1

Hitrust Contract Jobs in New York (NOW HIRING)

Director of Technology

New York, NY · On-site

$175K - $225K/yr

Experience with HIPAA-regulated environments including SOC2 Type 2 and HITRUST. * Experience managing technology budgets and vendor contracts. * Excellent communication and executive presentation ...

Hitrust Contract information

What is the difference between Hitrust Contract vs Security Analyst?

AspectHitrust ContractSecurity Analyst
CertificationsHITRUST CSF, HIPAACISSP, CISA, Security+
Work EnvironmentHealthcare, compliance-focusedIT security teams, various industries
Employer & IndustryHealthcare providers, vendorsAny industry with cybersecurity needs

HITRUST Contract roles focus on ensuring compliance with HITRUST standards, primarily in healthcare. Security Analysts handle broader cybersecurity tasks across industries, including threat detection and risk management. While both roles require security certifications, HITRUST Contract positions emphasize healthcare regulations, whereas Security Analysts have a wider scope in cybersecurity practices.

What are some common challenges faced by professionals working on HITRUST contract compliance projects?

Professionals working on HITRUST contract compliance projects often face challenges such as interpreting complex regulatory requirements, coordinating with multiple departments to gather documentation, and ensuring that all security controls are properly implemented and maintained. Additionally, meeting tight audit deadlines and effectively communicating technical requirements to non-technical stakeholders can be demanding. These roles frequently require strong project management skills, attention to detail, and the ability to adapt to evolving compliance standards.

What is a HITRUST contract?

A HITRUST contract is a legal agreement that outlines the requirements and responsibilities for achieving or maintaining HITRUST certification, a widely recognized standard for information security and privacy in the healthcare industry. These contracts are often used between organizations and their vendors or partners to ensure compliance with the HITRUST Common Security Framework (CSF). The contract typically specifies the controls, reporting, and audit obligations needed to protect sensitive data, such as patient health information, and to meet regulatory requirements like HIPAA. Entering into a HITRUST contract can help organizations demonstrate their commitment to security and build trust with clients and partners.

What are the key skills and qualifications needed to thrive as a HITRUST Compliance Manager, and why are they important?

To thrive as a HITRUST Compliance Manager, you need in-depth knowledge of information security, risk management, and regulatory frameworks, typically backed by a degree in IT or cybersecurity and experience with HITRUST CSF. Familiarity with compliance management tools, GRC systems, and HITRUST certification processes is crucial. Outstanding attention to detail, problem-solving skills, and strong communication abilities help you interpret standards and guide organizations through audits. These competencies ensure organizations maintain robust data protection, regulatory compliance, and successful HITRUST certification.
What are the most commonly searched types of Hitrust jobs in New York? The most popular types of Hitrust jobs in New York are:
What are popular job titles related to Hitrust Contract jobs in New York? For Hitrust Contract jobs in New York, the most frequently searched job titles are:
What cities in New York are hiring for Hitrust Contract jobs? Cities in New York with the most Hitrust Contract job openings:
Infographic showing various Hitrust Contract job openings in New York as of June 2026, with employment types broken down into 1% Internship, 1% As Needed, 2% Full Time, 95% Contract, and 1% Nights. Highlights an 83% Physical, 2% Hybrid, and 15% Remote job distribution.

Senior Project Manager Vulnerability Remediation (Healthcare Domain)

Krest Global Solutions

Jersey City, NJ

$60 - $65/hr

Contractor

Re-posted 14 days ago


Job description

Job Title: Senior Project Manager – Vulnerability Remediation (Healthcare Domain)

Location: Onsite

Experience: 10–15+ years

Employment Type: Contract

Rate: 60-65$/Hr.

Role Summary

The Senior Project Manager will lead and manage large-scale vulnerability remediation programs across healthcare application portfolios and infrastructure systems. This role will ensure timely identification, prioritization, and remediation of Critical and High vulnerabilities aligned to regulatory and compliance requirements (HIPAA, HITECH, CMS, HITRUST). The candidate must have hands-on experience driving remediation activities for both application development (code, libraries, APIs, and platform vulnerabilities) and infrastructure (patching, server configuration, network, and cloud security issues).


Key Responsibilities

  • Lead end-to-end program execution for vulnerability remediation related to applications, databases, servers, cloud environments, and legacy healthcare platforms.
  • Prioritize and track remediation of CVITs, VITs, vulnerabilities in code, patch deployments, and configuration fixes across technical teams.
  • Work with security, DevOps, application development, enterprise architecture, and infrastructure teams to systematically remediate scan findings.
  • Conduct backlog grooming, sprint planning, release coordination, and delivery tracking for remediation activities.
  • Analyze vulnerability scan reports and dashboards from tools such as Qualys, Tenable, Rapid7, CrowdStrike, Microsoft Defender, etc.
  • Develop remediation plans aligned to exposure of PHI/PII, severity, exploitability, and system criticality.
  • Prepare and present weekly status decks, risk registers, and executive scorecards for senior leadership and audit teams.
  • Oversee SOW deliverables, team onboarding, cross-shore coordination, and stakeholder alignment.
  • Ensure remediation governance, compliance documentation, and closure of cyber audit findings.
  • Develop and refine remediation SLAs, prioritization models, RAID logs, and approval workflows involving business, security, and IT stakeholders.

Required Skills & Qualifications

  • 10+ years of IT project or program management experience, including 5+ years dedicated to security or vulnerability remediation.
  • Must have experience managing both application development and infrastructure-related vulnerabilities, including:
    • Code vulnerabilities (OWASP, dependency issues, API weaknesses, encryption gaps)
    • Infrastructure vulnerabilities (OS patching, server hardening, cloud misconfigurations, IAM issues)
  • Deep understanding of healthcare systems and PHI security risks.
  • Strong knowledge of healthcare compliance frameworks such as HIPAA, HITECH, HITRUST, NIST CSF, CMS.
  • Experience working in distributed delivery models with offshore/onshore teams.
  • Proficient in Agile, Scrum, and hybrid methodologies.
  • Excellent communication, stakeholder influencing, and senior leadership reporting capabilities.
  • Familiarity with SQL, cloud platforms (Azure/AWS), CI/CD pipelines, and DevSecOps practices.

Preferred Certifications

  • PMP, CSM, SAFe
  • CompTIA Security+, CISSP, CISM
  • HITRUST or healthcare security certifications (preferred)

Healthcare Domain Experience (Preferred)

  • Payer systems (Medicaid, Medicare, Marketplace, Commercial)
  • Claims processing, provider data, enrollment, pharmacy, member access systems
  • Legacy remediation involving .NET, Java, SAP, Oracle, Salesforce Health Cloud, and Data Hub environments

Key Success Metrics

  • Reduction in Critical/High vulnerability backlog
  • SLA compliance for remediation (30/60/90-day closure)
  • Audit remediation closure rate
  • Legacy backlog risk reduction
  • Operational readiness and stability for healthcare systems