Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and ... Experience owning client security questionnaire responses and external audit engagements
Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and ... Experience owning client security questionnaire responses and external audit engagements
Conduct and oversee complex risk assessments , including HIPAA and HITRUST-aligned evaluations ... Lead security assessments of cloud and hybrid environments (e.g., IaaS, PaaS, SaaS) * Evaluate key ...
Conduct and oversee complex risk assessments , including HIPAA and HITRUST-aligned evaluations ... Lead security assessments of cloud and hybrid environments (e.g., IaaS, PaaS, SaaS) * Evaluate key ...
Manager, Security
Buffalo, NY · On-site
Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and ... Experience owning client security questionnaire responses and external audit engagements
Manager, Security
Buffalo, NY · On-site
Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and ... Experience owning client security questionnaire responses and external audit engagements
Senior Security Compliance Analyst
OR · Remote
$125K - $175K/yr
Conduct third-party vendor risk assessments, ensuring compliance with security policies and ... Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external ...
Senior Security Compliance Analyst
OR · Remote
$125K - $175K/yr
Conduct third-party vendor risk assessments, ensuring compliance with security policies and ... Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external ...
Senior GRC Analyst
Richmond, VA · On-site +1
$95K - $124K/yr
Experience supporting HITRUST readiness or validated assessments. Experience with vendor risk management or third-party security assessments. Experience supporting HIPAA, PCI DSS, GDPR, or other ...
Senior GRC Analyst
Richmond, VA · On-site +1
$95K - $124K/yr
Experience supporting HITRUST readiness or validated assessments. Experience with vendor risk management or third-party security assessments. Experience supporting HIPAA, PCI DSS, GDPR, or other ...
This role owns the operationalization of frameworks, certifications (SOC 2, HIPAA/HITECH, HITRUST ... Oversee governance activities including risk assessments, internal audits, compliance reviews, and ...
This role owns the operationalization of frameworks, certifications (SOC 2, HIPAA/HITECH, HITRUST ... Oversee governance activities including risk assessments, internal audits, compliance reviews, and ...
Lead IT Security Analyst
New York, NY · On-site
Assess alignment to frameworks such as: * HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively ...
Lead IT Security Analyst
New York, NY · On-site
Assess alignment to frameworks such as: * HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively ...
Manager, Security
Buffalo, NY · On-site
Description Manager, Security Overview The Manager, Security (Governance, Risk & Compliance) plays ... Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and ...
Manager, Security
Buffalo, NY · On-site
Description Manager, Security Overview The Manager, Security (Governance, Risk & Compliance) plays ... Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and ...
Its threat-adaptive approach combines tiered, selectable assessments (e1, i1, r2, and AI), an ... HITRUST delivers the only assurance certification with defensible proof of security, demonstrated ...
Its threat-adaptive approach combines tiered, selectable assessments (e1, i1, r2, and AI), an ... HITRUST delivers the only assurance certification with defensible proof of security, demonstrated ...
Lead IT Security Analyst
Manhattan, NY · On-site
$121K - $210K/yr
Assess alignment to frameworks such as: * HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively ...
Lead IT Security Analyst
Manhattan, NY · On-site
$121K - $210K/yr
Assess alignment to frameworks such as: * HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively ...
Sr. Information Security Engineer
$140K - $160K/yr
... HITRUST, SOC 2, and customer security assessments. • Maintain asset inventories, risk registers, and remediation tracking. • Collaborate with Compliance to ensure alignment between security ...
Sr. Information Security Engineer
$140K - $160K/yr
... HITRUST, SOC 2, and customer security assessments. • Maintain asset inventories, risk registers, and remediation tracking. • Collaborate with Compliance to ensure alignment between security ...
Manager, Security
Nashville, TN · On-site
Description Manager, Security Overview The Manager, Security (Governance, Risk & Compliance) plays ... Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and ...
Manager, Security
Nashville, TN · On-site
Description Manager, Security Overview The Manager, Security (Governance, Risk & Compliance) plays ... Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and ...
Its threat-adaptive approach combines tiered, selectable assessments (e1, i1, r2, and AI), an ... HITRUST delivers the only assurance certification with defensible proof of security, demonstrated ...
Its threat-adaptive approach combines tiered, selectable assessments (e1, i1, r2, and AI), an ... HITRUST delivers the only assurance certification with defensible proof of security, demonstrated ...
Manager, Security
Nashville, TN · On-site
Description Manager, Security Overview The Manager, Security (Governance, Risk & Compliance) plays ... Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and ...
Manager, Security
Nashville, TN · On-site
Description Manager, Security Overview The Manager, Security (Governance, Risk & Compliance) plays ... Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and ...
IT Security Specialist
Detroit, MI · On-site
... assessment remediation plans and documentation * Serve as a HITRUST subject matter expert ... Knowledge of security and risk frameworks, standards, best practices (e.g., HITRUST CSF, NIST CSF ...
Quick apply
IT Security Specialist
Detroit, MI · On-site
... assessment remediation plans and documentation * Serve as a HITRUST subject matter expert ... Knowledge of security and risk frameworks, standards, best practices (e.g., HITRUST CSF, NIST CSF ...
Senior GRC Analyst
Manhattan, NY · On-site +1
Experience supporting HITRUST readiness or validated assessments. Experience with vendor risk management or third-party security assessments. Experience supporting HIPAA, PCI DSS, GDPR, or other ...
Senior GRC Analyst
Manhattan, NY · On-site +1
Experience supporting HITRUST readiness or validated assessments. Experience with vendor risk management or third-party security assessments. Experience supporting HIPAA, PCI DSS, GDPR, or other ...
Security Analyst
Columbia, MD · Hybrid
$55 - $60/hr
... Security ... Rule, and HITRUST CSF, PCI-DSS. The role supports risk assessments, audit readiness, control ...
New
Security Analyst
Columbia, MD · Hybrid
$55 - $60/hr
... Security ... Rule, and HITRUST CSF, PCI-DSS. The role supports risk assessments, audit readiness, control ...
New
Security Architect
OR · Remote
$65 - $84/hr
About the Role The Security Architect is a technical, hands-on senior role responsible for ... risk assessments to identify control gaps and ensure technical alignment with SOC2, HITRUST, and ...
Security Architect
OR · Remote
$65 - $84/hr
About the Role The Security Architect is a technical, hands-on senior role responsible for ... risk assessments to identify control gaps and ensure technical alignment with SOC2, HITRUST, and ...
Director of Security
OR · Remote
$190K - $240K/yr
The scope includes third party risk, vendor assessment and qualification, security architecture ... HITRUST certification. * Experience with AI security risk management, data protection for AI use ...
Director of Security
OR · Remote
$190K - $240K/yr
The scope includes third party risk, vendor assessment and qualification, security architecture ... HITRUST certification. * Experience with AI security risk management, data protection for AI use ...
Security Analyst
Nashville, TN · On-site
Ensure compliance with HITRUST standards, HIPAA regulations, and other relevant healthcare security requirements. * Conduct ongoing risk assessments and security audits to maintain and demonstrate ...
Security Analyst
Nashville, TN · On-site
Ensure compliance with HITRUST standards, HIPAA regulations, and other relevant healthcare security requirements. * Conduct ongoing risk assessments and security audits to maintain and demonstrate ...
Hitrust Security Assessor information
See salary details
$8.89 - $15.19
2% of jobs
$15.19 - $21.48
2% of jobs
$21.48 - $27.78
0% of jobs
$27.78 - $34.07
0% of jobs
$34.07 - $40.36
3% of jobs
$40.36 - $46.66
5% of jobs
$50.35 is the 25th percentile. Wages below this are outliers.
$46.66 - $52.95
21% of jobs
The median wage is $58.08 / hr.
$52.95 - $59.24
20% of jobs
$59.24 - $65.54
18% of jobs
$67 is the 75th percentile. Wages above this are outliers.
$65.54 - $71.83
15% of jobs
$71.83 - $78.13
14% of jobs
$8
$58
$78
How much do hitrust security assessor jobs pay per hour?
What are HITRUST Security Assessors?
What are some common challenges faced by HITRUST Security Assessors during the certification process?
What is the difference between Hitrust Security Assessor vs Hitrust Risk Analyst?
| Aspect | Hitrust Security Assessor | Hitrust Risk Analyst |
|---|---|---|
| Certifications | HITRUST CSF Practitioner, CISSP, CISA | HITRUST CSF Practitioner, CISSP, CISA |
| Work Environment | Consulting firms, healthcare, and financial organizations | Healthcare, finance, and compliance teams within organizations |
| Primary Focus | Assessing and validating security controls for HITRUST compliance | Analyzing and identifying security risks and vulnerabilities |
Hitrust Security Assessors primarily evaluate organizations' security controls to ensure HITRUST compliance, while Hitrust Risk Analysts focus on identifying and analyzing security risks. Both roles require similar certifications and often work within healthcare and financial sectors, but their core responsibilities differ: assessment versus risk analysis.
What are the key skills and qualifications needed to thrive as a Hitrust Security Assessor, and why are they important?

Job description
Manager, SecurityOverview
TheManager, Security (Governance, Risk & Compliance)plays a critical role in protectingWayspring'smission and reputation by ensuring we are trusted,audit-ready, and confident in how we safeguard data. This leader owns our healthcare compliance and security assurance programs - including HIPAA, HITRUST, and vendor risk - and serves as the clearpointperson for how wedemonstratesecurity to clients, partners, auditors, and regulators. More than checking boxes, this role helps turn our security posture into a true business advantage by accelerating client trust, enabling sales, and strengtheningWayspring'slong-termregulatory foundation.
This is ahigh-impact,hands-onrole for someone who enjoys building smart, scalable programs and reducing friction across the organization.You'llwork closely with teams across Legal, IT, Engineering, Compliance, and the business to embed security into real workflows - not just policies on paper. With ownership of key audits, automation strategy, and future GRC growth, this role offers the opportunity to shape how compliance works at Wayspring as we scale, while making a measurable difference in how quickly and confidently we serve members and partners.This role reports to the VP, Architecture &Securityand partners closely with Legal and Compliance to support enterprise regulatory and contractual obligations through effective security and technology governance.
Why Wayspring?
We are passionate about breaking barriers alongside those facing substance usedisorder. Whetheryou'rein the field or in the corporate office - our mission is felt, and your impact is recognized. There is no inner circle, and we all have a seat at the table. Leaders are accessible and silos are avoided. We respect your craft and love to be challenged. We invest not only in our mission, but in each other. Internal promotions and cross departmental training are the norm- you grow, we grow.
Investment in your growth: Wayspring provides an annual learning and certification budget that can be used for conferences (e.g., HIMSS, HITRUST Collaborate, RSA), training, and industry certifications (e.g., CISSP, CISM, CRISC, HITRUST CCSFP maintenance). We are eager to support your continued development in this role.
Responsibilitiesof theManager, Security
- Runsclient securitydue-diligenceas a sales-enablement function. Ownsthe questionnaire response process, pre-fill library, and SLA commitments so that security acceleratesdealvelocity. Partnerswith Business Development and Account Management to turn our security posture into a competitive advantage
- OwnsThird-Party Risk Management (TPRM) and vendor risk. Build andoperate the vendor intake, review, re-assessment, and offboarding process; set risk tiers; integrate with Procurement and Legal workflows
- Ownsthe GRC platform and evidence automation strategy. Drives continuous control monitoring, automated evidence collection, and measurable reductions in manual compliance work
- Develops,maintains, andenforcesWayspring's information security policies and procedures, ensuring they reflect actual organizational practice
- Owns the company-wide security awareness program-phishing simulations, annual training, and role-based training for high-risk populations (executives, engineering, clinical operations)
- OwnsandmanagesWayspring's HITRUST certification lifecycle end-to-end: scoping, readiness, full and interim assessments, evidence collection, gap remediation, and auditor coordination
- LeadsPCI DSS compliance for the scope relevant toWayspring'smember payment processing, applying right-sized controls (e.g., SAQ-aligned whereappropriate) that match the risk profile
- Drivesconcrete outcomes againstWayspring's stated security commitments: close findings on defined timelines, track attestation coverage, and report posture metrics to the VP, Architecture & Security
- Partnerswith Legal, Compliance, HR, and IT & Infrastructure to embed compliance into business processes from the start
Management Practices & Expectations
- Remainsactively engaged in the healthcare regulatory and compliance landscape (e.g., OCR enforcement trends, HIPAA/HICCUP, HITRUST CSF updates, state privacy laws) toanticipate changes rather than react to them
- Ensures compliance activities meet security, reliability, and cost expectations, so compliance creates durable business value beyond audit outcomes
- Drives automation and leverage to reduce manual compliance burden for every team at Wayspring
- UsesAI-assisted tools to accelerate policy drafting, evidence analysis, questionnaire responses, and compliance research, whileremaining accountable for decisions
- Buildsandmaintain strong relationships with external auditors, assessors, and regulatory bodies
- Represent Wayspring'scompliance posture credibly to clients, prospects, regulators, and executive stakeholders
Ownership & Accountability
- Accountable forWayspring'scompliance posture across HITRUST, HIPAA, and the in-scopeportion of PCI DSS
- Accountable for timely,accurate, high-quality completion of client security questionnaires and due-diligence requests
- Accountable for third-party and vendor risk across the organization
- Owns the integrity and currency of all security policies, procedures, and training programs
- Owns building and developing GRC capacity, including future hiring as the program scales
The following expectations apply to every technical leader, with scope, impact, and accountability increasing at higher levels:
- Security comes first. Leaders are accountable for ensuring their teamsoperate with strong security, privacy, and compliance awareness.
- Leaders own outcomes, not just activity. Delivery, quality, reliability, and sustainability are core responsibilities.
- Functional leadership matters. Leaders actively guide technical direction, standards, and decision-making within their domain.
- Systems and teams are treated as products. Processes, team structures, and delivery mechanisms are intentionally designed and continuously improved.
- Automation and leverage are expected. Leaders push teams to reduce manual work and improve scalability through tooling and process improvement.
- Cross-functional collaboration is essential. Leaders partner effectively across disciplines to deliver outcomes.
- AI tools are used to increase effectiveness. Leaders may use AI-assisted tools to support planning, analysis, documentation, and communication, while remainingaccountable for decisions.
RequirementsandPreferred Qualifications
- 5+ years of experience in information security governance, risk, and compliance, with at least 2 years in a healthcare or health-tech environment
- Direct, hands-on experience leading at least one HITRUST certification cycle (CSF assessments and evidence lifecycle)
- Strong working knowledge of HIPAA requirements and how they apply in a clinical services environment
- Experience owning client security questionnaire responses and external audit engagements
- Experience operating a modern GRC platform (continuous control monitoring and automated evidence collection), with the judgment to select or transition platforms as the program matures
- Demonstrated ability to write, maintain, and operationalize security policies and procedures
- Strong communicationskills with the ability to translate compliance requirements into business-friendly language for non-technical stakeholders
Preferred
- Experience building or running a Third-Party Risk Management program
- Familiarity with the narrow-scope application of PCI DSS to member payment processing in a healthcare context
- Experience partnering directly with Business Development and Account Management on security-as-sales-enablement
- Experience in substance use disorder, behavioral health, or Medicare-adjacent healthcare environments
- Relevant certifications: CISSP, CISM, CRISC, HCISPP, HITRUST CCSFP, or equivalent
Our goal is to foster a workplace where everyone feels a true sense of belonging, is supported, and empowered to thrive. We actively seek different backgrounds, perspectives, and experiences-because we believe that drives better performance and innovation.We'recommitted toidentifyingand removing barriers for the communities we serve.
Benefit Summary
Creatinga greatemployee experience takes more than justperks-butlet'sbereal,those matter too.Here'showwe're building a company where you, your family, your pets, and your passions can thrive
- Comprehensive Medical, Dental and VisionInsurance options - including options for your pets!
- Company funded HSA +Monthly Gym Allowance
- Paid parental leave - all parents included!
- Company paid short term disability, long term disability and life insurance
- 401k with company match
- Premium Employee Assistance Program, inclusive of counseling sessions
- Pardon and Expungement Scholarship Program
- Company Contributions to Future Minded Savings (HSA and Emergency savings fund)
- Generous PTO package (accrual policy based on years of service) and an additional10 paid company holidays
- Company 2 week paid sabbatical program!
- Provider Benefits include ASAM training and membership + $2,500 CEU annual stipend and more!
About Wayspring
Sourced by ZipRecruiter
Industry
Health care and social assistance
Company size
51 - 200 Employees
Headquarters location
Nashville, TN, US
Year founded
2012