1

Hitrust Jobs in Chicago, IL (NOW HIRING)

Facilitate and support HITRUST readiness activities in collaboration with internal stakeholders, enhancing platform trustworthiness and compliance. Qualifications & Requirements: * 8+ years in ...

next page

Showing results 1-20

Hitrust information

What skills and qualifications are needed for a HITRUST position?

To thrive in a HITRUST professional role, you need a robust understanding of information security, healthcare compliance, and risk assessment, typically supported by a relevant degree or certifications such as HITRUST Certified CSF Practitioner (CCSFP). Proficiency with regulatory frameworks like HIPAA, GRC tools, and HITRUST’s MyCSF platform is crucial. Strong attention to detail, analytical thinking, and effective communication are key soft skills for working with cross-functional teams and translating complex requirements. These skills enable professionals to ensure organizational compliance, manage complex security assessments, and foster trust in healthcare data protection programs.

What does a HITRUST professional do?

As a HITRUST professional, you will be responsible for guiding organizations through the HITRUST CSF certification process, conducting comprehensive risk and gap assessments, and creating remediation plans to address compliance issues. Your work will often involve collaborating with IT, compliance, and executive teams to implement policies, improve security controls, and ensure adherence to industry standards like HIPAA and HITECH. You can also expect to manage regular audits, prepare documentation, and educate staff on emerging security requirements. This role plays a key part in maintaining regulatory compliance and safeguarding sensitive patient data.

What is a HITRUST?

A HITRUST job typically involves working with the HITRUST Common Security Framework (CSF) to help organizations achieve and maintain regulatory compliance, data security, and risk management. Professionals in this role may conduct risk assessments, implement security controls, and guide organizations through the HITRUST certification process. Common job titles include HITRUST Consultant, Compliance Analyst, and Security Auditor. These roles require expertise in cybersecurity, regulatory frameworks, and industry best practices.

What are the most commonly searched types of Hitrust jobs in Chicago, IL? The most popular types of Hitrust jobs in Chicago, IL are:
Infographic showing various Hitrust job openings in Chicago, IL as of August 2026, with employment types broken down into 91% Full Time, 4% Part Time, and 5% Contract. Highlights an 59% Physical, 5% Hybrid, and 36% Remote job distribution.

IT Audit, Cybersecurity & Risk Manager (HITRUST)

Bakertilly

Chicago, IL

Full-time

Re-posted 23 days ago


Job description

Overview

Baker Tilly is a leading advisory, tax and assurance firm, providing clients with a genuine coast-to-coast and global advantage in major regions of the U.S. and in many of the world's leading financial centers - New York, London, San Francisco, Los Angeles, Chicago and Boston. Baker Tilly Advisory Group, LP and Baker Tilly US, LLP (Baker Tilly) provide professional services through an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable laws, regulations and professional standards. Baker Tilly US, LLP is a licensed independent CPA firm that provides attest services to its clients. Baker Tilly Advisory Group, LP and its subsidiary entities provide tax and business advisory services to their clients. Baker Tilly Advisory Group, LP and its subsidiary entities are not licensed CPA firms.

Baker Tilly Advisory Group, LP and Baker Tilly US, LLP, trading as Baker Tilly, are independent members of Baker Tilly International, a worldwide network of independent accounting and business advisory firms in 141 territories, with 43,000 professionals and a combined worldwide revenue of $5.2 billion. Visitbakertilly.comor join the conversation onLinkedIn,FacebookandInstagram.

Please discuss the work location status with your Baker Tilly talent acquisition professional to understand the requirements for an opportunity you are exploring.

Baker Tilly is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability or protected veteran status, gender identity, sexual orientation, or any other legally protected basis, in accordance with applicable federal, state or local law.

Any unsolicited resumes submitted through our website or to Baker Tilly Advisory Group, LP, employee e-mail accounts are considered property of Baker Tilly Advisory Group, LP, and are not subject to payment of agency fees. In order to be an authorized recruitment agency ("search firm") for Baker Tilly Advisory Group, LP, there must be a formal written agreement in place and the agency must be invited, by Baker Tilly's Talent Attraction team, to submit candidates for review via our applicant tracking system.

