1

Hitrust Jobs (NOW HIRING)

You will ensure reliability, scalability, and compliance of critical systems in alignment with FDA GxP guidelines and HITRUST standards for healthcare data protection. You will lead initiatives in ...

Lead and maintain the company's HiTrust certification program, including gap assessments, remediation tracking, and audit coordination. * Own and manage the SOC 2 compliance program, including ...

Maintain and continuously improve SOC2/HITRUST CSF certification; ensure security control ownership, evidence collection, and audit readiness are operationalized across all responsible domains

Data Engineer

Manhattan, NY · Remote

$105K - $115K/yr

Ensure all data structures and processes adhere to HITRUST/HIPAA standards, collaborating with IT and the leads for technical efforts for HITRUST certification readiness. Required Skills & Experience

next page

Showing results 1-20

Hitrust information

See salary details

$71.5K

$122.4K

$181.5K

How much do hitrust jobs pay per year?

As of Jul 21, 2026, the average yearly pay for hitrust in the United States is $122,393.00, according to ZipRecruiter salary data. Most workers in this role earn between $97,500.00 and $146,500.00 per year, depending on experience, location, and employer.

Is cybersecurity a dying field?

Cybersecurity professionals, including those working with HITRUST compliance, are in high demand due to increasing cyber threats and data protection regulations. The field is expected to grow steadily as organizations prioritize security, requiring skills in risk management, threat detection, and security frameworks. Continuous learning and certifications like CISSP or CISA enhance job prospects in this evolving industry.

What are the key skills and qualifications needed to thrive in the Hitrust position, and why are they important?

To thrive in a HITRUST professional role, you need a robust understanding of information security, healthcare compliance, and risk assessment, typically supported by a relevant degree or certifications such as HITRUST Certified CSF Practitioner (CCSFP). Proficiency with regulatory frameworks like HIPAA, GRC tools, and HITRUST’s MyCSF platform is crucial. Strong attention to detail, analytical thinking, and effective communication are key soft skills for working with cross-functional teams and translating complex requirements. These skills enable professionals to ensure organizational compliance, manage complex security assessments, and foster trust in healthcare data protection programs.

What jobs in the US pay $300,000 a year?

High-paying jobs that can reach or exceed $300,000 annually include roles such as senior cybersecurity professionals, chief information security officers, and IT directors, especially in large organizations. These positions often require extensive experience, advanced certifications like CISSP or CISM, and leadership responsibilities within cybersecurity or technology departments.

What typical responsibilities can I expect as a HITRUST professional in a healthcare organization?

As a HITRUST professional, you will be responsible for guiding organizations through the HITRUST CSF certification process, conducting comprehensive risk and gap assessments, and creating remediation plans to address compliance issues. Your work will often involve collaborating with IT, compliance, and executive teams to implement policies, improve security controls, and ensure adherence to industry standards like HIPAA and HITECH. You can also expect to manage regular audits, prepare documentation, and educate staff on emerging security requirements. This role plays a key part in maintaining regulatory compliance and safeguarding sensitive patient data.

What is a HITRUST job?

A HITRUST job typically involves working with the HITRUST Common Security Framework (CSF) to help organizations achieve and maintain regulatory compliance, data security, and risk management. Professionals in this role may conduct risk assessments, implement security controls, and guide organizations through the HITRUST certification process. Common job titles include HITRUST Consultant, Compliance Analyst, and Security Auditor. These roles require expertise in cybersecurity, regulatory frameworks, and industry best practices.

How much do HITRUST analysts make?

HITRUST analysts typically earn between $70,000 and $110,000 annually, depending on experience, certifications, and location. They often work with compliance frameworks, security assessments, and risk management tools in healthcare or cybersecurity environments.
What cities are hiring for Hitrust jobs? Cities with the most Hitrust job openings:
What are the most commonly searched types of Hitrust jobs? The most popular types of Hitrust jobs are:
What states have the most Hitrust jobs? States with the most job openings for Hitrust jobs include:
Infographic showing various Hitrust job openings in the United States as of July 2026, with employment types broken down into 95% Full Time, 3% Part Time, and 2% Contract. Highlights an 62% Physical, 8% Hybrid, and 30% Remote job distribution, with an average salary of $122,393 per year, or $58.8 per hour.
Lead IT Security Analyst - HIPAA, HITRUST, FISMA

Lead IT Security Analyst - HIPAA, HITRUST, FISMA

NYU Langone Health

Manhattan, NY

$121K - $210K/yr

Full-time

Re-posted 19 days ago


NYU Langone Health rating

8.5

Company rating: 8.5 out of 10

Based on 247 frontline employees who took The Breakroom Quiz

15th of 886 rated healthcare providers


Job description

NYU Langone Health is a fully integrated health system that consistently achieves the best patient outcomes through a rigorous focus on quality that has resulted in some of the lowest mortality rates in the nation. Vizient Inc. has ranked NYU Langone the No. 1 comprehensive academic medical center in the country for three years in a row, and U.S. News & World Report recently placed nine of its clinical specialties among the top five in the nation. NYU Langone offers a comprehensive range of medical services with one high standard of care across 6 inpatient locations, its Perlmutter Cancer Center, and over 320 outpatient locations in the New York area and Florida. With $14.2 billion in revenue this year, the system also includes two tuition-free medical schools, in Manhattan and on Long Island, and a vast research enterprise with over $1 billion in active awards from the National Institutes of Health.
For more information, go to NYU Langone Health, and interact with us on LinkedIn, Glassdoor, Indeed, Facebook, Twitter, YouTube and Instagram.

Position Summary:
We have an exciting opportunity to join our team as a Lead IT Security Analyst.
This position reports to the IT Controls & Regulatory Compliance Manager and serves as a senior individual contributor and subject matter expert responsible for leading enterprise risk assessments and evaluating the security of modern technology environments, including cloud-based platforms. 
The IT Controls Lead drives the design, execution, and continuous improvement of the organizations risk assessment program to ensure compliance with regulatory and industry requirements, including HIPAA, HITRUST, PCI DSS, and FISMA.
This role partners closely with IT, Security, Clinical, Research, and Compliance stakeholders to assess risk across enterprise systems, research technologies, and cloud infrastructure, and to ensure that security controls are appropriately designed and operating effectively.

Job Responsibilities:

Enterprise Risk Assessment Leadership 

  • Lead the execution and maturation of the enterprise risk assessment program aligned to regulatory and industry frameworks  
  • Conduct and oversee complex risk assessments, including HIPAA and HITRUST-aligned evaluations  
  • Define and maintain risk assessment methodologies, scoring models, and standards  
  • Identify, analyze, and document risks, and develop actionable remediation strategies 

Cloud Security & Technology Risk Evaluation 

  • Lead security assessments of cloud and hybrid environments (e.g., IaaS, PaaS, SaaS)  
  • Evaluate key control domains, including:  
  • Identity and access management  
  • Network architecture and segmentation  
  • Logging, monitoring, and detection capabilities  
  • Data protection and encryption  
  • Assess alignment to frameworks such as:  
  • HITRUST 
  • PCI 
  • NIST Cybersecurity Framework  
  • ISO/IEC 27001  
  • Partner with engineering and security teams to validate that controls are effectively implemented in real-world environments 

What NYU Langone Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom