HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
Relevant certifications (CISA, CISSP, CRISC, CIPP/E, ISO Lead Auditor, HITRUST CCSFP, or similar) are strongly preferred * A minimum bachelor's degree in any discipline. Computer science ...
Relevant certifications (CISA, CISSP, CRISC, CIPP/E, ISO Lead Auditor, HITRUST CCSFP, or similar) are strongly preferred * A minimum bachelor's degree in any discipline. Computer science ...
Senior Security Compliance Analyst
$110K - $140K/yr
ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC. * Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
Senior Security Compliance Analyst
$110K - $140K/yr
ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC. * Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior GRC Manager
Louisiana, MO · On-site
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior GRC Manager
Louisiana, MO · On-site
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior Security Compliance Analyst
Boston, MA · Remote
$110K - $140K/yr
ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC. * Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
Quick apply
Senior Security Compliance Analyst
Boston, MA · Remote
$110K - $140K/yr
ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC. * Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
Assurance Associate, Third Party Attestation - Summer 2027 (Minneapolis)
$40.87 - $43.27/hr
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
Assurance Associate, Third Party Attestation - Summer 2027 (Minneapolis)
$40.87 - $43.27/hr
HITRUST Certified Common Security Framework Professional (CCSFP) * Certified Internal Auditor (CIA) * Certified Information Security Manager (CISM) * Certified Ethical Hacker (C | EH) * Certified in ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior GRC Manager
Indiana, PA · On-site
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior GRC Manager
Indiana, PA · On-site
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior GRC Manager
Washington, DC · On-site
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior GRC Manager
Washington, DC · On-site
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior GRC Manager
Delaware, OH · On-site
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior GRC Manager
Delaware, OH · On-site
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior GRC Manager
Michigan, ND · On-site
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Senior GRC Manager
Michigan, ND · On-site
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
CISA, HITRUST CCSFP, or CRISC certification - useful, but we care more about what you've actually run than what you've been certified in. * Experience with AWS, Azure, or GCP and related compliance ...
Ccsfp information
See salary details
$61.5K - $65.9K
12% of jobs
$69.8K is the 25th percentile. Wages below this are outliers.
$65.9K - $70.3K
14% of jobs
$70.3K - $74.7K
12% of jobs
The median wage is $78K / yr.
$74.7K - $79.1K
14% of jobs
$79.1K - $83.5K
2% of jobs
$83.5K - $88K
0% of jobs
$88K - $92.4K
0% of jobs
$92.4K - $96.8K
0% of jobs
$96.8K - $101.2K
0% of jobs
$101.2K - $105.6K
0% of jobs
$107.5K is the 75th percentile. Wages above this are outliers.
$105.6K - $110K
44% of jobs
$61.5K
$89.7K
$110K
How much do ccsfp jobs pay per year?
What is a CCSFP?
A CCSFP (Certified CSF Practitioner) is a cybersecurity professional specializing in the HITRUST Common Security Framework (CSF). They help organizations assess, implement, and maintain compliance with HITRUST CSF requirements. Their role often includes risk assessments, gap analyses, and advisory services to ensure organizations meet security and regulatory standards. CCSFPs typically work in healthcare, finance, and other regulated industries that require strong data protection.
What are the key skills and qualifications needed to thrive as a CCSFP?
To thrive as a CCSFP (Certified Cybersecurity Framework Professional), you need a thorough understanding of cybersecurity frameworks (such as HITRUST CSF, NIST, or ISO 27001), risk management, and compliance regulations, typically backed by relevant experience and industry-recognized certifications. Familiarity with assessment tools, audit software, and governance, risk, and compliance (GRC) platforms is commonly required. Strong analytical thinking, meticulous attention to detail, and effective communication help professionals excel when working with clients or cross-functional teams. These skills ensure proper evaluation of security controls, successful client interactions, and effective guidance in meeting compliance standards.