Job Description:
Responsibilities

Are you interested in joining one of the fastest growingconsulting and accounting firms in the country?

Would you like the ability to join a highly dynamic team focusedon providing exceptional client service in the areas of risk and advisory?

If yes, consider joining Baker Tilly (BT) as an IT Audit, Cybersecurity & Risk Manager (HITRUST)! Our Risk Advisory practice provides a full spectrum of services to help our clients assess their risks, develop strategies to compete in an ever-changing business environment, and achieve their goals and objectives. All of this is accomplished through deep industry knowledge of risk, governance, internal audit, compliance, IT, and cybersecurity best practices.

As one of the fastest growing firms in the nation, BT has the ability to offer you upward career trajectory, flexibility in how and where you get your work done and meaningful relationships with clients, teammates and leadership who truly care about you and your development.

Does this describe you?

  • You want to continue to expand your work experiences and hone your skills as a comprehensive risk professional in the areas of compliance, enterprise risk management, governance, internal controls, and data analytics

  • You crave the opportunity to be part of a fast growing, entrepreneurial risk consulting practice where your hard work and creativity will be rewarded

  • You do your best work when you are part of a talented, down-to-earth team that thrives in collaboration and truly enjoys working together

  • You feel valued when you are provided the resources and support to continually sharpen your technical skills and build your career now, for tomorrow

What you will do:

  • Work closely with client executives and management teams to understand their businesses and assist in identifying and managing financial and operational risks within their business processes and systems

    • Develop in-depth knowledge of clients' businesses and industries by having direct client interaction while working on multiple aspects of an engagement

    • Think independently and strategically about your clients' business, systems and risks providing recommendations for business and processimprovements based upon knowledge gained relative to the client'soperations, processes and business objectives

    • Provide strategic business advice to clients by assisting in the implementation of new processes and controls that address key risks

    • Assess, manage and optimize information technology risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT regulatory and compliance requirements, and business continuity and disaster recovery.

    • Review clients' processes and controls against industry frameworks, identifying gaps in design and execution, and communicating issues and recommendations to clients

    • Draft comprehensive executive summaries and final reports for delivery to the client, documenting and reviewing engagement work papers in accordance with industry-accepted internal audit methodologies

    • Act as a valued business advisor, build relationships and communicateeffectively with the client to provide superior client service

    • Facilitate professional and effective presentations to internal and external audiences

    • Continue to develop your knowledge and experience working with a variety of technology environments, platforms, applications and tools/utilities

  • Assist with managing client engagement staffing, billings/collections, and ensure client profitability targets are met

  • Utilize your entrepreneurial skills to network and build strong relationships internally and externally with clients and the community

  • Invest in your professional development individually and through participation in firm wide learning and development programs

  • Support the growth and development of team members through the Baker Tilly Care and Teach philosophy, helping associates meet their professional goals

  • Enjoy friendships, social activities and team outings that encourage a work-life balance

Qualifications
  • Bachelor's degree in accounting, finance, or a related program

  • CPA, CISA, CCSFP or CISSP designation(s) required

  • 5+ year(s) experience with risk advisory, internal/external audit, business process reengineering, and/or internal controls with focus on IT related subject matter (e.g., SOC 1/2 Exams, HITRUST, HIPAA, NIST CSF, NIST 800-53)

  • Experience performing HITRUST engagements preferred.Open to candidates willing to obtain HITRUST Certification in the future

  • Experience with Security+ is preferred

  • Experience with Cloud audit experience and certifications is preferred

  • Experience as a client serving professional for a consulting firm desired

  • Excellent analytical, technical, and problem-solving skills, with strong attention to detail

  • Exceptional verbal and written communication, collaboration, and time management skills

The compensation range for this role is $123,840 to $234,770. Actual compensation is influenced by a variety of factors including but not limited to skills, experience, qualifications, and geographic location.