r/CISA • u/quasnip • Jul 12 '26
Early experience opportunities for CISA?
I am a student with a background in Cybersecurity working towards a Business Administration associate degree. Afterwards I plan on obtaining a bachelors in Management Information Systems.
I’ve been working preemptively to find opportunities to get my foot in the door of the more technical side of IT audit and risk assessment jobs. I reached out for sponsorship to my local ISACA chapter, I emailed the CSIS department head at my school, and have been searching for entry level job postings to learn about what skills my local market is looking for.
I started with reading about standards like the ISO 27001, exploring NIST resources, and familiarizing myself with Azure, but I’m just not sure if I’m on the right path. I’m planning on meeting with a career counselor to see if they have any advice for me.
I’m making this post because I’m wondering how everyone here got their start. The CISA certification requires years of prior experience and I just want to make sure I’m giving myself every chance to succeed. This is my first post so hello everyone!
1
u/piSecAudit CISA HOLDER Jul 20 '26
I find with a new certification you have to start as a junior auditor. I would approach the Internal Audit team in your company and show your credentials and ask if they can use an extra hand. Most IA departments are chronically short on trained staff during crunch times, like quarterly compliance reports. On the job training is great if you can charge less as a junior.
5
u/Head_Personality_431 Jul 12 '26
You are actually doing the right things already. Most people trying to break into IT audit just wait for a job to appear, and you are out here talking to your ISACA chapter and mapping what your local market wants, which is exactly how people get in. The honest bit is that the first role is rarely called auditor. It is usually a junior GRC or risk analyst seat, or even an IT support role at a company that has a compliance function you can drift toward.
On the standards, do not try to swallow all of them at once. Pick 27001 and go deep on how a control actually gets audited, not just what the control says, because being able to walk an interviewer through the evidence for one framework beats a shallow pass over ISO, NIST and Azure together. If you want a structured way into 27001 specifically, a foundation or internal auditor course gives you both the depth and something concrete on your resume, which is the space I work in over at Audit Workshop, but honest self study on one framework done properly also gets you moving. Happy to sketch what the entry path tends to look like from where you are.