What kind of career growth can I expect as a CCSFP?
As a CCSFP, you benefit from strong career growth opportunities in the cybersecurity and compliance domains, with potential paths leading to senior consultant, manager, or director roles in risk management and information security. Your expertise in complex cybersecurity frameworks is highly valued in industries such as healthcare, finance, and technology, opening doors to specialized advisory or leadership positions. Many professionals also broaden their credentials by pursuing advanced certifications like CISSP or CISA. The demand for compliance and risk professionals continues to grow, allowing skilled CCSFPs to shape the future of organizational security and compliance strategies.
What job categories do people searching Ccsfp jobs look for?
The top searched job categories for Ccsfp jobs are:

Assurance Associate, Third Party Attestation - Summer 2027 (Minneapolis)
Minneapolis, MN • On-site
Full-time
Retirement
Posted 12 days ago
BDO USA rating
8.2
Based on 29 frontline employees who took The Breakroom Quiz
9th of 23 rated bookkeepers and accountants
Job description
Job Summary:
The Assurance Associate, Third Party Attestation will be responsible for the preparation of third-party attestation reports, including System and Organization Controls (SOC) 1, SOC 2, SOC 3, SOC for Cybersecurity and WebTrust for CAs, as well as HITRUST, SSPA, ISO, MRC and CSA STAR applying most areas of the governing standard as necessary and documenting, validating, testing, and assessing various control systems, including internal controls. Our TPA individuals specialize in thesespecific areas to understand the entire technology risk umbrella rather thanmaintaining overall knowledge in Information TechnologyGeneralControl (ITGC)audit or IT audit.
Job Duties:
Control Environment:
- Applies knowledge and understanding of the collective effect of various factors on establishing or enhancing effectiveness, or mitigating the risks, of specific policies and procedures by:
- Identifying and considering all applicable policies, laws, rules, and regulations of the firm, regulators, or other authoritative bodies as part of engagement team
- Making constructive suggestions to improve client internal control procedures
- Documenting and validating the operating effectiveness of the clients' internal control system
- Documenting business and IT processes and controls and tests key controls for service organizations in a variety of industries
- Identifying and prioritizing key risks, and assesses their impact and likeliness of occurrence
- Communicating to the client areas to improve processes, strengthen controls, mitigate risks, and/or increase efficiency
- Developing and maintaining relationships with client personnel and management
- Ensuring technology is appropriately integrated into the examination process
GAAS:
- Applies knowledge and understanding of professional standards; application of the principles contained in professional standards; and the ability to document and communicate an understanding and application of professional standards on an engagement by:
- Developing and applying an intermediate knowledge of auditing theory, a sense of audit skepticism, and the use of BDO audit manuals
- Applying auditing theory to various client situations
- Documenting working papers and attestation reports in line with BDO policy, identifying deviations and notifying more senior team members in order to obtain appropriate approvals
- Applying knowledge to identify instances where testing may be reduced or expanded and notifying more senior team members of the occurrence
- Contributing ideas/opinions to the engagement team
Methodology:
- Applies knowledge and application of BDO standards to guide effective and efficient delivery of quality services and products by:
- Completing all appropriate documentation of BDO work papers
- Ensuring assigned work is performed in accordance with BDO methodology and requirements
Research:
- Applies methodology used to seek or maintain information from authoritative sources and to draw conclusions regarding a target issue based on the information by:
- Researching basic and intermediate topics and forming an initial opinion on the treatment independently
Training:
- Attend professional development and training sessions on a regular basis
- Complete required CPE hours to maintain applicable certifications
Qualifications, Knowledge, Skills and Abilities:
Education:
- Bachelor's degree in Accounting, Computer Science, Management Information Systems, Finance, Economics, Business Administration, Managerial Marketing and Entrepreneurship with a concentration in any of the previous areas noted, required
