
1001 - 5000 employees
Founded 2001
💼 Consulting
🏥 Healthcare
📦 Logistics
Consulting • Healthcare • Logistics
Coalfire is a cybersecurity services provider that helps businesses improve their security resilience and streamline regulatory compliance. The company offers expert-led services, including threat-focused cybersecurity programs, compliance automation, risk management, and security advisory services across various industries such as financial services, healthcare, retail, and technology. Coalfire is known for its hacker and defender expertise, and its platforms are designed to fortify clients' cyber resilience, reduce attack surfaces, and accelerate the achievement of compliance objectives like FedRAMP and HITRUST.
🔥 1 minute ago
🇺🇸 United States – Remote
💵 $71k - $119k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
🚔 Compliance
🦅 H1B Visa Sponsor
👻 Ghost score 0%
Improve your chances of getting an interview by checking your resume score before you apply.

1001 - 5000 employees
Founded 2001
💼 Consulting
🏥 Healthcare
📦 Logistics
Consulting • Healthcare • Logistics
Coalfire is a cybersecurity services provider that helps businesses improve their security resilience and streamline regulatory compliance. The company offers expert-led services, including threat-focused cybersecurity programs, compliance automation, risk management, and security advisory services across various industries such as financial services, healthcare, retail, and technology. Coalfire is known for its hacker and defender expertise, and its platforms are designed to fortify clients' cyber resilience, reduce attack surfaces, and accelerate the achievement of compliance objectives like FedRAMP and HITRUST.
• Support security and compliance consulting for cloud-based, hybrid, and on-premises healthcare environments • Manage assigned priorities and tasks to meet delivery timelines, utilization expectations, and quality standards; raise schedule, scope, resource, or evidence issues early • Support client SME interviews, workshops, readouts, and status meetings; co-facilitate assigned portions when appropriate • Assist with developing System Security Plans, configuration management plans, information system security policies, rules of behavior, privacy impact analyses, IT contingency and business continuity plans, and incident response plans • Support risk assessments, gap analyses, assessment readiness, system security plan development, policy and procedure development, and other consulting services • Collect, organize, and interpret client information and evidence; map information to applicable requirements; identify compliance and risk implications • Prepare, update, and quality-check client deliverables, including compliance documentation, reports, policies, procedures, plans, evidence matrices, and workpapers • Support engagement planning by reviewing contractual requirements, agendas, data requests, action items, schedules, and assigned responsibilities • Review technology, control evidence, and configurations related to cloud infrastructure, identity and access management, MFA, user access lifecycle, privileged access, access reviews, logging and monitoring, vulnerability management, incident response, endpoint security, and network security • Support engagements involving business continuity and disaster recovery, incident response, and vendor risk management • Translate technical requirements and security findings into clear, practical recommendations • Contribute to reusable tools, templates, workpapers, methodologies, and process improvements • Participate in internal knowledge sharing, peer review, and constructive feedback activities • Maintain current knowledge of assigned frameworks, industry practices, and relevant technology and security topics • Collaborate with project management, quality management, sales, and delivery teams to support customer satisfaction and successful project delivery • Communicate professionally with clients, project leads, and Coalfire team members through email, video conferencing, and in-person meetings • Explain technical requirements, evidence needs, control gaps, and recommendations clearly to technical and non-technical audiences • Build professional relationships with client stakeholders and internal team members • Document decisions, action items, risks, dependencies, and follow-up requirements accurately • Use sound judgment, diplomacy, and discretion when working with sensitive client and patient-related information • Work remotely using computers and video-conferencing tools • Travel may be required based on engagement needs; up to 25% travel is uncommon
