The HITRUST Common Security Framework, “HITRUST CSF”, is a risk based, prescriptive security and privacy framework that streamlines compliance of multiple regulations, risk factors, and standards. The HITRUST Assessor will work closely with clients and other team members, under the direction of an Executive Sponsor, to guide customers through the process of HITRUST Readiness and Validated Assessment to submit to the HITRUST Alliance for Certification.
A good candidate for this position is individuals looking to apply information security and privacy focused frameworks and methodologies to expand their knowledge and skills in diverse and complex data privacy regulations on a global basis. Secondarily this role will provide guidance in implementation of various frameworks for security and privacy.
- Work closely with clients to understand systems and business functions in order to determine the scope of their HITRUST assessments
- Review and evaluate an organization’s information security posture for compliance with the HITRUST CSF and other relevant frameworks
- Develop a GAP assessment with prioritized remediations
- Assist organizations with the implementation of a remediation plan to strengthen information security posture
- Research and understand Security and Privacy matters
- Communicate IT, Security, and Privacy concepts to an organization as it relates to the inscope environment
- Develop and execute test plans to validate an organization’s compliance with the HITRUST CSF for certification submission
Qualifications and Requirements
- BA/BS in information technology, business administration, or related field preferred
- 5+ years in a security/privacy consulting position
- High attention to detail with a focus on persistent and timely follow-up
- Certifications in HIPAA (HCISPP) and or HITRUST (CCSFP, CHQP) is a plus
- Certifications in Security and/or Privacy Technology (CISSP, CIPP) is a plus
- Prior Big 4 consulting experience is a significant plus
- *Post COVID-19 – this position may include travel up to 25%
- Medical, vision, and disability insurance program
- Employer-funded life insurance for all employees
- Unlimited vacation policy with a requirement to take at least two weeks
- Encourage and compensate for advanced training, certifications, and industry events
- Have a voice and be heard with the opportunity to make a positive difference
The Managing Consultant is primarily responsible for managing a team of offensive security consultants and ensuring that the quality of work performed aligns with our standards and client expectations. Secondarily, the Managing Consultant will also execute and deliver client engagements, including penetration tests, threat and vulnerability assessments, purple team engagements, ransomware exposure assessments, and custom assessments designed to meet our clients’ needs. The following high-level goals and objectives are expected to be met by the Managing Consultant.
- Engaged and High Performing Teams
The Managing Consultant plays a critical role in setting the strategy for the offensive security work we perform, staffing the team with the top-tier talent, and creating an environment where consultants can thrive personally and professionally.
Aligning capabilities with client needs and maximizing quality and efficiency is imperative in consulting. The Managing Consultant will continually evaluate how we deliver our consulting engagements, including methodology and technology enablement, to ensure we achieve these objectives. Strategically, the Managing Consultant will be instrumental in helping anticipate client needs and establishing those capabilities on the team.
- Excellence in Project Delivery and Client Relationships
All Security services are designed to forge a trusted partnership with our clients. This comes from ensuring that all security services are delivered with excellence and are executed in a timely manner. Regular communication with clients and the Security Advisory Services team is equally important to ensure that expectations are being met.
- Technical Expertise in Delivered Services
The Managing Consultant is expected to demonstrate technical expertise when delivering our services. Gaps in technical proficiency should be communicated prior to project execution to ensure clients receive expected value. Identified gaps will be used to guide training objectives
- Ownership of Unique or Complex Projects
We offers a wide breadth of service offerings that range from shorter term assessments to more involved, custom security services. The Managing Consultant may be responsible for taking ownership of these projects and client relationships to ensure that unique or complex projects are delivered successfully.
- Prior experience as Lead/Managing Consultant or equivalent corporate experience, such as Manager of Red Team Operations with a record for overseeing offensive security projects such as:
- Threat and Vulnerability Assessments
- Penetration Testing
- Web Application Security Assessments
- Social Engineering
- Proven ability to build and manage high performing teams; and who is adept at communicating clearly, listening, giving feedback, prioritizing, and cultivating skills with individual staff.
- Expert knowledge of offensive security testing, exploitation, and remediation across a range of infrastructure technologies and applications
- Working knowledge of network and systems architecture
- Network segmentation
- Intrusion Detection Systems
- Web application architecture
- Active Directory
- Advanced understanding of how major application layer protocols function (e.g., HTTP, SMTP, DNS, Kerberos)
- Advanced knowledge of categories of malware and how they function (e.g., rootkits, trojans, adware, ransomware)
- Advanced knowledge related to vulnerabilities and attack vectors such as:
- SQL Injection
- Brute force attacks
- Active Directory exploitation
- Malware infection vectors
- Phishing attacks
- Drive-by/Redirection attacks
- Experience performing security assessments on multiple operating systems (Windows, Linux, Unix, OSX)
Experience, Education, and Certifications
- Minimum of 10 years’ experience working in security consulting or equivalent internal roles
- Minimum of two years’ experience successfully mentoring/managing staff
- Bachelor’s degree or equivalent experience
- Offensive security certification(s) expected for this role (e.g., OSCP or similar)
Essential Duties and Responsibilities
- Perform technical security testing, including cyber-attack simulations and threat and vulnerability assessments.
- Support cybersecurity assessments consisting of security architecture reviews, system configuration reviews and cloud security evaluations.
- Support cybersecurity incident response readiness activities, including tabletop exercises and evaluations of incident response capabilities.
- Document results from technical testing performed and develop tailored recommendations to mitigate associated cyber threats and risks.
- Execute assigned client engagements from start to finish, which includes engagement planning, fieldwork execution and reporting.
- Remain current and apply knowledge of cybersecurity trends and risks.
- Communicate (verbally and in writing) externally with clients and internally with all levels of the organization to successfully accomplish objectives portraying knowledge and confidence.
- Proactively interact with key client management to gather information, resolve problems and make recommendations for improvements.
- Develop client relationships with the intention to exceed client expectations.
- Adhere to the highest degree of professional standards and strict client confidentiality.
- Participate in professional development activities and training sessions on regular basis.
- Other duties as assigned.
Required Skills and Experience
- 3+ years of related cybersecurity experience in a similar consulting practice or function.
- Experience in one or more of the overarching areas below:
- Conducting technical security testing, including one or more of the following: cyber-attack simulations, vulnerability assessments, web application testing, and/or penetration testing.
- Reviewing security architecture deployments and assessing and/or implementing secure configurations for common network devices (routers, switches, firewalls), server operating systems (Windows and Linux) and database management systems.
- Assessing and/or implementing security solutions and controls within cloud service provider platforms (e.g., AWS, Azure, GCP, O365).
- Ability to document technical testing and assessment results in a formal report format and present results and recommendations to both a technical and non-technical audience.
- Exceptional client service and communication skills, with a demonstrated ability to develop and maintain outstanding client relationships.
- Ability to execute multiple engagements and competing priorities in a rapidly growing, fast-paced, interactive, results-based team environment.
- Strong professional verbal and written skills.
- Excellent analytical, organizational and project management skills.
Desired Skills and Experience
- Bachelor’s and/or Master’s degree in Information Technology, Cybersecurity, Computer Science or a related field.
- One or more relevant technical certifications such as: CISSP, GIAC (GSEC, GCIH, GSIP, etc.), MS-500, AZ-500, AWS Certified Security, Google Cloud Professional Architect / Security Engineer
- Working knowledge of cybersecurity industry leading practices and frameworks, such as NIST CSF, CIS Controls, CIS Benchmarks, OWASP, MITRE.
- Familiarity with common threat and vulnerability management and endpoint security solutions.