvements to prevent security breaches or data loss. Security Auditors often conduct regular audits, prepare detailed reports, and collaborate with IT and management teams to strengthen the organization's security posture.

How much do security auditors make?

Security auditors typically earn a median annual salary of around $70,000 to $100,000, depending on experience, certifications, and location. Senior or specialized auditors with certifications like CISSP or CISA can earn higher salaries, often exceeding $120,000 annually.

What Is a Security Auditor?

A security auditor is an IT professional in charge of evaluating cybersecurity for a company. As a security auditor, you regularly test information systems, looking for exploits or loopholes that would give an unscrupulous individual access to protected company information. Your job duties also include developing security protocols and working with other teams within the company to ensure everyone is kept up to date with the best practices and other protocols. You must also keep track of relevant laws and regulations, as well as new security threats, to maintain proper cybersecurity for your employer.

What is the difference between Security Auditor vs Security Analyst?

AspectSecurity AuditorSecurity Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, CompTIA Security+, GIAC Security Essentials
Work EnvironmentAudit firms, consulting companies, corporate compliance teamsIT departments, security operations centers, corporate environments
Primary FocusAssessing security policies, compliance, and controlsMonitoring security threats, incident response, and vulnerability management

While both roles focus on cybersecurity, Security Auditors primarily evaluate security policies and compliance through audits, whereas Security Analysts monitor and respond to security threats in real-time. Understanding these differences helps organizations assign the right professionals to their security needs.

What does a security auditor do?

A security auditor evaluates an organization's information systems, networks, and security policies to identify vulnerabilities and ensure compliance with security standards. They perform assessments using tools like vulnerability scanners and may prepare reports to recommend improvements, often holding certifications such as CISSP or CISA. Their work helps protect data and maintain the integrity of IT infrastructure.
What cities are hiring for Security Auditor jobs? Cities with the most Security Auditor job openings:
Who are the top companies hiring for Security Auditor jobs? The top employers for Security Auditor jobs are:
What states have the most Security Auditor jobs? States with the most job openings for Security Auditor jobs include:
Infographic showing various Security Auditor job openings in the United States as of June 2026, with employment types broken down into 11% Full Time, and 89% Part Time. Highlights an 87% Physical, 6% Hybrid, and 7% Remote job distribution, with an average salary of $89,997 per year, or $43.3 per hour.

Other

Posted 18 days ago


Job description

Senior Full Stack Application Development Security Auditor

Senior Full Stack Application Development Security Auditor who is passionate about designing and building secure platforms and applications through Dynamic, Static and Software Composition Analysis assessments.

This position is not a member of the Security Operations Center, rather it is dedicated to working with software development teams on secure coding practices.

The ideal candidate will feel comfortable working with both front-end, back-end and cloud-based application developers.

Partnering with distributed teams to help transform the way systems are built, secured, authorized and securely operated for continuous compliance and risk mitigation.

Specifically, this candidate will help lead efforts to implement security patterns and practices with orchestration and automation tools that automate the secure configuration, verification, compliance, and authorization of systems and their development.

They will be a key member of a team tasked with maturing the organization's secure software development practices.

Functional Knowledge:
  • Chrome/Firefox/Edge Development tools to see the request/response headers
  • Experience with Application Security scanning tools (SAST, DAST, SCA, ASOC, Container/Cloud) a must.
  • Experience with Coverity, BlackDuck, STRM, Fortify a plus
  • HTTP Request/Response headers for web and Restful API calls
  • Ability to explain in detail any of the OWASP top 10 vulnerabilities
  • Cross Site Scripting, Injection attacks, SSRF, CSRF, XML entity, etc.
  • API Security
  • JWT
  • OAUTH/OIDC/PKCE
  • Web, API replay attacks
  • High-level understanding of containers
  • Cloud development experience (Azure, AWS, GCP)

Minimum of 5+ years of total IT related experience.

  • 3+ years implementing/utilizing Federal, Industry and Open-Source Security Guidance and Secure Coding Practices (OWASP Top 10, SANS, CERT, CWE Top 25, Critical Security Controls, Cloud Security Alliance, SafeCode etc.)
  • 3+ years with both compiled and interpreted languages such as Angular, React, Node.js, Java, Spring Boot, IBM WebSphere App server, Oracle JBoss, .NET stacks
  • 3+ years with networking, infrastructure, secure application development and security automation (DevSecOps).
  • 3+ years of hands-on knowledge building and deploying secure complex distributed web and mobile applications.