1

Hitrust Jobs in Houston, TX (NOW HIRING)

Familiarity with compliance benchmarks such as CIS level 1 & 2, PCI, HIPAA, HITRUST, NERC, CIP, NIST, etc. * Must possess strong presentation skills and be able to communicate professionally in ...

Risk Advisory Associate | 2027 | IT

Houston, TX · On-site

$77K - $95K/yr

Strong knowledge of security risk management frameworks including related regulatory compliance requirements (NIST CSF & 800-53, ISO27001, SOC, HITRUST, HIPAA, FedRamp, PCI, GDPR, etc.) * Experience ...

DevOps Engineer

Houston, TX · On-site

$50.25 - $69/hr

Maintain configurations and documentation needed to support audits and compliance frameworks (e.g., HIPAA, and SOC 2 / HITRUST as we mature). * Manage backups, retention policies, encryption keys ...

Execute compliance assessments, gap analyses, remediation planning, and evidence collection across frameworks such as PCI DSS, SOC 1, SOC 2, ISO 27001, ISO 27701, HITRUST, CMMC, FedRAMP, NIST CSF ...

DevOps Engineer

Houston, TX · Hybrid

$50.25 - $69/hr

Maintain configurations and documentation needed to support audits and compliance frameworks (e.g., HIPAA, and SOC 2 / HITRUST as we mature). * Manage backups, retention policies, encryption keys ...

next page

Showing results 1-20

Hitrust information

See Houston, TX salary details

$69.3K

$118.6K

$175.9K

How much do hitrust jobs pay per year?

As of Jul 27, 2026, the average yearly pay for hitrust in Houston, TX is $118,625.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,498.00 and $141,989.00 per year, depending on experience, location, and employer.

Is cybersecurity a dying field?

Cybersecurity professionals, including those working with HITRUST compliance, are in high demand due to increasing cyber threats and data protection regulations. The field is expected to grow steadily as organizations prioritize security, requiring skills in risk management, threat detection, and security frameworks. Continuous learning and certifications like CISSP or CISA enhance job prospects in this evolving industry.

What are the key skills and qualifications needed to thrive in the Hitrust position, and why are they important?

To thrive in a HITRUST professional role, you need a robust understanding of information security, healthcare compliance, and risk assessment, typically supported by a relevant degree or certifications such as HITRUST Certified CSF Practitioner (CCSFP). Proficiency with regulatory frameworks like HIPAA, GRC tools, and HITRUST’s MyCSF platform is crucial. Strong attention to detail, analytical thinking, and effective communication are key soft skills for working with cross-functional teams and translating complex requirements. These skills enable professionals to ensure organizational compliance, manage complex security assessments, and foster trust in healthcare data protection programs.

What jobs in the US pay $300,000 a year?

High-paying jobs that can reach or exceed $300,000 annually include roles such as senior cybersecurity professionals, chief information security officers, and IT directors, especially in large organizations. These positions often require extensive experience, advanced certifications like CISSP or CISM, and leadership responsibilities within cybersecurity or technology departments.

What typical responsibilities can I expect as a HITRUST professional in a healthcare organization?

As a HITRUST professional, you will be responsible for guiding organizations through the HITRUST CSF certification process, conducting comprehensive risk and gap assessments, and creating remediation plans to address compliance issues. Your work will often involve collaborating with IT, compliance, and executive teams to implement policies, improve security controls, and ensure adherence to industry standards like HIPAA and HITECH. You can also expect to manage regular audits, prepare documentation, and educate staff on emerging security requirements. This role plays a key part in maintaining regulatory compliance and safeguarding sensitive patient data.

What is a HITRUST job?

A HITRUST job typically involves working with the HITRUST Common Security Framework (CSF) to help organizations achieve and maintain regulatory compliance, data security, and risk management. Professionals in this role may conduct risk assessments, implement security controls, and guide organizations through the HITRUST certification process. Common job titles include HITRUST Consultant, Compliance Analyst, and Security Auditor. These roles require expertise in cybersecurity, regulatory frameworks, and industry best practices.

