HITRUST Consultant

Summary

The HITRUST Common Security Framework, “HITRUST CSF”, is a risk based, prescriptive security and privacy framework that streamlines compliance of multiple regulations, risk factors, and standards. The HITRUST Assessor will work closely with clients and other team members, under the direction of an Executive Sponsor, to guide customers through the process of HITRUST Readiness and Validated Assessment to submit to the HITRUST Alliance for Certification.

A good candidate for this position is individuals looking to apply information security and privacy focused frameworks and methodologies to expand their knowledge and skills in diverse and complex data privacy regulations on a global basis. Secondarily this role will provide guidance in implementation of various frameworks for security and privacy.

Role Responsibilities

  • Work closely with clients to understand systems and business functions in order to determine the scope of their HITRUST assessments
  • Review and evaluate an organization’s information security posture for compliance with the HITRUST CSF and other relevant frameworks
  • Develop a GAP assessment with prioritized remediations
  • Assist organizations with the implementation of a remediation plan to strengthen information security posture
  • Research and understand Security and Privacy matters
  • Communicate IT, Security, and Privacy concepts to an organization as it relates to the inscope environment
  • Develop and execute test plans to validate an organization’s compliance with the HITRUST CSF for certification submission

Qualifications and Requirements

  • BA/BS in information technology, business administration, or related field preferred
  • 5+ years in a security/privacy consulting position
  • High attention to detail with a focus on persistent and timely follow-up
  • Certifications in HIPAA (HCISPP) and or HITRUST (CCSFP, CHQP) is a plus
  • Certifications in Security and/or Privacy Technology (CISSP, CIPP) is a plus
  • Prior Big 4 consulting experience is a significant plus
  • *Post COVID-19 – this position may include travel up to 25%

Employee Perks

  • Medical, vision, and disability insurance program
  • Employer-funded life insurance for all employees
  • Unlimited vacation policy with a requirement to take at least two weeks
  • Encourage and compensate for advanced training, certifications, and industry events
  • Have a voice and be heard with the opportunity to make a positive difference

Data Protection and Privacy Manager

Essential Duties and Responsibilities

  • Adhere to the highest degree of professional standards and strict client confidentiality.
  • Ability to manage multiple engagements and competing priorities in a rapidly growing, fast-paced, interactive, results-based team environment.
  • Ability to communicate in an organized and knowledgeable manner in written and verbal means – including delivering clear requests for information, developing responses to client requests, and communicating conflicts and risks.
  • Deep understanding of global privacy and data protection regulations, such as EU’s GDPR and US laws such as CCPA, CPRA, CDPA, CPA, HIPAA, GLBA.
  • Apply current knowledge of privacy and data protection trends and to issues and other opportunities for improvement.
  • Assist clients in planning and executing remediation plans identified in assessment activities.
  • Proactively interact with key client management to gather information, resolve problems and make recommendations for improvements.
  • Collaborate with team members at all levels in the development and marketing of the privacy service offering.
  • Develop high quality deliverables through collaboration with clients and team members to address needs and demonstrate an understanding of clients’ business.
  • Additional duties as assigned.

Qualifications 

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or a related field is required.  A Masters or JD degree is preferred.
  • 3+ years of related work experience in a similar consulting practice or function, servicing cross- industry clients at a national level.
  • Certification(s) Preferred: Obtained or demonstrates an active pursuit of one or more of the following certifications: Certified Information Privacy Professional (CIPP), Certified Information Privacy Technologist (CIPT), Information Systems Security Professional (CISSP), or other related certifications.
  • Experience working with leading privacy regulations to perform privacy assessments and support privacy program implementations.
  • Experience preparing reports and other deliverables that contain strategy, project, or technical analysis and findings in connection with consulting engagements and communicating those results to the team and client.
  • Knowledge of privacy technology solutions and experience implementing and sustaining tools such as OneTrust, WireWheel, Securiti.ai, BigID is a plus.
  • Experience in project management and the ability to clearly communicate privacy and data protection issues verbally on both a formal and informal basis to all levels of client staff.
  • Exceptional client service and communication skills, with a demonstrated ability to develop and maintain outstanding client relationships.
  • Demonstrates creative thinking and problem-solving skills, and advanced knowledge of MS Office Word, Excel, Visio, and PowerPoint.
  • Ability to work additional hours as needed and travel on a regular basis to clients as required.

Cyber Transformation, Manager

Essential Duties and Responsibilities

  • Adhere to the highest degree of professional standards and strict client confidentiality.
  • Execute assigned client engagements from start to finish, which includes the engagement planning, directing, and completion of IT security assessments and Information Security architectural design and deployments while managing those engagements to budget.
  • Apply current knowledge of technology and cyber trends and to identify security and risk management issues and other opportunities for improvement.
  • Assist clients in planning and executing remediation plans identified in assessment activities.
  • Work with the client to plan an engagement strategy, define objectives, and address technology- related controls risks and issues.
  • Proactively interact with key client management to gather information, resolve problems and make recommendations for improvements.
  • Ability to manage multiple engagements and competing priorities in a rapidly growing, fast-paced, interactive, results-based team environment.
  • Participate in professional development activities and training sessions on regular basis.
  • Other duties as assigned.

Qualifications

  • Minimum Year(s) of Experience: 5 years.
  • Bachelor’s degree in Information Technology, Computer Science or a related field is required.
  • Masters in cybersecurity, Information system or business administration is preferred.
  • Certification(s) Preferred: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), ISACA, Certified in Risk and Information Systems Control
  • Complete understanding of Industry Standards/frameworks such as COBIT, NIST, ISO 27001, and PCI-DSS etc. is necessary.
  • Demonstrate proven and extensive abilities solving complex cyber-risk management issues, including the following areas:
  • Design and development of IT Risk and Cyber security programs using industry frameworks and methodologies;
  • Designing KRIs and metrics to build risk reports for management
  • ­Implementation and maintenance of enterprise-wide cyber risk governance frameworks;
  • Assessment of enterprise-wide business risks and cyber threats;
  • Development of detailed business risk scenarios and cyber threat models;
  • Design and implementation of cyber risk management controls;
  • Monitoring and reporting of cyber risks, threats and vulnerabilities;
  • Development, implementation and periodic testing of cyber resiliency plans;
  • Use of tools and technology to provide data analytics and business intelligence on cyber threats, risks and vulnerabilities;
  • Advising clients on complying with regulatory requirements such as FFIEC, GLBA, NY DFS etc. as well as industry frameworks such as NIST CSF, COBIT, COSO and PCI;
  • Building and operationalizing complex IT risk management and cyber security programs for clients.

Skills Preferred 

  • Take ownership of your work, by performing self-reviews of all work performed.
  • Produce high quality deliverables on client engagements requiring little re-work. Ensure they are on time and well organized.
  • Ability to manage multiple engagements and competing priorities in a rapidly growing, fast-paced, interactive, results-based team environment.
  • Ability to deal with ill-defined problems and propose coherent solutions for the client.
  • Execution of assigned client engagements from start to finish, which includes the engagement planning, directing, and completion while managing those engagements to budget.
  • Manage the team comprising of seniors and associates and maintain professionalism across team.
  • Apply current knowledge of IT trends and systems processes to identify security and risk management issues and other opportunities for improvement.
  • Assist clients in developing and executing risk management activities.
  • Participate in clients call as Security SME; provide solutions best fitted to the requirement and in line with the Industry best practices.
  • Ability to work additional hours and travel domestically as needed.