Assess all audit findings, establishing a prioritized path to mitigation * Report the state of ... Experience within a HiTrust certified organization and involvement in ongoing adherence
Assess all audit findings, establishing a prioritized path to mitigation * Report the state of ... Experience within a HiTrust certified organization and involvement in ongoing adherence
Assess all audit findings, establishing a prioritized path to mitigation * Report the state of ... Experience within a HiTrust certified organization and involvement in ongoing adherence
Assess all audit findings, establishing a prioritized path to mitigation * Report the state of ... Experience within a HiTrust certified organization and involvement in ongoing adherence
The CISO will lead security strategy across HITRUST CSF, SOC 2 (Type I & II), HIPAA/HITECH, and ... assessor engagement, and gap remediation * Lead SOC 2 Type II audits, including Trust Services ...
The CISO will lead security strategy across HITRUST CSF, SOC 2 (Type I & II), HIPAA/HITECH, and ... assessor engagement, and gap remediation * Lead SOC 2 Type II audits, including Trust Services ...
Security Analyst
Nashville, TN · On-site
Ensure compliance with HITRUST standards, HIPAA regulations, and other relevant healthcare securityrequirements. * Conduct ongoing risk assessments and security audits to maintain and demonstrate ...
Security Analyst
Nashville, TN · On-site
Ensure compliance with HITRUST standards, HIPAA regulations, and other relevant healthcare securityrequirements. * Conduct ongoing risk assessments and security audits to maintain and demonstrate ...
Assess all audit findings, establishing a prioritized path to mitigation * Report the state of ... Experience within a HiTrust certified organization and involvement in ongoing adherence
Quick apply
Assess all audit findings, establishing a prioritized path to mitigation * Report the state of ... Experience within a HiTrust certified organization and involvement in ongoing adherence
Assess all audit findings, establishing a prioritized path to mitigation * Report the state of ... Experience within a HiTrust certified organization and involvement in ongoing adherence
Assess all audit findings, establishing a prioritized path to mitigation * Report the state of ... Experience within a HiTrust certified organization and involvement in ongoing adherence
Staff, Security Engineer (App & Product Sec)
San Francisco, CA · On-site +1
$69.25 - $92.50/hr
... 2, HITRUST, ISO 27001, or similar * Led vulnerability management, penetration testing coordination, remediation workflows, and security assessments * Partnered with engineering teams to embed ...
Staff, Security Engineer (App & Product Sec)
San Francisco, CA · On-site +1
$69.25 - $92.50/hr
... 2, HITRUST, ISO 27001, or similar * Led vulnerability management, penetration testing coordination, remediation workflows, and security assessments * Partnered with engineering teams to embed ...
Staff, Security Engineer (App & Product Sec)
San Francisco, CA · On-site +1
$235K - $300K/yr
... 2, HITRUST, ISO 27001, or similar * Led vulnerability management, penetration testing coordination, remediation workflows, and security assessments * Partnered with engineering teams to embed ...
Staff, Security Engineer (App & Product Sec)
San Francisco, CA · On-site +1
$235K - $300K/yr
... 2, HITRUST, ISO 27001, or similar * Led vulnerability management, penetration testing coordination, remediation workflows, and security assessments * Partnered with engineering teams to embed ...
Security Analyst/Third-Party Risk Management (TPRM) - remote PST
Long Beach, CA · Remote
$60 - $70/hr
Conduct end-to-end vendor information security assessments, reviewing questionnaires (SIG, CAIQ ... Working knowledge of NIST CSF, HITRUST CSF, SOC 2, ISO 27001, and HIPAA Security Rule, with an ...
Security Analyst/Third-Party Risk Management (TPRM) - remote PST
Long Beach, CA · Remote
$60 - $70/hr
Conduct end-to-end vendor information security assessments, reviewing questionnaires (SIG, CAIQ ... Working knowledge of NIST CSF, HITRUST CSF, SOC 2, ISO 27001, and HIPAA Security Rule, with an ...
