Jobs › CISM
CISM Jobs: Certified Information Security Manager Careers
CISM, the Certified Information Security Manager, is the leading credential for security leadership and governance.
CISM, from ISACA, certifies the management side of information security, governance, risk management, program development, and incident response, rather than the hands-on technical side. It is built for people who run security programs and answer for them to the business, which is why it shows up on security manager, security governance, and CISO-track roles.
In a GRC context, CISM is the bridge between security and governance. It signals that a candidate can set security strategy, manage risk, and align a security program with business and regulatory requirements, and it pairs naturally with CRISC and CISSP.
CISM: Frequently Asked Questions
What is CISM?
CISM, the Certified Information Security Manager, is an ISACA credential focused on information security management, governance, risk, and program leadership.
How is CISM different from CISSP?
CISM emphasizes the management and governance of security programs, while CISSP covers a broader, more technical body of security knowledge. Many security leaders hold both.
What roles ask for CISM?
Security manager, information security governance, risk and security program leadership, and CISO-track positions.
Open CISM GRC jobs (40)
Security Risk Management Specialist II
Senior Governance Analyst
Senior Compliance Manager
Security Compliance, GRC Engineer
Product GRC Subject Matter Expert, (V4G)
Subject Matter Expert, GTM GRC - V4G
Director, Cyber GRC
ICT Risk Assessment Manager
ICT GRC – Risk & Compliance Manager
Director of Cybersecurity Governance, Risk and Compliance
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Operational Resilience Manager
Digital Risk Services - SOC Reporting and HITRUST Managing Director
Cybersecurity Risk Management and Compliance - Technical
ICT Risk Oversight Lead
Senior Manager, Information Compliance, AI Governance & Privacy
Staff Program Manager, Compliance
Field CISO
Senior IT Internal Auditor
Virtual CISO & Cybersecurity Practice Lead
Cyber AI Governance and Privacy Senior Consultant
Security, Risk and Compliance Consultant
Director of Governance, Risk & Compliance (GRC)
Sr Manager, Governance, Risk, Compliance & Privacy
Security Assurance Lead
Senior Internal Auditor, Technology
Senior Manager, Internal Audit - Audit Automation & Technology Risk
Cybersecurity AI Risk and Governance Director
Chief Information Security Officer
Compliance Analyst, Texas Institute for Electronics
EMEA Assurance Lead
Director, Governance, Risk, and Compliance (GRC)
Tech Governance - Security Compliance & Governance Engineer
CISM jobs: what the market looks like right now
A snapshot built from the 40 CISM roles currently on this page.
What these roles pay
Of the 40 open CISM roles on this page, 12 publish a salary range. Across those:
- Median advertised midpoint: $161k
- Middle half of the market: $126k to $170k
- Full advertised range: $86k to $350k
Computed from the live postings on this page, not from survey data, and recalculated every time the board refreshes. Roles without a published range are excluded.
Where the work is
- Work mode: 8 remote, 1 hybrid, 31 on-site or unstated.
- Seniority mix: mid (16), senior (15), director (6), executive (3)
- Employers hiring more than one: SEI (9), Vanta (2), N26 (2), UT Austin (2), Scale AI (2), GitLab (2)
Skills these postings ask for
- policy and procedure writing
- control testing and evidence collection
- regulatory change management
- SOX and SOC 2 readiness
- issue management and remediation tracking
How to get a compliance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in CISM postings to be worth knowing: CCEP, CRCM, CAMS, CIPP/US, AIGP. The certification academy covers what each one actually tests and who it is for.
Hiring for CISM?
We have 40 open CISM roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
About the CISM certification · All GRC jobs · Job alerts