HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
Lead IT Security Analyst - HIPAA, HITRUST, FISMA
$121K - $210K/yr
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
Lead IT Security Analyst - HIPAA, HITRUST, FISMA
$121K - $210K/yr
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments Research ...
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments Research ...
Lead IT Security Analyst - HIPAA, HITRUST, FISMA
$121K - $210K/yr
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments Research ...
Lead IT Security Analyst - HIPAA, HITRUST, FISMA
$121K - $210K/yr
HITRUST * PCI * NIST Cybersecurity Framework * ISO/IEC 27001 * Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments Research ...
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3 * Knowledge of NIST Risk Assessment methodology * Familiarity with secure SDLC best ...
Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL 3 * Knowledge of NIST Risk Assessment methodology * Familiarity with secure SDLC best ...
Data Engineer
Manhattan, NY · Remote
$105K - $115K/yr
Ensure all data structures and processes adhere to HITRUST/HIPAA standards, collaborating with IT and the leads for technical efforts for HITRUST certification readiness. Required Skills & Experience
Quick apply
Data Engineer
Manhattan, NY · Remote
$105K - $115K/yr
Ensure all data structures and processes adhere to HITRUST/HIPAA standards, collaborating with IT and the leads for technical efforts for HITRUST certification readiness. Required Skills & Experience
If yes, consider joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Manager (HITRUST) ! Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ...
If yes, consider joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Manager (HITRUST) ! Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ...
This role will ensure timely identification, prioritization, and remediation of Critical and High vulnerabilities aligned to regulatory and compliance requirements (HIPAA, HITECH, CMS, HITRUST). The ...
Quick apply
This role will ensure timely identification, prioritization, and remediation of Critical and High vulnerabilities aligned to regulatory and compliance requirements (HIPAA, HITECH, CMS, HITRUST). The ...
Sr. Product Manager, Healthcare Platform
$138K - $182K/yr
Facilitate and support HITRUST readiness activities in collaboration with internal stakeholders, enhancing platform trustworthiness and compliance. Qualifications & Requirements: * 8+ years in ...
Sr. Product Manager, Healthcare Platform
$138K - $182K/yr
Facilitate and support HITRUST readiness activities in collaboration with internal stakeholders, enhancing platform trustworthiness and compliance. Qualifications & Requirements: * 8+ years in ...
Strong expertise with ISO 27001 and HiTrust certification requirements. * Demonstrated capability in conducting risk assessments, vulnerability scanning, and business continuity/disaster recovery ...
Strong expertise with ISO 27001 and HiTrust certification requirements. * Demonstrated capability in conducting risk assessments, vulnerability scanning, and business continuity/disaster recovery ...
SKILLS Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL3. Identity Access Management Platforms: Systems integration or software ...
SKILLS Knowledge of HITRUST CSF, NIST 800-83 cyber security framework, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, and ITIL3. Identity Access Management Platforms: Systems integration or software ...
Experience managing an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework * Experience supporting SSAE 16 or SOC 2 ...
Experience managing an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework * Experience supporting SSAE 16 or SOC 2 ...
Senior Cloud Security Engineer
Parsippany Troy Hills, NJ · On-site
$140 - $190/hr
Design and implement security controls supporting HIPAA, HITRUST, PCI DSS, SOC 2, NIST CSF, and NIST AI RMF requirements * Support technical readiness, evidence collection, and remediation activities ...
New
Senior Cloud Security Engineer
Parsippany Troy Hills, NJ · On-site
$140 - $190/hr
Design and implement security controls supporting HIPAA, HITRUST, PCI DSS, SOC 2, NIST CSF, and NIST AI RMF requirements * Support technical readiness, evidence collection, and remediation activities ...
New
Senior Cloud Security Engineer
Parsippany, NJ · On-site
$115K - $157K/yr
Design and implement security controls supporting HIPAA, HITRUST, PCI DSS, SOC 2, NIST CSF, and NIST AI RMF requirements * Support technical readiness, evidence collection, and remediation activities ...