How much do HITRUST analysts make?

HITRUST analysts typically earn between $70,000 and $110,000 annually, depending on experience, certifications, and location. They often work with compliance frameworks, security assessments, and risk management tools in healthcare or cybersecurity environments.
What are the most commonly searched types of Hitrust jobs in Houston, TX? The most popular types of Hitrust jobs in Houston, TX are:
What are popular job titles related to Hitrust jobs in Houston, TX? For Hitrust jobs in Houston, TX, the most frequently searched job titles are:
What cities near Houston, TX are hiring for Hitrust jobs? Cities near Houston, TX with the most Hitrust job openings:
Infographic showing various Hitrust job openings in Houston, TX as of July 2026, with employment types broken down into 92% Full Time, 6% Part Time, and 2% Contract. Highlights an 62% Physical, 8% Hybrid, and 30% Remote job distribution, with an average salary of $118,625 per year, or $57 per hour.
Principal Cybersecurity Analyst - Risk Mgmt & AI Security

Principal Cybersecurity Analyst - Risk Mgmt & AI Security

MD Anderson

Houston, TX • On-site, Remote

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 18 days ago


MD Anderson Cancer Center rating

8.4

Company rating: 8.4 out of 10

Based on 169 frontline employees who took The Breakroom Quiz

27th of 890 rated healthcare providers


Job description

The University of Texas MD Anderson Cancer Center is seeking a highly skilled Principal Cybersecurity Analyst to serve as a technical authority within its Cybersecurity department. The Principal Cybersecurity Analyst plays a critical role in shaping and advancing enterprise-wide governance, risk, and compliance (GRC) programs, with expanded accountability for emerging AI security and governance initiatives. This role operates at a strategic and architectural level while also ensuring operational effectiveness across cybersecurity risk management practices.

The Principal Cybersecurity Analyst contributes directly to safeguarding sensitive data, maintaining regulatory compliance, and strengthening the organization's security posture through innovative, data-driven risk management and governance strategies. The Principal Cybersecurity Analyst serves as a trusted advisor, architect, and leader within the cybersecurity function. The ideal candidate brings advanced education in information systems or cybersecurity, extensive experience leading enterprise risk management or GRC programs, and strong knowledge of frameworks such as NIST, HIPAA, and HITRUST.

Preferred candidates will also have hands-on experience assessing AI/ML risk, strong executive communication skills, and certifications such as CISSP, CISM, or PMP. Minimum $123,000 - Midpoint $154,000 - Maximum $185,000 Work Location: Remote 100% Why Us. At UT MD Anderson, the Principal Cybersecurity Analyst plays an essential role in advancing cybersecurity innovation in a mission-driven healthcare environment.

This position offers the opportunity to shape enterprise risk strategy, influence executive decision-making, and lead emerging AI governance practices, all while supporting an organization dedicated to saving lives. Employees benefit from a collaborative culture, professional development opportunities, and a strong commitment to work-life balance. Employer-paid medical coverage starting day one for employees working 30+ hours/week, plus optional group dental, vision, life, AD&D, and disability insurance.

Accruals for PTO and Extended Illness Bank, plus paid holidays, wellness, childcare, and other leave options. Tuition Assistance Program after six months of service and access to extensive wellness, fitness, and employee resource groups. Defined-benefit pension through the Teachers Retirement System, voluntary retirement plans, and employer-paid life and reduced salary protection programs.