... HITRUST, ISO 27000, GLBA, and various other IT Audit, IT Risk Assessments, and Information Security Assessments * Work on multiple projects in varying stages through completion and issuance of final ...
Quick apply
... HITRUST, ISO 27000, GLBA, and various other IT Audit, IT Risk Assessments, and Information Security Assessments * Work on multiple projects in varying stages through completion and issuance of final ...
IT Security Specialist I- Governance Analyst : Detroit, MI (Onsite)(Only local)
Detroit, MI · On-site
... assessment remediation plans and documentation • Serve as a HITRUST subject matter expert • ... of security and risk frameworks, standards, best practices (e.g., HITRUST CSF, NIST CSF, ISO/IEC ...
Quick apply
IT Security Specialist I- Governance Analyst : Detroit, MI (Onsite)(Only local)
Detroit, MI · On-site
... assessment remediation plans and documentation • Serve as a HITRUST subject matter expert • ... of security and risk frameworks, standards, best practices (e.g., HITRUST CSF, NIST CSF, ISO/IEC ...
The scope includes third party risk, vendor assessment and qualification, security architecture ... HITRUST certification. * Experience with AI security risk management, data protection for AI use ...
The scope includes third party risk, vendor assessment and qualification, security architecture ... HITRUST certification. * Experience with AI security risk management, data protection for AI use ...
Senior Security Compliance Analyst
Boston, MA · Remote
$125K - $175K/yr
Conduct third-party vendor risk assessments, ensuring compliance with security policies and ... Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external ...
Quick apply
Senior Security Compliance Analyst
Boston, MA · Remote
$125K - $175K/yr
Conduct third-party vendor risk assessments, ensuring compliance with security policies and ... Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external ...
Director of Security
Boston, MA · Remote
The scope includes third party risk, vendor assessment and qualification, security architecture ... HITRUST certification. * Experience with AI security risk management, data protection for AI use ...
Quick apply
Director of Security
Boston, MA · Remote
The scope includes third party risk, vendor assessment and qualification, security architecture ... HITRUST certification. * Experience with AI security risk management, data protection for AI use ...
Senior Security Compliance Analyst
$125K - $175K/yr
Conduct third-party vendor risk assessments, ensuring compliance with security policies and ... Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external ...
Senior Security Compliance Analyst
$125K - $175K/yr
Conduct third-party vendor risk assessments, ensuring compliance with security policies and ... Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external ...
Security Manager II - GRC
Tampa, FL · On-site
$145K - $160K/yr
Key Responsibilities: · Lead and mature the GRC program across security, privacy, and regulatory ... HITRUST CSF assessment cycles -- scoping, gap analysis, corrective action plans, and Validated ...
Quick apply
Security Manager II - GRC
Tampa, FL · On-site
$145K - $160K/yr
Key Responsibilities: · Lead and mature the GRC program across security, privacy, and regulatory ... HITRUST CSF assessment cycles -- scoping, gap analysis, corrective action plans, and Validated ...
Oversee SOC 2 Type II, HITRUST, ISO 27001, and other certification efforts as appropriate. * Maintain audit readiness for client security assessments and regulatory inquiries. * Support Business ...
Oversee SOC 2 Type II, HITRUST, ISO 27001, and other certification efforts as appropriate. * Maintain audit readiness for client security assessments and regulatory inquiries. * Support Business ...
Experience conducting SOC 2 Type 1 and Type 2 audits Experience with working on HITRUST assessments (certification not required at hire) Knowledge/experience on HIPAA compliance (Privacy & Security ...
Experience conducting SOC 2 Type 1 and Type 2 audits Experience with working on HITRUST assessments (certification not required at hire) Knowledge/experience on HIPAA compliance (Privacy & Security ...
Security Architect
$178K - $203K/yr
... risk assessments to identify control gaps and ensure technical alignment with SOC2, HITRUST, and ... Core Security Stack: Proven ability to manage and tune Cloudflare (WAF/Zero Trust) and CrowdStrike ...
