GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsCISA Jobs

CISA Certification Careers

CISA Jobs in IT Audit, GRC and AI Governance

Search current positions that require or prefer the Certified Information Systems Auditor credential, including IT audit, technology risk, compliance, assurance, third-party risk and AI governance jobs. Every position is labeled CISA required, CISA preferred or CISA relevant, so you can focus on the opportunities that best match your experience.

Looking for careers with the U.S. Cybersecurity and Infrastructure Security Agency? Visit the official CISA careers page. This page is about the Certified Information Systems Auditor credential, not the federal agency.

Get new CISA jobs when they are posted

Receive new IT audit, technology-risk, GRC and AI-assurance opportunities that match the CISA credential.

Free and confidential. Unsubscribe anytime. This is a CISA job alert, separate from the GRC Careers newsletter.

CISA Job Market Snapshot

Active CISA-related jobs
49
Remote or hybrid
18%
Median advertised salary
$136k
Listings showing salary
37%
Most common category
Audit
Most active location
Washington, District of Columbia
Most common level
Senior

Updated September 12, 2026. Based on active positions currently listed by AI Governance Jobs; salary uses the 18 postings that disclose compensation and should not be read as the salary of every CISA professional. We never estimate figures the postings do not provide.

49 CISA jobs

Live CISA jobs

CISA RequiredGRC

Product GRC Subject Matter Expert, (V4G)

Vanta
Remote · Full-time
Posted Sep 7, 2026
CISA RequiredIT Audit

Digital Risk Services - SOC Reporting and HITRUST Managing Director

Elliott Davis
On-site · Charlotte, NC · Full-time
Posted Aug 31, 2026
CISA RequiredTechnology Risk

Risk Manager

Betterment
On-site · Betterment HQ - New York City · Full-time
$140k to $155k Posted Aug 11, 2026
CISA RequiredIT Audit

Vice President, Internal Audit

Cloudflare
On-site · Hybrid · Full-time
$300k to $375k Posted Aug 11, 2026
CISA PreferredGRC

Lead, Security Controls Assurance - SOX

Anthropic
On-site · San Francisco, CA, WA New York City · Full-time
$410k Posted Sep 10, 2026
CISA PreferredGRC

Senior Governance Analyst

GE Vernova
On-site · 5 Locations · Full-time
$91k Posted Sep 8, 2026
CISA PreferredIT Audit

Principal Auditor – APAC & MEA Fungible Audit Team

Deutsche Bank
On-site · Mumbai Nirlon Knowledge Pk B1 · Full-time
Posted Sep 8, 2026
CISA PreferredIT Audit

Lead Principal Auditor – APAC & MEA Fungible Audit Team

Deutsche Bank
On-site · Mumbai Nirlon Knowledge Pk B1 · Full-time
Posted Sep 8, 2026
CISA PreferredCybersecurity

Director, Cyber GRC

Mariner
On-site · United States · Full-time
Posted Sep 7, 2026
CISA PreferredGRC

Senior GRC Analyst

Gusto
On-site · San Francisco, CA · Full-time
$183k Posted Sep 7, 2026
Hiring professionals with CISA, IT audit or technology-risk experience? Post your position on AI Governance Jobs.
CISA PreferredIT Audit

Internal Audit Manager

Kraken
On-site · United States · Full-time
Posted Sep 7, 2026
CISA PreferredTechnology Risk

ICT Risk Assessment Manager

N26
On-site · Berlin · Full-time
Posted Sep 7, 2026
CISA PreferredGRC

Senior Manager, IT SOX

Anthropic
On-site · San Francisco, CA · Full-time
$230k Posted Sep 7, 2026
CISA PreferredCompliance

ICT GRC – Risk & Compliance Manager

N26
On-site · Berlin · Full-time
Posted Sep 7, 2026
CISA PreferredIT Audit

Senior Manager, Internal Audit

Workday
On-site · CA, Pleasanton · Full-time
$167k Posted Sep 7, 2026
CISA PreferredIT Audit

DWS - Internal Auditor (m/f/d) IT Applications

Deutsche Bank
On-site · Frankfurt Weserst 54 Mainz Landst 11-17 · Full-time
Posted Sep 7, 2026
CISA PreferredIT Audit

Risk Services - Cyber Security Audit, Experienced/Senior Associate

PwC
On-site · Singapore · Full-time
Posted Aug 31, 2026
CISA PreferredIT Audit

Technology Audit Manager

TD Bank
On-site · Dublin, Ireland · Full-time
Posted Aug 31, 2026
CISA PreferredTechnology Risk

ICT Risk Oversight Lead

Robinhood
On-site · Luxembourg · Full-time
Posted Aug 30, 2026
CISA PreferredIT Audit

Director, Internal Audit

Oscar Health
On-site · Tempe, Arizona · Full-time
$162k to $213k Posted Aug 27, 2026
CISA PreferredIT Audit

Senior IT Internal Auditor

Okta
On-site · San Francisco, California · Full-time
$117k Posted Aug 22, 2026
CISA PreferredAI Governance

Director of Governance, Risk & Compliance (GRC)

State of Maryland (DoIT)
On-site · Crownsville, MD · Full-time
Posted Aug 18, 2026
CISA PreferredCompliance

Sr Manager, Governance, Risk, Compliance & Privacy

Data Analysis Inc
Plano, TX · Full-time
Posted Aug 13, 2026
CISA PreferredTechnology Risk

Senior Analyst, Security Risk

Twilio
Remote · Full-time
Posted Aug 11, 2026
CISA PreferredGRC

Senior GRC Program Manager

Ripple
On-site · Luxembourg · Full-time
Posted Jun 20, 2026
CISA RelevantTechnology Risk

Security Risk Management Specialist II

Affirm
Remote · Canada Remote · Full-time
$101k to $151k Posted Sep 10, 2026
CISA RelevantIT Audit

DWS Internal Audit Manager - Technology & Security

Deutsche Bank
On-site · Pune - Business Bay · Full-time
Posted Sep 8, 2026
CISA RelevantCompliance

Security Compliance, GRC Engineer

Mistral AI
On-site · Paris · Full-time
Posted Sep 7, 2026
CISA RelevantGRC

Subject Matter Expert, GTM GRC - V4G

Vanta
Remote · Full-time
Posted Sep 7, 2026
CISA RelevantIT Audit

Technical Audit Manager - CSO CTO (f/m/x)

Deutsche Bank
On-site · Bucharest, 6A Dimitrie Pompeiu Blvd · Full-time
Posted Sep 7, 2026
CISA RelevantIT Audit

Technology Auditor – Compliance & Anti-Financial Crime - Assistant Vice President

Deutsche Bank
On-site · Jacksonville, 5201 Gate Parkway · Full-time
$78k to $121k Posted Sep 7, 2026
CISA RelevantGRC

Senior Manager, Finance Governance

Rehlko
On-site · Milwaukee, WI · Full-time
$117k to $150k Posted Sep 7, 2026
CISA RelevantCybersecurity

Director of Cybersecurity Governance, Risk and Compliance

UT Austin
On-site · UT MAIN CAMPUS · Full-time
$170k Posted Sep 3, 2026
CISA RelevantGRC

IT SOX Controls Specialist

Stripe
On-site · SEA, SF, NYC · Full-time
Posted Aug 31, 2026
CISA RelevantIT Audit

Internal Audit Manager

Coinbase
Remote · Luxembourg Remote · Full-time
Posted Aug 30, 2026
CISA RelevantIT Audit

Auditor / Senior Auditor

House of Representatives
On-site · Washington, District of Columbia · Full-time
$122k to $150k Posted Aug 29, 2026
CISA RelevantAI Governance

AI Auditor

GRC Careers
Remote · Full-time
Posted Aug 27, 2026
CISA RelevantCompliance

Staff Program Manager, Compliance

Zscaler
On-site · Mohali, IND · Full-time
Posted Aug 22, 2026
CISA RelevantIT Audit

Governance, Risk, and Compliance Manager (IT)

Weaver
Hybrid · Dallas, TX · Full-time
$85k to $150k Posted Aug 14, 2026
CISA RelevantGRC

Security Assurance Lead

Scale AI
On-site · Washington, DC · Full-time
Posted Aug 11, 2026
CISA RelevantIT Audit

SOX Senior IT Auditor

Okta
On-site · Bengaluru, India · Full-time
Posted Aug 11, 2026
CISA RelevantIT Audit

Senior Internal Auditor, Technology

GitLab
Remote · Canada Remote · Full-time
$86k Posted Aug 11, 2026
CISA RelevantIT Audit

Senior Manager, Internal Audit - Audit Automation & Technology Risk

GitLab
On-site · Bangalore, India · Full-time
Posted Aug 11, 2026
CISA RelevantCybersecurity

