Jobs › CISSP
CISSP Jobs: Certified Information Systems Security Professional Careers
CISSP is the most widely held senior credential in information security.
CISSP, from (ISC)2, is the most widely recognized senior credential in information security. It covers a broad body of knowledge across security domains and is built for experienced practitioners, which is why it appears on a large share of senior security, security architecture, and security-leadership roles.
In GRC, CISSP is common on the security and risk side and often sits alongside CISM for leadership roles or CRISC for risk. For many employers it is the baseline credential that gets a security-focused GRC candidate through the door.
CISSP: Frequently Asked Questions
What is CISSP?
CISSP, Certified Information Systems Security Professional, is a senior security credential from (ISC)2 covering a broad body of information-security knowledge.
Is CISSP required for security jobs?
It is not legally required, but it is one of the most commonly requested credentials on senior security and security-leadership roles.
Does CISSP help in GRC?
Yes. It is widely requested on the security and risk side of GRC, and it pairs well with CISM and CRISC.
Open CISSP GRC jobs (48)
Lead, Security Controls Assurance - SOX
Security Risk Management Specialist II
DWS Internal Audit Manager - Technology & Security
Senior Compliance Manager
Security Compliance, GRC Engineer
Product GRC Subject Matter Expert, (V4G)
Subject Matter Expert, GTM GRC - V4G
Director, Cyber GRC
Technical Audit Manager - CSO CTO (f/m/x)
Senior Manager, IT SOX
DWS - Internal Auditor (m/f/d) IT Applications
Director of Cybersecurity Governance, Risk and Compliance
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Digital Risk Services - SOC Reporting and HITRUST Managing Director
Cybersecurity Risk Management and Compliance - Technical
ICT Risk Oversight Lead
Auditor / Senior Auditor
Senior Manager, Information Compliance, AI Governance & Privacy
Staff Program Manager, Compliance
Field CISO
Senior IT Internal Auditor
Virtual CISO & Cybersecurity Practice Lead
Cybersecurity Consultant
Cyber AI Governance and Privacy Senior Consultant
Security, Risk and Compliance Consultant
Director of Governance, Risk & Compliance (GRC)
Senior Manager, Cyber Threat Intelligence
Governance, Risk, and Compliance Manager (IT)
Sr Manager, Governance, Risk, Compliance & Privacy
Security Assurance Lead
Senior Analyst, Security Risk
Senior Internal Auditor, Technology
Senior Manager, Internal Audit - Audit Automation & Technology Risk
Cyber Security Engineer III - Incident Response & Risk
Cybersecurity AI Risk and Governance Director
Chief Information Security Officer
Compliance Analyst, Texas Institute for Electronics
EMEA Assurance Lead
Tech Governance - Security Compliance & Governance Engineer
Senior GRC Program Manager
NRO IG IT Auditor
CISSP jobs: what the market looks like right now
A snapshot built from the 48 CISSP roles currently on this page.
What these roles pay by level
| Level | Median midpoint | Postings |
|---|---|---|
| Mid-level | $126k | 7 |
| Senior / lead / manager | $136k | 7 |
How these figures were calculated, and sources
Primary source: our own board. Every figure above is the median midpoint of the salary ranges published in the live postings on this page. Nothing is estimated, modelled, or carried over from a previous month. It is recalculated each time the board refreshes.
What is included. Only postings that publish a salary range. Hourly, weekly and monthly rates are annualised (2,080 hours, 52 weeks, 12 months). Ranges below $20,000 a year are excluded as data-entry placeholders. A seniority band is shown only when at least five postings support it; director and executive / c-suite are present on this page but below that threshold, so no median is published for those bands.
What this is not. These are advertised ranges, not accepted offers. Advertised ranges tend to run wider than what is actually paid, and roles that do not publish a range are missing from the calculation entirely, which can bias the result upward.
For an independent benchmark, compare against the U.S. Bureau of Labor Statistics Occupational Employment and Wage Statistics for SOC 13-1041 — Compliance Officers, published annually at bls.gov/oes. BLS reports actual wages across all employers rather than advertised ranges, so its medians normally sit below job-board figures.
Where the work is
- Work mode: 8 remote, 3 hybrid, 37 on-site or unstated.
- Seniority mix: mid (20), senior (19), director (5), executive (4)
- Employers hiring more than one: SEI (9), Deutsche Bank (3), Anthropic (2), Vanta (2), UT Austin (2), Scale AI (2)
Skills these postings ask for
- policy and procedure writing
- control testing and evidence collection
- regulatory change management
- SOX and SOC 2 readiness
- issue management and remediation tracking
How to get a compliance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in CISSP postings to be worth knowing: CCEP, CRCM, CAMS, CIPP/US, AIGP. The certification academy covers what each one actually tests and who it is for.
Hiring for CISSP?
We have 48 open CISSP roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
About the CISSP certification · All GRC jobs · Job alerts