HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
Lead IT Security Analyst - HIPAA, HITRUST, FISMA
$121K - $210K/yr
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
Lead IT Security Analyst - HIPAA, HITRUST, FISMA
$121K - $210K/yr
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments Research ...
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments Research ...
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3 * Knowledge of NIST Risk Assessment methodology * Familiarity with secure SDLC best ...
New
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3 * Knowledge of NIST Risk Assessment methodology * Familiarity with secure SDLC best ...
New
Data Engineer
Manhattan, NY · Remote
$105K - $115K/yr
Ensure all data structures and processes adhere to HITRUST/HIPAA standards, collaborating with IT and the leads for technical efforts for HITRUST certification readiness. Required Skills & Experience
Quick apply
Data Engineer
Manhattan, NY · Remote
$105K - $115K/yr
Ensure all data structures and processes adhere to HITRUST/HIPAA standards, collaborating with IT and the leads for technical efforts for HITRUST certification readiness. Required Skills & Experience
If yes, consider joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Manager (HITRUST) ! Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ...
If yes, consider joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Manager (HITRUST) ! Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ...
If yes, consider joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Manager (HITRUST) ! Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ...
If yes, consider joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Manager (HITRUST) ! Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ...
This role will ensure timely identification, prioritization, and remediation of Critical and High vulnerabilities aligned to regulatory and compliance requirements (HIPAA, HITECH, CMS, HITRUST). The ...
Quick apply
This role will ensure timely identification, prioritization, and remediation of Critical and High vulnerabilities aligned to regulatory and compliance requirements (HIPAA, HITECH, CMS, HITRUST). The ...
Sr. Product Manager, Healthcare Platform
$138K - $182K/yr
Facilitate and support HITRUST readiness activities in collaboration with internal stakeholders, enhancing platform trustworthiness and compliance. Qualifications & Requirements: * 8+ years in ...
Sr. Product Manager, Healthcare Platform
$138K - $182K/yr
Facilitate and support HITRUST readiness activities in collaboration with internal stakeholders, enhancing platform trustworthiness and compliance. Qualifications & Requirements: * 8+ years in ...
Experience managing an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework * Experience supporting SSAE 16 or SOC 2 ...
New
Experience managing an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework * Experience supporting SSAE 16 or SOC 2 ...
New
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3 * Familiarity with secure SDLC best practices * Knowledge of Microsoft Apps and ...
New
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3 * Familiarity with secure SDLC best practices * Knowledge of Microsoft Apps and ...
New
Security Engineer
Westbury, NY · On-site
E WannaCry) Participate in internal and external audits (HiTrust) Maintain or create policies, procedures, and other documentation when necessary Find security gaps within the infrastructure ...
Security Engineer
Westbury, NY · On-site
E WannaCry) Participate in internal and external audits (HiTrust) Maintain or create policies, procedures, and other documentation when necessary Find security gaps within the infrastructure ...
Director of Security & Compliance
New York, NY · Remote
$220K - $270K/yr
This is a high-impact role where you'll define our security architecture, lead our HITRUST certification effort as technical owner, and protect the patient data at the heart of our platform. You'll ...
Quick apply
Director of Security & Compliance
New York, NY · Remote
$220K - $270K/yr
This is a high-impact role where you'll define our security architecture, lead our HITRUST certification effort as technical owner, and protect the patient data at the heart of our platform. You'll ...
Director of Security & Compliance
New York, NY · On-site
$220K - $270K/yr
This is a high-impact role where you'll define our security architecture, lead our HITRUST certification effort as technical owner, and protect the patient data at the heart of our platform. You'll ...
Director of Security & Compliance
New York, NY · On-site
$220K - $270K/yr
This is a high-impact role where you'll define our security architecture, lead our HITRUST certification effort as technical owner, and protect the patient data at the heart of our platform. You'll ...
Security Operations Lead
New York, NY · On-site
You will own our compliance programs end to end - SOC 2, HIPAA, and HITRUST - and build the customer trust function that ensures security remains a core competency at Forus. You will run vendor and ...
Security Operations Lead
New York, NY · On-site
You will own our compliance programs end to end - SOC 2, HIPAA, and HITRUST - and build the customer trust function that ensures security remains a core competency at Forus. You will run vendor and ...
HITRUST, PCI, NIST, HIPAA, SOC2 • Experience across multiple platforms: Windows, Linux/Unix, macOS; networks and endpoints • Experience with vulnerability assessments and penetration testing ...
HITRUST, PCI, NIST, HIPAA, SOC2 • Experience across multiple platforms: Windows, Linux/Unix, macOS; networks and endpoints • Experience with vulnerability assessments and penetration testing ...
Director of Technology
New York, NY · On-site
$175K - $225K/yr
HIPAA compliance including SOC2 Type 2 readiness/certifications and any HITRUST initiatives. * Security governance including policy development and enforcement * Vendor risk management. * Audit ...
Quick apply
Director of Technology
New York, NY · On-site
$175K - $225K/yr
HIPAA compliance including SOC2 Type 2 readiness/certifications and any HITRUST initiatives. * Security governance including policy development and enforcement * Vendor risk management. * Audit ...
Experience with healthcare compliance standards like HIPPA and HITRUST * Knowledge of container security and Kubernetes * Experience with CI/CD security integration * Understanding of compliance ...
Quick apply
Experience with healthcare compliance standards like HIPPA and HITRUST * Knowledge of container security and Kubernetes * Experience with CI/CD security integration * Understanding of compliance ...
Own forecasting accuracy and pipeline hygiene. • Partner with the customer to define cloud governance, security, and compliance frameworks aligned to HIPAA, HITRUST, and state regulatory ...
Own forecasting accuracy and pipeline hygiene. • Partner with the customer to define cloud governance, security, and compliance frameworks aligned to HIPAA, HITRUST, and state regulatory ...
Senior Cyber Incident Responder
$109K - $141K/yr
... HITRUST CSF), or the NIST 800-83 cyber security framework Preferred * Masters in computer science, cybersecurity, information technology, software engineering, information systems, computer ...
Senior Cyber Incident Responder
$109K - $141K/yr
... HITRUST CSF), or the NIST 800-83 cyber security framework Preferred * Masters in computer science, cybersecurity, information technology, software engineering, information systems, computer ...
Hitrust information
See New York salary details
$78.2K - $89.1K
9% of jobs
$89.1K - $100K
13% of jobs
$105.5K is the 25th percentile. Wages below this are outliers.
$100K - $111K
7% of jobs
$111K - $121.9K
9% of jobs
The median wage is $128.5K / yr.
$121.9K - $132.8K
21% of jobs
$132.8K - $143.8K
12% of jobs
$152K is the 75th percentile. Wages above this are outliers.
$143.8K - $154.7K
6% of jobs
$154.7K - $165.6K
7% of jobs
$165.6K - $176.6K
10% of jobs
$176.6K - $187.5K
4% of jobs
$187.5K - $198.4K
2% of jobs
$78.2K
$133.8K
$198.4K
How much do hitrust jobs pay per year?
Is cybersecurity a dying field?
What are the key skills and qualifications needed to thrive in the Hitrust position, and why are they important?
To thrive in a HITRUST professional role, you need a robust understanding of information security, healthcare compliance, and risk assessment, typically supported by a relevant degree or certifications such as HITRUST Certified CSF Practitioner (CCSFP). Proficiency with regulatory frameworks like HIPAA, GRC tools, and HITRUST’s MyCSF platform is crucial. Strong attention to detail, analytical thinking, and effective communication are key soft skills for working with cross-functional teams and translating complex requirements. These skills enable professionals to ensure organizational compliance, manage complex security assessments, and foster trust in healthcare data protection programs.
What jobs in the US pay $300,000 a year?
What typical responsibilities can I expect as a HITRUST professional in a healthcare organization?
As a HITRUST professional, you will be responsible for guiding organizations through the HITRUST CSF certification process, conducting comprehensive risk and gap assessments, and creating remediation plans to address compliance issues. Your work will often involve collaborating with IT, compliance, and executive teams to implement policies, improve security controls, and ensure adherence to industry standards like HIPAA and HITECH. You can also expect to manage regular audits, prepare documentation, and educate staff on emerging security requirements. This role plays a key part in maintaining regulatory compliance and safeguarding sensitive patient data.
What is a HITRUST job?
A HITRUST job typically involves working with the HITRUST Common Security Framework (CSF) to help organizations achieve and maintain regulatory compliance, data security, and risk management. Professionals in this role may conduct risk assessments, implement security controls, and guide organizations through the HITRUST certification process. Common job titles include HITRUST Consultant, Compliance Analyst, and Security Auditor. These roles require expertise in cybersecurity, regulatory frameworks, and industry best practices.
How much do HITRUST analysts make?

Full-time
Posted 24 days ago
NYU Langone Health rating
8.5
Based on 247 frontline employees who took The Breakroom Quiz
16th of 890 rated healthcare providers
Job description
NYU Langone Health is a fully integrated health system that consistently achieves the best patient outcomes through a rigorous focus on quality that has resulted in some of the lowest mortality rates in the nation. Vizient Inc. has ranked NYU Langone the No. 1 comprehensive academic medical center in the country for three years in a row, and U.S. News & World Report recently placed nine of its clinical specialties among the top five in the nation. NYU Langone offers a comprehensive range of medical services with one high standard of care across 6 inpatient locations, its Perlmutter Cancer Center, and over 320 outpatient locations in the New York area and Florida. With $14.2 billion in revenue this year, the system also includes two tuition-free medical schools, in Manhattan and on Long Island, and a vast research enterprise with over $1 billion in active awards from the National Institutes of Health.
For more information, go to NYU Langone Health, and interact with us on LinkedIn, Glassdoor, Indeed, Facebook, Twitter, YouTube and Instagram.
Position Summary:
We have an exciting opportunity to join our team as a Lead IT Security Analyst.
This position reports to the IT Controls & Regulatory Compliance Manager and serves as a senior individual contributor and subject matter expert responsible for leading enterprise risk assessments and evaluating the security of modern technology environments, including cloud-based platforms.
The IT Controls Lead drives the design, execution, and continuous improvement of the organizations risk assessment program to ensure compliance with regulatory and industry requirements, including HIPAA, HITRUST, PCI DSS, and FISMA.
This role partners closely with IT, Security, Clinical, Research, and Compliance stakeholders to assess risk across enterprise systems, research technologies, and cloud infrastructure, and to ensure that security controls are appropriately designed and operating effectively.
Job Responsibilities:
Enterprise Risk Assessment Leadership
- Lead the execution and maturation of the enterprise risk assessment program aligned to regulatory and industry frameworks
- Conduct and oversee complex risk assessments, including HIPAA and HITRUST-aligned evaluations
- Define and maintain risk assessment methodologies, scoring models, and standards
- Identify, analyze, and document risks, and develop actionable remediation strategies
Cloud Security & Technology Risk Evaluation
- Lead security assessments of cloud and hybrid environments (e.g., IaaS, PaaS, SaaS)
- Evaluate key control domains, including:
- Identity and access management
- Network architecture and segmentation
- Logging, monitoring, and detection capabilities
- Data protection and encryption
- Assess alignment to frameworks such as:
- HITRUST
- PCI
- NIST Cybersecurity Framework
- ISO/IEC 27001
- Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
What NYU Langone Health employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About NYU Langone Health
Sourced by ZipRecruiter
Industry
Hospitals
Company size
501 - 1,000 Employees
Headquarters location
New York, NY, US
Year founded
1841