Head of Government Cyber Integration

OpenAI
Remote · Full-time
Posted Jul 27, 2026
CISA RelevantCompliance

Compliance Analyst, Texas Institute for Electronics

UT Austin
On-site · 2 Locations · Full-time
Posted Jun 28, 2026
CISA RelevantGRC

EMEA Assurance Lead

Scale AI
On-site · Doha, Qatar · Full-time
Posted Jun 28, 2026
CISA RelevantCompliance

Tech Governance - Security Compliance & Governance Engineer

OKX
On-site · Hong Kong, Hong Kong SAR · Full-time
Posted Jun 20, 2026
CISA RelevantIT Audit

IG Auditor/Program Analyst

Central Intelligence Agency
On-site · Washington, District of Columbia · Full-time
$76k to $185k Posted Jun 18, 2026
CISA RelevantIT Audit

NRO IG IT Auditor

Central Intelligence Agency
On-site · Washington, District of Columbia · Full-time
$63k to $157k Posted Jun 18, 2026

The CISA Career Guide

What Jobs Can You Get With CISA?

CISA opens the audit and assurance track across technology and, increasingly, AI. The most common destinations are the IT audit ladder, the technology-risk and GRC functions, and the specialized controls jobs that keep regulated organizations honest.

Typical jobs include IT Auditor, Senior IT Auditor, and IT Audit Manager; Technology Risk Analyst and Manager; GRC Analyst and Manager; SOX and IT Controls Specialist; Third-Party Risk Analyst; Cybersecurity Compliance Manager; Internal Audit Manager or Director; and a growing set of AI-facing jobs such as AI Risk and Assurance Specialist, AI Governance Auditor, and Head of Audit, Controls, or Assurance.

CISA Career Paths

Certification opens doors, but progression is earned through scope, results, and leadership, not the credential alone. Common realistic paths include:

  • IT Auditor → Senior IT Auditor → IT Audit Manager → Director of IT Audit
  • Technology Risk Analyst → Technology Risk Manager → GRC Director
  • IT Controls Specialist → AI Controls and Assurance Lead → Director of AI Governance Assurance

Skills Employers Want Alongside CISA

Employers consistently pair CISA with practical, demonstrable skills. The strongest candidates can point to hands-on work with IT general controls; SOX; SOC 1 and SOC 2; COBIT; the NIST frameworks; ISO 27001; and cloud controls. On the practice side, they want risk-based audit planning, evidence collection, control testing, and clear executive reporting, plus third-party risk, strong stakeholder communication, and a working grasp of AI control and governance frameworks.

How CISA Fits Into AI Governance

This is where a CISA holder has a distinct and underappreciated advantage. AI governance is not, at its core, a data-science problem; it is an assurance and controls problem. The organizations that will pass regulatory scrutiny are the ones that can prove their AI systems are inventoried, documented, tested, and monitored, and proving control effectiveness is exactly what auditors do.

CISA and IT-audit experience transfer directly into AI control design and testing, AI governance audits, model-risk assurance, and third-party AI risk. They apply to regulatory readiness, AI system inventories, documentation and evidence reviews, audit trails and accountability, continuous control monitoring, and the validation of responsible-AI policies. CISA is not exclusively an AI credential, but it provides one of the strongest assurance-and-controls foundations for a professional moving into AI governance.

CISA Salary and Market Information

The most reliable page-specific figures come from the live snapshot above, which reflects only the CISA-related jobs currently posted here and only the postings that disclose compensation. It is a picture of the live market on this board, not a claim about every CISA professional. For official information on the credential itself, its exam, and its requirements, consult ISACA's official CISA page. Treat any external average you encounter as context, with its source and date, never as a guaranteed salary.

Industries Hiring CISA Professionals

Demand for CISA-credentialed auditors is broad. Technology and financial services lead, followed by consulting and professional services, healthcare, government and the public sector, critical infrastructure, education, and mission-driven organizations. Any sector facing regulatory scrutiny over its systems, and now over its AI, needs people who can independently assess whether its controls actually work.

How to Present CISA on a Résumé

List the credential clearly, then make it earn its place. Connect CISA to measurable audit and control results: the audits you led and their scope, the controls you designed or tested, the risks you helped remediate, and the frameworks you applied. A credential backed by concrete outcomes and named frameworks, from SOX and SOC reporting to COBIT, NIST, and ISO 27001, reads far more convincingly than a line item on its own.