Responsibilities Governance, Risk & Compliance (GRC) Architecture & Risk Management Program Leadership Serve as principal architect and subject matter expert for enterprise GRC and cybersecurity risk programs Define and maintain risk assessment methodologies, control frameworks, and risk scoring models Establish workflows across development, staging, and production environments Develop SOPs, roles, segregation of duties, and change management processes Lead design and execution of enterprise risk management strategies Security & Risk Platform Integration and Automation Architect and maintain integrations across Archer, Tenable, ServiceNow, Microsoft Configuration Manager (SCCM/MECM), and Medigate Design automated workflows consolidating asset, vulnerability, and risk data Enable enterprise-wide risk visibility and reporting through data-driven systems Ensure data quality, reconciliation, and interoperability across platforms and CMDB Regulatory & Compliance Framework Management Apply frameworks including NIST CSF, NIST 800-53, HIPAA, and HITRUST Conduct control mapping, gap assessments, and compliance reporting Advise stakeholders on remediation strategies and regulatory requirements Align institutional policies with regulatory and accreditation standards AI Security & Governance Establish and mature AI security and governance programs Develop AI risk assessment criteria and governance standards Align controls to NIST AI Risk Management Framework and institutional policies Evaluate AI/ML tools and vendors for data protection and compliance risks Partner with data governance, privacy, and legal teams on AI initiatives Strategic Risk Visioning, Assessment & Executive Advisory Develop multi-year roadmaps, milestones, and resource plans Lead enterprise and project-level risk assessments Translate technical findings into executive-level reporting and dashboards Advise leadership on risk posture and investment prioritization Provide technical leadership and mentorship across teams EDUCATION Required: Bachelor's Degree Computer Information Systems, Business Information Systems, Computer Science or related field. Preferred: Master's Degree Information Security, Computer Science or related field WORK EXPERIENCE Required: 7 years In information security and/or cybersecurity experience including multiple security domains, to include two years lead/supervisory experience. May substitute required education degree with additional years of equivalent experience on a one to one basis.

Preferred: At least 7-8 years of progressive cybersecurity experience, hands-on risk management (risk assessment, risk register ownership, control evaluation, or risk quantification), led or owned a security risk management program or framework implementation (e.g., NIST RMF/CSF, ISO 27005, FAIR, or equivalent), direct hands-on experience assessing the security or risk posture of AI/ML systems or GenAI deployments, ability to translate technical risk into business-level language for executive and governance audiences (e.g., briefing a CISO, risk committee, or board), experience using Archer, excellent communication skills, risk management, and cybersecurity framework is a must. LICENSES AND CERTIFICATIONS Preferred: CISSP - Cert IS Security Professional Issued by the International Information Systems Security Certification Consortium ((ISC). Preferred: CISM - Cert Info Security Manager Issued by Information Systems Audit and Control Association (ISACA)

Preferred: PMP - Project Mgt Professional Issued by the Project Management Institute (PMI). Preferred: Other applicable security industry certifications. The University of Texas MD Anderson Cancer Center offers excellent benefits, including medical, dental, paid time off, retirement, tuition benefits, educational opportunities, and individual and team recognition.

This position may be responsible for maintaining the security and integrity of critical infrastructure, as defined in Section 113.001(2) of the Texas Business and Commerce Code and therefore may require routine reviews and screening. The ability to satisfy and maintain all requirements necessary to ensure the continued security and integrity of such infrastructure is a condition of hire and continued employment. It is the policy of The University of Texas MD Anderson Cancer Center to provide equal employment opportunity without regard to race, color, religion, age, national origin, sex, gender, sexual orientation, gender identity/expression, disability, protected veteran status, genetic information, or any other basis protected by institutional policy or by federal, state, or local laws unless such distinction is required by law.http://www.mdanderson.org/about-us/legal-and-policy/legal-statements/eeo-affirmative-action.html Additional Information Requisition ID: 181706 Employment Status: Full-Time Employee Status: Regular Work Week: Days Minimum Salary: US Dollar (USD) 123,000 Midpoint Salary: US Dollar (USD) 154,000 Maximum Salary : US Dollar (USD) 185,000 FLSA: exempt and not eligible for overtime pay Fund Type: Hard Work Location: Remote (within Texas only) Pivotal Position: Yes Referral Bonus Available?: Yes Relocation Assistance Available?: Yes #LI-Remote Apply


What MD Anderson Cancer Center employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom