Audit & Framework Management (SOC 2 & HITRUST) * Serve as a primary point of contact for external auditors during SOC 2 and HITRUST assessments. * Collect, organize, and review evidence on the ...
Audit & Framework Management (SOC 2 & HITRUST) * Serve as a primary point of contact for external auditors during SOC 2 and HITRUST assessments. * Collect, organize, and review evidence on the ...
SOC 2 Senior Manager (CPA) - US
$76K - $94K/yr
... 27001, PCI DSS (QSA), HITRUST, CMMC (C3PAO), and FedRAMP (3PAO) frameworks. We're not your ... Preferred (not required) certifications: • CISA, CISSP, ISO 27001 Lead Auditor, or PCI QSA ...
Quick apply
SOC 2 Senior Manager (CPA) - US
$76K - $94K/yr
... 27001, PCI DSS (QSA), HITRUST, CMMC (C3PAO), and FedRAMP (3PAO) frameworks. We're not your ... Preferred (not required) certifications: • CISA, CISSP, ISO 27001 Lead Auditor, or PCI QSA ...
$80K - $99K/yr
... 27001, PCI DSS (QSA), HITRUST, CMMC (C3PAO), and FedRAMP (3PAO) frameworks. We're not your ... CISA, CISSP, ISO 27001 Lead Auditor, or PCI QSA Privacy Notice CCPA : * Insight Assurance shares ...
$80K - $99K/yr
... 27001, PCI DSS (QSA), HITRUST, CMMC (C3PAO), and FedRAMP (3PAO) frameworks. We're not your ... CISA, CISSP, ISO 27001 Lead Auditor, or PCI QSA Privacy Notice CCPA : * Insight Assurance shares ...
Business Development Representative
Tampa, FL · On-site +1
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Business Development Representative
Tampa, FL · On-site +1
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Senior GRC Associate
$70K - $94K/yr
Key Responsibilities: * Lead and coordinate HITRUST certification efforts, including audit ... Internal/External auditing * Preferred qualifications: CCSFP, CRISC, CISA Estimated Salary Range ...
Senior GRC Associate
$70K - $94K/yr
Key Responsibilities: * Lead and coordinate HITRUST certification efforts, including audit ... Internal/External auditing * Preferred qualifications: CCSFP, CRISC, CISA Estimated Salary Range ...
Business Development Representative
Tampa, FL · On-site +1
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Business Development Representative
Tampa, FL · On-site +1
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Chief Information Security Officer
$145K - $170K/yr
... auditors to ensure compliance with healthcare and international security standards, including HITRUST, HIPAA, SOC 2 Type II, NIST, and ISO. Company Overview We provide solutions that make a ...
Quick apply
Chief Information Security Officer
$145K - $170K/yr
... auditors to ensure compliance with healthcare and international security standards, including HITRUST, HIPAA, SOC 2 Type II, NIST, and ISO. Company Overview We provide solutions that make a ...
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
OR · On-site
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
OR · On-site
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
OR · On-site
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
OR · On-site
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
... HITRUST, Vendor Privacy Assurance, GDPR and various other risk-based projects) * Plan, execute ... Petersburg and are looking for a Practice Manager/ IT Auditor to join our team.
Quick apply
... HITRUST, Vendor Privacy Assurance, GDPR and various other risk-based projects) * Plan, execute ... Petersburg and are looking for a Practice Manager/ IT Auditor to join our team.
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Cyber Security Specialist
Minneapolis, MN · On-site
... HITRUST). * Experience with Cloudflare, Burp Suite, Metasploit preferred. * Experience deploying and auditing Microsoft Mobile Device Management (Intune). * Strong core competencies in detail ...
Cyber Security Specialist
Minneapolis, MN · On-site
... HITRUST). * Experience with Cloudflare, Burp Suite, Metasploit preferred. * Experience deploying and auditing Microsoft Mobile Device Management (Intune). * Strong core competencies in detail ...
Support SOC 2, HITRUST, and other frameworks. * Complete customer security questionnaires, RFPs ... auditors. * Provide technical support during customer security reviews and sales processes.
Support SOC 2, HITRUST, and other frameworks. * Complete customer security questionnaires, RFPs ... auditors. * Provide technical support during customer security reviews and sales processes.
Security & Compliance Specialist
OR · On-site +1
Support SOC 2, HITRUST, and other frameworks. * Complete customer security questionnaires, RFPs ... auditors. * Provide technical support during customer security reviews and sales processes.
Security & Compliance Specialist
OR · On-site +1
Support SOC 2, HITRUST, and other frameworks. * Complete customer security questionnaires, RFPs ... auditors. * Provide technical support during customer security reviews and sales processes.
Cyber Security Specialist
Minneapolis, MN · On-site
... HITRUST). * Experience with Cloudflare, Burp Suite, Metasploit preferred. * Experience deploying and auditing Microsoft Mobile Device Management (Intune). * Strong core competencies in detail ...
Cyber Security Specialist
Minneapolis, MN · On-site
... HITRUST). * Experience with Cloudflare, Burp Suite, Metasploit preferred. * Experience deploying and auditing Microsoft Mobile Device Management (Intune). * Strong core competencies in detail ...