Security Architect
$178K - $203K/yr
... risk assessments to identify control gaps and ensure technical alignment with SOC2, HITRUST, and ... Core Security Stack: Proven ability to manage and tune Cloudflare (WAF/Zero Trust) and CrowdStrike ...
Experience conducting SOC 2 Type 1 and Type 2 audits Experience with working on HITRUST assessments (certification not required at hire) Knowledge/experience on HIPAA compliance (Privacy & Security ...
Experience conducting SOC 2 Type 1 and Type 2 audits Experience with working on HITRUST assessments (certification not required at hire) Knowledge/experience on HIPAA compliance (Privacy & Security ...
Hitrust Security Assessor information
See salary details
$8.89 - $15.19
2% of jobs
$15.19 - $21.48
2% of jobs
$21.48 - $27.78
0% of jobs
$27.78 - $34.07
0% of jobs
$34.07 - $40.36
3% of jobs
$40.36 - $46.66
5% of jobs
$50.35 is the 25th percentile. Wages below this are outliers.
$46.66 - $52.95
21% of jobs
The median wage is $58.08 / hr.
$52.95 - $59.24
20% of jobs
$59.24 - $65.54
18% of jobs
$67 is the 75th percentile. Wages above this are outliers.
$65.54 - $71.83
15% of jobs
$71.83 - $78.13
14% of jobs
$8
$58
$78
How much do hitrust security assessor jobs pay per hour?
What are HITRUST Security Assessors?
What are some common challenges faced by HITRUST Security Assessors during the certification process?
What is the difference between Hitrust Security Assessor vs Hitrust Risk Analyst?
| Aspect | Hitrust Security Assessor | Hitrust Risk Analyst |
|---|---|---|
| Certifications | HITRUST CSF Practitioner, CISSP, CISA | HITRUST CSF Practitioner, CISSP, CISA |
| Work Environment | Consulting firms, healthcare, and financial organizations | Healthcare, finance, and compliance teams within organizations |
| Primary Focus | Assessing and validating security controls for HITRUST compliance | Analyzing and identifying security risks and vulnerabilities |
Hitrust Security Assessors primarily evaluate organizations' security controls to ensure HITRUST compliance, while Hitrust Risk Analysts focus on identifying and analyzing security risks. Both roles require similar certifications and often work within healthcare and financial sectors, but their core responsibilities differ: assessment versus risk analysis.
What are the key skills and qualifications needed to thrive as a Hitrust Security Assessor, and why are they important?

Full-time
Posted 10 days ago
Job description
GENERAL STATEMENT OF DUTIES
The Chief Information Security Officer (CISO) is the executive leader responsible for all cybersecurity and data protection needs across HOPCo. This leader is tasked with proactively ensuring all systems, networks, methods of storing and moving data, are secured in a manner that is robust and protects member personal health information and all other sensitive or business confidential information and assets. The CISO will protect HOPCo from “bad actors” seeking to undermine the HOPCo business or access protected data. This leader will stay aware of all new threats, to proactively monitor, detect, and mitigate.
This leader will work with HOPCo Compliance to ensure all HOPCo employees understand the role they play in protecting HOPCo assets and data. The CISO is responsible for all security standards, policies, and enforcement across HOPCo. This includes accountability for the security standards enforced with all third parties upon which HOPCo depends. This also includes the security profiles for all clinical sites owned or managed by HOPCo.
This leader plays a critical role in making certain HOPCo is prepared to continue to function in the event of a ransomware attack or natural disaster.
The CISO is also tasked with gaining and maintaining HiTrust certification for HOPCo and ensuring ongoing compliance with regulatory requirements like HIPAA and GDPR.