Senior Cloud Security Engineer
Parsippany, NJ · On-site
$115K - $157K/yr
Design and implement security controls supporting HIPAA, HITRUST, PCI DSS, SOC 2, NIST CSF, and NIST AI RMF requirements * Support technical readiness, evidence collection, and remediation activities ...
Security Operations Lead
Manhattan, NY · On-site
You will own our SOC 2, HIPAA, and HITRUST compliance programs end-to-end, building a customer trust function that turns enterprise security diligence into a repeatable, high-quality motion. As Forus ...
Security Operations Lead
Manhattan, NY · On-site
You will own our SOC 2, HIPAA, and HITRUST compliance programs end-to-end, building a customer trust function that turns enterprise security diligence into a repeatable, high-quality motion. As Forus ...
Security Operations Lead
Manhattan, NY · On-site
You will own our compliance programs end to end - SOC 2, HIPAA, and HITRUST - and build the customer trust function that ensures security remains a core competency at Forus. You will run vendor and ...
Security Operations Lead
Manhattan, NY · On-site
You will own our compliance programs end to end - SOC 2, HIPAA, and HITRUST - and build the customer trust function that ensures security remains a core competency at Forus. You will run vendor and ...
Director of Security & Compliance
New York, NY · On-site
$220K - $270K/yr
This is a high-impact role where you'll define our security architecture, lead our HITRUST certification effort as technical owner, and protect the patient data at the heart of our platform. You'll ...
Director of Security & Compliance
New York, NY · On-site
$220K - $270K/yr
This is a high-impact role where you'll define our security architecture, lead our HITRUST certification effort as technical owner, and protect the patient data at the heart of our platform. You'll ...
Security Operations Lead
New York, NY · On-site
You will own our SOC 2, HIPAA, and HITRUST compliance programs end-to-end, building a customer trust function that turns enterprise security diligence into a repeatable, high-quality motion. As Forus ...
Security Operations Lead
New York, NY · On-site
You will own our SOC 2, HIPAA, and HITRUST compliance programs end-to-end, building a customer trust function that turns enterprise security diligence into a repeatable, high-quality motion. As Forus ...
HITRUST, PCI, NIST, HIPAA, SOC2 • Experience across multiple platforms: Windows, Linux/Unix, macOS; networks and endpoints • Experience with vulnerability assessments and penetration testing ...
HITRUST, PCI, NIST, HIPAA, SOC2 • Experience across multiple platforms: Windows, Linux/Unix, macOS; networks and endpoints • Experience with vulnerability assessments and penetration testing ...
Experience with healthcare compliance standards like HIPPA and HITRUST * Knowledge of container security and Kubernetes * Experience with CI/CD security integration * Understanding of compliance ...
Quick apply
Experience with healthcare compliance standards like HIPPA and HITRUST * Knowledge of container security and Kubernetes * Experience with CI/CD security integration * Understanding of compliance ...
Hitrust information
See New York salary details
$78.2K - $89.1K
9% of jobs
$89.1K - $100K
13% of jobs
$105.5K is the 25th percentile. Wages below this are outliers.
$100K - $111K
7% of jobs
$111K - $121.9K
9% of jobs
The median wage is $128.5K / yr.
$121.9K - $132.8K
21% of jobs
$132.8K - $143.8K
12% of jobs
$152K is the 75th percentile. Wages above this are outliers.
$143.8K - $154.7K
6% of jobs
$154.7K - $165.6K
7% of jobs
$165.6K - $176.6K
10% of jobs
$176.6K - $187.5K
4% of jobs
$187.5K - $198.4K
2% of jobs
$78.2K
$133.8K
$198.4K
How much do hitrust jobs pay per year?
What skills and qualifications are needed for a HITRUST position?
To thrive in a HITRUST professional role, you need a robust understanding of information security, healthcare compliance, and risk assessment, typically supported by a relevant degree or certifications such as HITRUST Certified CSF Practitioner (CCSFP). Proficiency with regulatory frameworks like HIPAA, GRC tools, and HITRUST’s MyCSF platform is crucial. Strong attention to detail, analytical thinking, and effective communication are key soft skills for working with cross-functional teams and translating complex requirements. These skills enable professionals to ensure organizational compliance, manage complex security assessments, and foster trust in healthcare data protection programs.
What does a HITRUST professional do?
As a HITRUST professional, you will be responsible for guiding organizations through the HITRUST CSF certification process, conducting comprehensive risk and gap assessments, and creating remediation plans to address compliance issues. Your work will often involve collaborating with IT, compliance, and executive teams to implement policies, improve security controls, and ensure adherence to industry standards like HIPAA and HITECH. You can also expect to manage regular audits, prepare documentation, and educate staff on emerging security requirements. This role plays a key part in maintaining regulatory compliance and safeguarding sensitive patient data.
What is a HITRUST?
A HITRUST job typically involves working with the HITRUST Common Security Framework (CSF) to help organizations achieve and maintain regulatory compliance, data security, and risk management. Professionals in this role may conduct risk assessments, implement security controls, and guide organizations through the HITRUST certification process. Common job titles include HITRUST Consultant, Compliance Analyst, and Security Auditor. These roles require expertise in cybersecurity, regulatory frameworks, and industry best practices.

Full-time
Re-posted 10 days ago
NYU Langone Health rating
8.5
Based on 247 frontline employees who took The Breakroom Quiz
13th of 887 rated healthcare providers
Job description
NYU Langone Health is a fully integrated health system that consistently achieves the best patient outcomes through a rigorous focus on quality that has resulted in some of the lowest mortality rates in the nation. Vizient Inc. has ranked NYU Langone the No. 1 comprehensive academic medical center in the country for three years in a row, and U.S. News & World Report recently placed nine of its clinical specialties among the top five in the nation. NYU Langone offers a comprehensive range of medical services with one high standard of care across 6 inpatient locations, its Perlmutter Cancer Center, and over 320 outpatient locations in the New York area and Florida. With $14.2 billion in revenue this year, the system also includes two tuition-free medical schools, in Manhattan and on Long Island, and a vast research enterprise with over $1 billion in active awards from the National Institutes of Health.
For more information, go to NYU Langone Health, and interact with us on LinkedIn, Glassdoor, Indeed, Facebook, Twitter, YouTube and Instagram.
Position Summary:
We have an exciting opportunity to join our team as a Lead IT Security Analyst.
This position reports to the IT Controls & Regulatory Compliance Manager and serves as a senior individual contributor and subject matter expert responsible for leading enterprise risk assessments and evaluating the security of modern technology environments, including cloud-based platforms.
The IT Controls Lead drives the design, execution, and continuous improvement of the organizations risk assessment program to ensure compliance with regulatory and industry requirements, including HIPAA, HITRUST, PCI DSS, and FISMA.
This role partners closely with IT, Security, Clinical, Research, and Compliance stakeholders to assess risk across enterprise systems, research technologies, and cloud infrastructure, and to ensure that security controls are appropriately designed and operating effectively.
Job Responsibilities:
Enterprise Risk Assessment Leadership
- Lead the execution and maturation of the enterprise risk assessment program aligned to regulatory and industry frameworks
- Conduct and oversee complex risk assessments, including HIPAA and HITRUST-aligned evaluations
- Define and maintain risk assessment methodologies, scoring models, and standards
- Identify, analyze, and document risks, and develop actionable remediation strategies
Cloud Security & Technology Risk Evaluation
- Lead security assessments of cloud and hybrid environments (e.g., IaaS, PaaS, SaaS)
- Evaluate key control domains, including:
- Identity and access management
- Network architecture and segmentation
- Logging, monitoring, and detection capabilities
- Data protection and encryption
- Assess alignment to frameworks such as:
- HITRUST
- PCI
- NIST Cybersecurity Framework
- ISO/IEC 27001
- Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments
What NYU Langone Health employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About NYU Langone Health
Sourced by ZipRecruiter
Industry
Hospitals
Company size
501 - 1,000 Employees
Headquarters location
New York, NY, US
Year founded
1841