Mid-Level

Information Security Auditor

A specialist auditing information security controls โ€” examining how the organization protects data, who has access, how incidents are detected and handled, and where security gaps could expose the business. The audit lens on cybersecurity.

Career Level
Junior
Mid
Senior
Director
VP
Executive
Work Personality
C
I
R
E
S
A
Conventionalorganizing, detail-oriented
Investigativeanalytical, curious
Based on Holland Code framework
Job markets for Information Security Auditors
Employment concentration ยท ~354 areas
Based on employment in related occupations
Mapped SOC categories:
BLS Occupational Employment Statistics
What it's like

What it's like to be a Information Security Auditor

Most days tend to involve controls testing, evidence review, interviews with IT and security teams, and the documentation that supports findings. You'll often test access controls, change management, vulnerability management, incident response, and data protection programs โ€” producing findings that map to frameworks like NIST CSF, ISO 27001, SOC 2, or PCI DSS. Engagement cadence varies by employer.

The variance between settings is real โ€” internal audit shops at large enterprises have specialized IT and security auditors; Big Four and second-tier audit firms run SOC 2, PCI, ISO certification engagements; consulting firms offer security assessments and program work; regulators audit security at financial institutions and critical infrastructure. Technical credibility with security operations matters โ€” auditors who can talk specifics get further.

People who tend to thrive here are comfortable with deep systems thinking, patient with the documentation requirements of audit work, and capable of bridging audit and security cultures. CISA is the dominant credential, with CISSP, CISM, CRISC also common. The work tends to offer strong demand and broad career paths, with the trade-off being the constant evolution of the underlying technology โ€” for those who enjoy the security-and-audit intersection, the work compounds in value as institutional knowledge grows.

Work values data not available for this role.
โœฆ Editorial โ€” written by Truest from industry research and career patterns
Career Paths

Where this role sits in the broader career landscape โ€” and where it can take you.

$239K$179K$119K$60K$0KLower paying386 metro areas, sorted by salary level
All experience levels1
This level's estimated range
INDUSTRIES PAYING ABOVE AVERAGE
1 BLS OEWS May 2024 covers all Information Security Auditors (SOC 15-1299.05), not just this title ยท BEA RPP 2023
* Top salaries exceed this figure. BLS caps reported wages at ~$240K to protect individual privacy in high-earning roles.
Exploring the Information Security Auditor career path? Truest helps you figure out if it's the right fit โ€” and plan your path forward.
Explore career tools
โœฆ Editorial โ€” career progression and interview guidance based on industry patterns
The Broader Landscape

Roles like this one sit within a broader occupational category. The numbers below reflect that full landscape โ€” helpful for context, but your specific experience will depend on level, specialty, and where you work.

$53Kโ€“$177K
Salary Range
10th โ€“ 90th percentile
439K
U.S. Employment
+8.2%
10yr Growth
31K
Annual Openings

How this category is changing

$77K$74K$72K$69K$66K201920202021202220232024$66K$77K
BLS OEWS May 2024 ยท BLS Employment Projections 2024โ€“2034

Skills & Requirements

Reading ComprehensionCritical ThinkingActive ListeningMonitoringWritingSpeakingSystems AnalysisSystems EvaluationQuality Control AnalysisActive Learning
O*NET OnLine ยท Bureau of Labor Statistics
15-1299.05

Navigate your career with clarity

Truest gives you tools to understand your strengths, explore roles that fit, and plan your next move.

Explore Truest career tools
Federal data: BLS Occupational Employment & Wage Statistics (May 2024) ยท BLS Employment Projections ยท O*NET OnLine
Truest editorial: Fit check, role profile, things that vary, advancement analysis, lateral moves, interview questions.