ESSENTIAL FUNCTIONS
- Develop and execute on a plan to gain and maintain HiTrust certification
- Own ongoing compliance with data protection regulations like HIPAA and GDPR
- Stay aware and current on all government policies related to data protection
- Stay aware of the developing cybersecurity threat landscape using regular NIST alerts (or equivalent) and filter noise from actual threats to the HOPCo ecosystem
- Monitor the HOPCo systems for suspicious activity
- Establish cybersecurity policies and protocols
- Establish data privacy policies and protocols
- Partner with Compliance to maintain and deliver regular cybersecurity and data privacy training to all employees
- Enforce HOPCo cybersecurity and data privacy policies with all third parties
- Initiate and sponsor regular cybersecurity audits, including penetration tests, to identify vulnerabilities
- Assess all audit findings, establishing a prioritized path to mitigation
- Report the state of cybersecurity threats and readiness to the CTO, CEO, and board on a regular basis
- Establish dashboards and metrics to monitor current state and improvement over time
- Select and implement appropriate monitoring tools
- Develop an annual budget and business case tied to security investment needs
- Establish a plan to protect HOPCo against ransomware attacks and to ensure the business can continue uninterrupted in the event of an attack
- Work with other IT and business leaders to establish a robust Disaster Recovery Business Continuity Plan
- Manage prioritization and execution priority on all cybersecurity and data privacy work
- Manage MSSP vendors, including the selection and financial arrangement of using vendors
- Work with the CTO to manage the security-related budget
- Hire, manage, and coach security team members
- Manage security assessments of HOPCo for customers and potential customer audits
- Ensure HOPCo Access Management processes and policies are robust and followed
EDUCATION
- Bachelor’s Degree required (Computer Science preferred); CISSP or equivalent security professional certification.
EXPERIENCE
- 10+ years in various roles leading IT cybersecurity and data privacy teams and processes within healthcare
- Exceptional written and verbal communication skills. Ability to communicate complex technical topics effectively to executive audiences.
- Experience within a HiTrust certified organization and involvement in ongoing adherence
- Experience implementing security programs within complex environments
- Experience directly managing third parties to implement security tools and protocols
- Demonstrated experience as successful influential leader across matrixed teams
- Experience leading, hiring and coaching a team that includes internal and external team members
REQUIREMENTS
- None
KNOWLEDGE
- Expert knowledge and insight into threat vectors, ransomware risks, and data privacy regulations
- Expert knowledge of available monitoring and threat-detection tools
- Familiarity with IAM toolsets including Active Directory and Okta
SKILLS
- Strong negotiation skills for keeping organizational focus on needed investments, while keeping the bigger HOPCo business picture in mind
- Expert knowledge and insight into cybersecurity threat vectors and ransomware risks
- Current and thorough knowledge regarding data privacy and protection regulations (HIPAA, GDPR, etc.)
- Expertise in technical infrastructure, network architecture, and data movement
- Expertise in data storage, cloud technologies, database configuration, data protection techniques
- Expertise in system monitoring and threat detection toolsets and techniques
- Excellent listening, analytical, and communication skills
- Analytical thinking and problem-solving skills, with acute attention to detail, accuracy and accountability balanced with sound business judgment.
- Exceptional interpersonal skills
ABILITIES
- Ability to successfully manage multiple projects simultaneously
- Ability to communicate complex information in a clear and concise manner to managers and executives
- Ability to practice good judgment and discretion
- Ability to act with integrity
- Ability to engage and foster strong partnerships
ENVIRONMENTAL WORKING CONDITIONS
- Normal office environment
- Travel required
PHYSICAL/MENTAL DEMANDS
- Requires sitting and standing associated with a normal office environment.
- Manual dexterity using a calculator and computer keyboard.
ORGANIZATIONAL REQUIREMENTS
- HOPCo Mission, Vision and Values must be read and signed.
This description is intended to provide only basic guidelines for meeting job requirements. Responsibilities, knowledge, skills, abilities and working conditions may change as needs evolve.
About Healthcare Outcomes Performance
Sourced by ZipRecruiter
Industry
Health care and social assistance
Company size
1,001 - 5,000 Employees
Headquarters location
Phoenix, AZ, US
Year founded
1996