• 3+ years of relevant experience in professional IT services, cybersecurity, technology risk, technology compliance, security assessment, or related consulting; 4+ years preferred • At least 2 years of experience working with one or more security, privacy, risk, or compliance frameworks or regulations, preferably in healthcare or a highly regulated environment • Bachelor’s degree from a four-year college or university in information technology, computer science, business, risk management, cybersecurity, or a related field; or an equivalent combination of education and work experience • Experience facilitating or supporting security and compliance audits, risk assessments, gap analyses, advisory engagements, or assessment-readiness activities • Experience working with healthcare, life-sciences, or other highly regulated environments is preferred • Experience implementing technical controls or evaluating technology risk is highly valued • Working knowledge of virtualization and cloud technologies • Working knowledge of client-server and traditional on-premises architecture • Working knowledge of identity and access management concepts, including authentication, MFA, least privilege, joiner/mover/leaver processes, privileged access, access reviews, and access-request workflows • Working knowledge of security operations concepts, including incident response, vulnerability management, security logging and monitoring, endpoint or network security, and remediation tracking • Familiarity with enterprise technology support processes, system administration, technical support, or help desk operations is preferred • Familiarity with Governance Risk and Compliance (GRC) tools and information-security-related solutions, tools, and utilities • Ability to evaluate evidence carefully, identify control or process concerns, and communicate risks and dependencies to an engagement lead • Ability to support interviews and ask follow-up questions to clarify processes, identify gaps, and support root-cause analysis • Ability to produce accurate, well-organized, client-ready written work • Experience with one or more security, privacy, risk, or compliance frameworks is required, including HITRUST, HIPAA/HITECH, NIST SP 800-53, NIST SP 800-30, NIST CSF, ARC-AMPE, BSI C5, ISMAP, or other cloud and healthcare-related frameworks • Strong written and verbal communication skills • Strong consulting skills • Strong personal initiative and ability to manage time, priorities, and deadlines • High attention to detail and commitment to quality • Ability to support or co-facilitate meetings and communicate effectively with small or large groups • Ability to work collaboratively in a team-based delivery model and accept direction and feedback • Proactive problem solving, adaptability, flexibility, and active learning • Ability to handle sensitive information professionally and maintain appropriate confidentiality • Relevant certifications are preferred; examples include HITRUST CCSFP, Security+, CISA, CRISC, CISM, CISSP, CCISO, CAP, CIPM, CIPP/US, CCSK, CCSP, AWS, Azure, or Google Cloud security certifications • For engagements with a framework-specific credential requirement, the Consultant must hold the applicable credential or obtain it within the timeframe established by the practice • Candidates without a relevant certification must demonstrate the ability to achieve a manager-prescribed certification within two years
• Flexible work model allowing work from home or an office • Paid parental leave • Flexible time off • Certification and training reimbursement • Digital mental health and wellbeing support membership • Comprehensive insurance options • Employee resource groups • In-person and virtual events • Annual incentive, commission, and/or recognition programs may be available • Relevant certifications and framework-specific credentials may be supported or required for client engagements • Remote work environment
Apply Now🔥 1 hour ago
Cyber risk specialist securing LivaNova’s medtech financial systems and healthcare compliance. Leading IT SOX, HIPAA, NIS2, risk assessment, and security awareness programs.
🔥 1 hour ago
Global Trade Compliance Manager advancing Autodesk’s software-driven trade compliance program. Leading export classification, audits, training, workflows, and M&A integration.
🔥 1 hour ago
Senior Director guiding U.S. FDA strategy for BeOne’s oncology medicines portfolio. Leading submissions, agency interactions, regulatory risk, and U.S. regulatory organization development.
🔥 1 hour ago
Expert Compliance Risk Advisor guiding Experian's data and technology business through consumer-credit regulatory compliance. Assessing risks, supporting regulatory exams, and improving controls across business teams.
🇺🇸 United States – Remote
💵 $82.6k - $143.2k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
🚔 Compliance
🦅 H1B Visa Sponsor
🔥 3 hours ago
Associate Director overseeing sales compliance, regulatory governance, and risk mitigation for Humana's healthcare and insurance operations. Remote nationwide role partnering with sales, legal, compliance, and agency teams.