Jobs › CISA Jobs
CISA Certification Careers
CISA Jobs in IT Audit, GRC and AI Governance
Search current positions that require or prefer the Certified Information Systems Auditor credential, including IT audit, technology risk, compliance, assurance, third-party risk and AI governance jobs. Every position is labeled CISA required, CISA preferred or CISA relevant, so you can focus on the opportunities that best match your experience.
Looking for careers with the U.S. Cybersecurity and Infrastructure Security Agency? Visit the official CISA careers page. This page is about the Certified Information Systems Auditor credential, not the federal agency.
CISA Job Market Snapshot
Updated September 12, 2026. Based on active positions currently listed by AI Governance Jobs; salary uses the 18 postings that disclose compensation and should not be read as the salary of every CISA professional. We never estimate figures the postings do not provide.
Live CISA jobs
Product GRC Subject Matter Expert, (V4G)
Digital Risk Services - SOC Reporting and HITRUST Managing Director
Risk Manager
Vice President, Internal Audit
Lead, Security Controls Assurance - SOX
Senior Governance Analyst
Principal Auditor – APAC & MEA Fungible Audit Team
Lead Principal Auditor – APAC & MEA Fungible Audit Team
Director, Cyber GRC
Senior GRC Analyst
Internal Audit Manager
ICT Risk Assessment Manager
Senior Manager, IT SOX
ICT GRC – Risk & Compliance Manager
Senior Manager, Internal Audit
DWS - Internal Auditor (m/f/d) IT Applications
Risk Services - Cyber Security Audit, Experienced/Senior Associate
Technology Audit Manager
ICT Risk Oversight Lead
Director, Internal Audit
Senior IT Internal Auditor
Director of Governance, Risk & Compliance (GRC)
Sr Manager, Governance, Risk, Compliance & Privacy
Senior Analyst, Security Risk
Senior GRC Program Manager
Security Risk Management Specialist II
DWS Internal Audit Manager - Technology & Security
Security Compliance, GRC Engineer
Subject Matter Expert, GTM GRC - V4G
Technical Audit Manager - CSO CTO (f/m/x)
Technology Auditor – Compliance & Anti-Financial Crime - Assistant Vice President
Senior Manager, Finance Governance
Director of Cybersecurity Governance, Risk and Compliance
IT SOX Controls Specialist
Internal Audit Manager
Auditor / Senior Auditor
AI Auditor
Staff Program Manager, Compliance
Governance, Risk, and Compliance Manager (IT)
Security Assurance Lead
SOX Senior IT Auditor
Senior Internal Auditor, Technology
Senior Manager, Internal Audit - Audit Automation & Technology Risk
Head of Government Cyber Integration
Compliance Analyst, Texas Institute for Electronics
EMEA Assurance Lead
Tech Governance - Security Compliance & Governance Engineer
IG Auditor/Program Analyst
NRO IG IT Auditor
The CISA Career Guide
What Jobs Can You Get With CISA?
CISA opens the audit and assurance track across technology and, increasingly, AI. The most common destinations are the IT audit ladder, the technology-risk and GRC functions, and the specialized controls jobs that keep regulated organizations honest.
Typical jobs include IT Auditor, Senior IT Auditor, and IT Audit Manager; Technology Risk Analyst and Manager; GRC Analyst and Manager; SOX and IT Controls Specialist; Third-Party Risk Analyst; Cybersecurity Compliance Manager; Internal Audit Manager or Director; and a growing set of AI-facing jobs such as AI Risk and Assurance Specialist, AI Governance Auditor, and Head of Audit, Controls, or Assurance.
CISA Career Paths
Certification opens doors, but progression is earned through scope, results, and leadership, not the credential alone. Common realistic paths include:
- IT Auditor → Senior IT Auditor → IT Audit Manager → Director of IT Audit
- Technology Risk Analyst → Technology Risk Manager → GRC Director
- IT Controls Specialist → AI Controls and Assurance Lead → Director of AI Governance Assurance
Skills Employers Want Alongside CISA
Employers consistently pair CISA with practical, demonstrable skills. The strongest candidates can point to hands-on work with IT general controls; SOX; SOC 1 and SOC 2; COBIT; the NIST frameworks; ISO 27001; and cloud controls. On the practice side, they want risk-based audit planning, evidence collection, control testing, and clear executive reporting, plus third-party risk, strong stakeholder communication, and a working grasp of AI control and governance frameworks.
How CISA Fits Into AI Governance
This is where a CISA holder has a distinct and underappreciated advantage. AI governance is not, at its core, a data-science problem; it is an assurance and controls problem. The organizations that will pass regulatory scrutiny are the ones that can prove their AI systems are inventoried, documented, tested, and monitored, and proving control effectiveness is exactly what auditors do.
CISA and IT-audit experience transfer directly into AI control design and testing, AI governance audits, model-risk assurance, and third-party AI risk. They apply to regulatory readiness, AI system inventories, documentation and evidence reviews, audit trails and accountability, continuous control monitoring, and the validation of responsible-AI policies. CISA is not exclusively an AI credential, but it provides one of the strongest assurance-and-controls foundations for a professional moving into AI governance.
CISA Salary and Market Information
The most reliable page-specific figures come from the live snapshot above, which reflects only the CISA-related jobs currently posted here and only the postings that disclose compensation. It is a picture of the live market on this board, not a claim about every CISA professional. For official information on the credential itself, its exam, and its requirements, consult ISACA's official CISA page. Treat any external average you encounter as context, with its source and date, never as a guaranteed salary.
Industries Hiring CISA Professionals
Demand for CISA-credentialed auditors is broad. Technology and financial services lead, followed by consulting and professional services, healthcare, government and the public sector, critical infrastructure, education, and mission-driven organizations. Any sector facing regulatory scrutiny over its systems, and now over its AI, needs people who can independently assess whether its controls actually work.
How to Present CISA on a Résumé
List the credential clearly, then make it earn its place. Connect CISA to measurable audit and control results: the audits you led and their scope, the controls you designed or tested, the risks you helped remediate, and the frameworks you applied. A credential backed by concrete outcomes and named frameworks, from SOX and SOC reporting to COBIT, NIST, and ISO 27001, reads far more convincingly than a line item on its own.
How CISA Compares to Related Credentials
| Credential | Primary career focus |
|---|---|
| CISA | IT audit, technology controls and assurance |
| CRISC | Technology and enterprise risk |
| CISM | Information-security program leadership |
| CISSP | Broad cybersecurity expertise and leadership |
| AIGP | AI governance and responsible-AI programs |
| CIA | Internal audit and audit leadership |
Most professionals combine credentials to match their responsibilities. An IT auditor moving into risk often pairs CISA with CRISC; a security leader adds CISM or CISSP; and auditors moving into AI oversight increasingly add the AIGP to sit at the intersection of controls and AI governance.
CISA Careers: Frequently Asked Questions
What is the CISA certification?
CISA, the Certified Information Systems Auditor, is ISACA's globally recognized credential for professionals who audit, assess, and provide assurance over information systems and technology controls. It signals demonstrated skill in IT audit, control evaluation, and reporting on the security and integrity of systems.
What jobs can you get with CISA?
CISA supports jobs such as IT auditor and senior IT auditor, IT audit manager and director, technology-risk analyst and manager, GRC analyst and manager, SOX and IT-controls specialist, third-party risk analyst, cybersecurity compliance manager, and increasingly AI risk, assurance, and governance-audit jobs.
Does every job on this page require CISA?
No. Every listing is labeled CISA Required, CISA Preferred, or CISA Relevant based on the employer's own wording. Required means the posting explicitly states CISA is required. Preferred means it is described as preferred, desired, or a plus. Relevant means the job clearly draws on CISA skills but the posting does not state that the credential is required or preferred.
Can you take the CISA exam before meeting the experience requirement?
Yes. You can sit for and pass the CISA exam before you have the required experience. You then have a defined window to submit evidence of the qualifying professional experience to be awarded the full certification. Confirm the current window and rules on the official ISACA page.
What is the CISA Associate pathway?
ISACA offers an Associate designation for candidates who pass the exam but do not yet meet the full experience requirement. It lets you demonstrate that you have passed while you accumulate the qualifying experience needed to convert to full CISA. Check ISACA for the current requirements and time limits.
Is CISA useful for AI governance careers?
Yes. CISA is not an AI-specific credential, but AI governance is fundamentally an assurance and controls discipline. IT-audit skills, control design and testing, evidence review, and independent assessment transfer directly into AI control testing, AI governance audits, model-risk assurance, and regulatory readiness.
What is the difference between CISA, CISM, and CRISC?
CISA centers on auditing and assurance of IT systems and controls. CISM focuses on leading and managing an information-security program. CRISC focuses on identifying and managing technology and enterprise risk. Many professionals hold more than one as their responsibilities broaden across audit, security, and risk.
Is CISA better than CISSP for an audit career?
For an audit or assurance career, CISA is usually the more directly relevant credential because it is built around auditing systems and controls. CISSP is broader cybersecurity expertise and leadership. They serve different goals, and some professionals hold both when a job spans audit and security.
Are remote CISA jobs available?
Yes. Many IT-audit, technology-risk, and compliance jobs are offered remote or hybrid. Use the Remote or Hybrid filter above to see the current remote CISA openings on the board, since availability changes as new jobs post.
How should CISA appear on a résumé?
List CISA clearly near your name or in a certifications section, then connect it to measurable audit and control outcomes, for example the scope of audits led, controls tested, or risks remediated. Reference the frameworks you have used, such as SOX, SOC 1 and SOC 2, COBIT, NIST, and ISO 27001, so the credential is backed by demonstrated work.
About This Page
Last reviewed: September 12, 2026. How jobs qualify: a job appears here when its posting references the CISA credential or Certified Information Systems Auditor in its title, description, or qualifications; each is then labeled Required, Preferred, or Relevant from the employer's own wording. Salary snapshot: computed live from the CISA jobs currently posted here, using only listings that disclose compensation, normalized to an annual basis. Credential facts reference ISACA's official CISA page. "CISA" on this page means the Certified Information Systems Auditor credential from ISACA, not the U.S. Cybersecurity and Infrastructure Security Agency. AI Governance Jobs is an independent job board and is not affiliated with or endorsed by ISACA. Your data is yours; we never sell it or use it to train AI.