- Master's degree in Accounting, and minor or dual major in Information Systems or other relevant advanced degree, preferred
Experience:
- Less than one (1) year of prior experience in IT, internal or external audit or relevant industry experience, required
- Leadership experience, preferred
- Experience performing SOC, WebTrust, HITRUST, SOX, ISO 27001 and security/privacy advisory engagements, preferred
- Prior internship or experience working within a public accounting or internal auditing environment, preferred
License/Certifications:
- One or more of the following certifications are preferred:
- Certified Public Accountant (CPA)
- Certified Information Systems Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
- ISO 27001 Lead Auditor certification
- HITRUST Certified Common Security Framework Professional (CCSFP)
- Certified Internal Auditor (CIA)
- Certified Information Security Manager (CISM)
- Certified Ethical Hacker (C | EH)
- Certified in Risk and Information Systems Control (CRISC)
- Certified in the Governance of Enterprise IT (CGEIT)
Software:
- Proficiency in Microsoft Office Suite, specifically Word, Excel, and PowerPoint, required
Other Preferred Knowledge, Skills & Abilities:
- Strong written and verbal communication skills
- Ability to follow instructions as directed
- Ability to work effectively in a team setting
- Ability to travel as necessary
- Takes appropriate actions without being asked
- Basic understanding of the planning and coordination stages of an audit preferred
- Ability to successfully interact with professionals at all levels
Individual salaries that are offered to a candidate are determined after consideration of numerous factors including but not limited to the candidate's qualifications, experience, skills, and geography.
California Range: $85,000 - $90,000
Colorado Range: $73,000 - $77,000
Illinois Range: $78,000 - $82,000
Maryland Range: $83,000 - $87,000
Massachusetts Range: $83,000 - $87,000
Minnesota Range: $70,000 - $74,000
New Jersey Range: $78,000 - $82,000
NYC/Long Island/Westchester Range: $83,000 - $87,000
Ohio Range: $71,000 - $75,000
Virginia Range: $83,000 - $87,000
Washington Range: $78,000 - $80,000
Washington DC Range: $83,000 - $87,000
At BDO, how we show up matters. We build strong relationships by supporting one another, our clients, and our communities with care, curiosity, and a commitment to helping one another grow and succeed. Here, you'll find meaningful work, leaders invested in your success, and opportunities to build a career around what matters most to you.
Our purpose is to be the people our clients count on to grow with confidence and achieve what matters most. Our values guide how we bring that purpose to life each day. Together, they shape how we work with one another, serve our clients, and create meaningful impact.
BDO provides assurance, tax, and advisory services to clients across the U.S. and around the world. No matter your role, you'll be part of a team helping clients navigate complexity and move forward with clarity.
We are proud to be an ESOP company, offering participants a stake in the firm's success through beneficial ownership and a unique opportunity to enhance their financial well-being. As a qualified retirement plan, the ESOP is a meaningful addition to our comprehensive compensation and Total Rewards benefits* offerings. It also reinforces an ownership mindset that strengthens our connection to one another, our clients, and the future we're building together.
Learn more about our benefits: BDO Total Rewards encompass more than traditional benefits. Click here to find out more!
*Benefits may be subject to eligibility requirements.
Equal Opportunity Employer, including disability/vets
Click here to find out more!
About BDO
Sourced by ZipRecruiter
At BDO, culture is the first order of business. We succeed when we cultivate a conscious and caring corporate culture that puts people at the center of everything we do. In essence, the business of our business is to help people thrive every day. This mindset powers our growth by supporting the development of our people, the success of our clients, and the betterment of our communities. It means taking an expansive view of what’s possible, and committing ourselves to achieving exceptional outcomes. At BDO, we are cultivating a culture where our professionals thrive in their work of providing middle market leaders with insight-driven perspectives and assurance, tax and advisory services, helping companies take business as usual to better than usual.
Industry
Administrative assistance services and accounting services
Company size
10,000+ Employees
Headquarters location
Chicago, IL, US