How CISA Compares to Related Credentials

CredentialPrimary career focus
CISAIT audit, technology controls and assurance
CRISCTechnology and enterprise risk
CISMInformation-security program leadership
CISSPBroad cybersecurity expertise and leadership
AIGPAI governance and responsible-AI programs
CIAInternal audit and audit leadership

Most professionals combine credentials to match their responsibilities. An IT auditor moving into risk often pairs CISA with CRISC; a security leader adds CISM or CISSP; and auditors moving into AI oversight increasingly add the AIGP to sit at the intersection of controls and AI governance.

CISA Careers: Frequently Asked Questions

What is the CISA certification?

CISA, the Certified Information Systems Auditor, is ISACA's globally recognized credential for professionals who audit, assess, and provide assurance over information systems and technology controls. It signals demonstrated skill in IT audit, control evaluation, and reporting on the security and integrity of systems.

What jobs can you get with CISA?

CISA supports jobs such as IT auditor and senior IT auditor, IT audit manager and director, technology-risk analyst and manager, GRC analyst and manager, SOX and IT-controls specialist, third-party risk analyst, cybersecurity compliance manager, and increasingly AI risk, assurance, and governance-audit jobs.

Does every job on this page require CISA?

No. Every listing is labeled CISA Required, CISA Preferred, or CISA Relevant based on the employer's own wording. Required means the posting explicitly states CISA is required. Preferred means it is described as preferred, desired, or a plus. Relevant means the job clearly draws on CISA skills but the posting does not state that the credential is required or preferred.

Can you take the CISA exam before meeting the experience requirement?

Yes. You can sit for and pass the CISA exam before you have the required experience. You then have a defined window to submit evidence of the qualifying professional experience to be awarded the full certification. Confirm the current window and rules on the official ISACA page.

What is the CISA Associate pathway?

ISACA offers an Associate designation for candidates who pass the exam but do not yet meet the full experience requirement. It lets you demonstrate that you have passed while you accumulate the qualifying experience needed to convert to full CISA. Check ISACA for the current requirements and time limits.

Is CISA useful for AI governance careers?

Yes. CISA is not an AI-specific credential, but AI governance is fundamentally an assurance and controls discipline. IT-audit skills, control design and testing, evidence review, and independent assessment transfer directly into AI control testing, AI governance audits, model-risk assurance, and regulatory readiness.

What is the difference between CISA, CISM, and CRISC?

CISA centers on auditing and assurance of IT systems and controls. CISM focuses on leading and managing an information-security program. CRISC focuses on identifying and managing technology and enterprise risk. Many professionals hold more than one as their responsibilities broaden across audit, security, and risk.

Is CISA better than CISSP for an audit career?

For an audit or assurance career, CISA is usually the more directly relevant credential because it is built around auditing systems and controls. CISSP is broader cybersecurity expertise and leadership. They serve different goals, and some professionals hold both when a job spans audit and security.

Are remote CISA jobs available?

Yes. Many IT-audit, technology-risk, and compliance jobs are offered remote or hybrid. Use the Remote or Hybrid filter above to see the current remote CISA openings on the board, since availability changes as new jobs post.

How should CISA appear on a résumé?

List CISA clearly near your name or in a certifications section, then connect it to measurable audit and control outcomes, for example the scope of audits led, controls tested, or risks remediated. Reference the frameworks you have used, such as SOX, SOC 1 and SOC 2, COBIT, NIST, and ISO 27001, so the credential is backed by demonstrated work.

Get new CISA jobs when they are posted

Receive new IT audit, technology-risk, GRC and AI-assurance opportunities that match the CISA credential.

Free and confidential. Unsubscribe anytime. This is a CISA job alert, separate from the GRC Careers newsletter.

Hiring for CISA, IT audit or technology-risk jobs?
Post your position on AI Governance Jobs and reach the specialists who do this work.
Post a Job

About This Page

Last reviewed: September 12, 2026. How jobs qualify: a job appears here when its posting references the CISA credential or Certified Information Systems Auditor in its title, description, or qualifications; each is then labeled Required, Preferred, or Relevant from the employer's own wording. Salary snapshot: computed live from the CISA jobs currently posted here, using only listings that disclose compensation, normalized to an annual basis. Credential facts reference ISACA's official CISA page. "CISA" on this page means the Certified Information Systems Auditor credential from ISACA, not the U.S. Cybersecurity and Infrastructure Security Agency. AI Governance Jobs is an independent job board and is not affiliated with or endorsed by ISACA. Your data is yours; we never sell it or use it to train AI.