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number ...
Security Manager II - GRC
Tampa, FL · On-site
$145K - $160K/yr
... auditor liaising, and remediation tracking. · Own HIPAA Security Rule and Privacy Rule compliance programs, including risk analysis, workforce training, and BAA management. · Lead HITRUST CSF ...
New
Quick apply
Security Manager II - GRC
Tampa, FL · On-site
$145K - $160K/yr
... auditor liaising, and remediation tracking. · Own HIPAA Security Rule and Privacy Rule compliance programs, including risk analysis, workforce training, and BAA management. · Lead HITRUST CSF ...
New
Hitrust Auditor information
See salary details
$38.5K - $48.7K
3% of jobs
$48.7K - $59K
11% of jobs
$59K - $69.2K
8% of jobs
$72.5K is the 25th percentile. Wages below this are outliers.
$69.2K - $79.4K
11% of jobs
The median wage is $88.3K / yr.
$79.4K - $89.6K
20% of jobs
$89.6K - $99.9K
13% of jobs
$108K is the 75th percentile. Wages above this are outliers.
$99.9K - $110.1K
12% of jobs
$110.1K - $120.3K
11% of jobs
$120.3K - $130.5K
9% of jobs
$130.5K - $140.8K
3% of jobs
$140.8K - $151K
0% of jobs
$38.5K
$92.8K
$151K
How much do hitrust auditor jobs pay per year?
What is the difference between Hitrust Auditor vs SOC Auditor?
| Aspect | Hitrust Auditor | SOC Auditor |
|---|---|---|
| Certifications | HITRUST CSF Assessor, Certified Information Systems Auditor (CISA) | SOC 1, SOC 2, CISA |
| Work Environment | Healthcare, health information organizations | Various industries including healthcare, finance, tech |
| Employer & Industry Usage | Healthcare providers, health plans, vendors | Organizations requiring compliance reports |
| Search & Comparison Intent | Understanding HITRUST compliance assessments | Evaluating controls via SOC reports |
The Hitrust Auditor primarily focuses on assessing healthcare organizations' compliance with the HITRUST CSF, while the SOC Auditor evaluates controls across various industries through SOC reports. Both roles require similar certifications like CISA and involve compliance and risk assessment, but they serve different regulatory frameworks and industry needs.

Other
Medical, Dental, Vision, Retirement, PTO
Posted 25 days ago
Job description
We are seeking a detail-oriented, proactive Security Compliance Engineer to join our Security team.
In this role, you will not just check boxes; you will own the governance and compliance lifecycle for critical security programs and, in many cases, be actively involved in implementation and remediation. You will ensure that our vulnerability management, privacy, data retention, and business continuity efforts meet the rigorous standards of SOC 2, HIPAA, and HITRUST, protecting our sensitive healthcare data and maintaining trust with our partners.
This role requires onsite presence in our New York City office 4 days a week and does not provide immigration support.
What you will do: Vulnerability Management Governance- Oversee the compliance aspect of the vulnerability management program, ensuring scans and remediation efforts adhere to SLAs.
- Track and report on remediation timelines to ensure evidence is audit-ready.
- Collaborate with engineering and IT teams to validate that exceptions are documented, risk-accepted, and reviewed periodically.
- Manage and handle "tracking technologies" to comply with partner requirements
Privacy & Data Governance
- Manage adherence to internal privacy policies and external regulations (HIPAA, State Laws, CCPA).
- Manage adherence to partner-specific health system requirements
- Monitor data retention schedules to ensure data is stored, archived, and purged in accordance with policy and legal requirements.
- Conduct periodic privacy impact assessments (PIAs) for new products or features.
Disaster Recovery (DR) & Business Continuity (BCP)
- Coordinate annual or bi-annual DR/BCP table-top exercises and technical tests.
- Maintain and update DR/BCP documentation, ensuring contact lists and recovery procedures are current.
- Review post-mortem reports from tests to ensure continuous improvement and compliance with availability trust principles.
Audit & Framework Management (SOC 2 & HITRUST)
- Serve as a primary point of contact for external auditors during SOC 2 and HITRUST assessments.
- Collect, organize, and review evidence on the controls for the programs above.
- Identify compliance gaps and drive remediation projects before external audits begin.
AI/ML in healthcare and emerging federal and state AI regulations
What we're looking for:- Experience: 3-5+ years of experience in Information Security, Governance, Risk, Vulnerability Management, Compliance (GRC), or IT Audit.
- Program Management: Proven experience managing specific compliance verticals like vulnerability management or business continuity.
- Communication: Ability to translate compliance requirements into actionable technical tasks for engineering teams.
- Organization: Exceptional documentation skills-you understand that "if it isn't written down, it didn't happen."
- Influence: Ability to drive consensus and compliance across teams without direct management authority.
Benefits & Perks: #LI-Hybrid
- Hybrid work schedule with weekly lunches and stocked fridges
- Monthly social committees for company events
- 18 vacation days, 9 company holidays, 5 sick days, and 2 personal days
- Stock options for every full-time employee
- Paid parental leave
- 401k benefit
- Commuter Benefits
- Competitive health, dental, and vision insurance options