Information Security Assurance Advisor

🔥 13 hours ago

🇺🇸 United States – Remote

💵 $104k - $140k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of MRO

MRO

1001 - 5000 employees

🏥 Healthcare

☁️ SaaS

📋 Compliance

💰 Series unknown on 2019-11

Healthcare • SaaS • Compliance

MRO is an enterprise healthcare software company that provides a Clinical Data Exchange Platform (CDXP) and modular solutions to securely curate, normalize, and exchange clinical data across providers, payers, registries, and clinical data requesters. MRO helps hospitals, health systems, ambulatory practices, and payers streamline release of information, compliance workflows, MIPS/quality reporting, ACO tracking, and clinical intelligence by connecting to hundreds of disparate EHRs, reducing administrative burden and accelerating patient-focused care delivery. The company emphasizes security and regulatory compliance and has been recognized with Best in KLAS awards for Release of Information.

📋 Description

• Develop, implement, and maintain information security policies, procedures, controls, and evidence • Lead audit readiness and execution for HITRUST and SOC 2 Type II examinations • Administer audit activities through the Vanta GRC platform • Apply regulations, standards, and industry practices to manage risk, maintain audit readiness, and support compliance • Define, update, and deploy processes across teams in consultation with relevant functions • Identify best practices and drive continuous information security process improvement • Document information security policies and processes and maintain Information Security Management Systems • Perform due diligence for third-party contracts and periodic third-party risk assessments • Drive and complete information security assessments assigned by clients • Manage and support the information security risk management lifecycle • Ensure appropriate treatment of risk, compliance, and assurance from internal and external perspectives • Own and drive the information security incident management program • Coordinate HITRUST readiness and validated assessments and SOC 2 Type II examinations from planning through report issuance • Configure frameworks and controls in Vanta; assign owners; manage policies, documents, evidence, auditor access, requests, findings, and remediation • Maintain a continuously audit-ready control environment across HITRUST and SOC 2 requirements • Drive and continuously improve the phishing simulation program • Drive Business Impact Analysis and Privacy Impact Analysis to determine and update applicable RTOs and RPOs • Design and participate in Business Continuity and Disaster Recovery efforts • Maintain security training materials and conduct training programs • Support departments in collecting security metrics, conducting analysis, and identifying process improvements • Prepare and circulate weekly, monthly, and quarterly reports and present them to Infosec leadership • Keep procedures and playbooks for Infosec sub-teams up to date

🎯 Requirements

• Flexibility and ability to shift to operational hands-on activities as needed • Ability to conform to shifting priorities, demands, and timelines through analytical and problem-solving capabilities • Client management experience • Excellent communication and presentation skills • Hands-on experience managing at least one complete HITRUST readiness and validated assessment cycle, including scoping, requirement interpretation, evidence validation, assessor coordination, gap remediation, and certification support • Hands-on experience managing at least one complete SOC 2 Type II examination cycle, including control mapping to the AICPA Trust Services Criteria, observation-period evidence, control-owner coordination, sample requests, auditor inquiries, exceptions, complementary user entity controls, subservice organization considerations, remediation, and report review • Practical experience using Vanta to execute audits, including framework and control administration, ownership assignments, system integrations and automated tests, policy and document management, evidence mapping and review, auditor collaboration, issue tracking, remediation workflows, and audit-readiness reporting • Knowledge or work experience with HIPAA, PCI DSS, TX-RAMP, NIST Cybersecurity Framework, and cross-framework control mapping (preferred) • Bachelor's degree in Engineering or Technology (BE/B.Tech.) or an equivalent degree in a related technical field • 6+ years of information security assurance, GRC, compliance, or audit experience, including direct responsibility for coordinating HITRUST and SOC 2 Type II audits and using Vanta to manage controls, evidence, auditor requests, findings, and remediation

🏖️ Benefits

• Annual cash bonus eligibility • Medical insurance • Dental insurance • Vision insurance • Life insurance • 401(k) plan

Apply Now

Similar Jobs

🔥 13 hours ago

Optiv

1001 - 5000

Optiv cybersecurity advisor designing threat management solutions for client security programs. Driving security services sales, client strategy, and scalable defensive architectures.

🔥 13 hours ago

Accenture Federal Services

10,000+ employees

💼 Consulting

🎖️ Defense

📦 Logistics

Security Engineer managing vulnerability assessments, remediation, and ATO readiness. Supporting Accenture Federal Services’ mission to strengthen US federal government technology and security.

🔥 13 hours ago

FAR.AI

11 - 50

🤖 Artificial Intelligence

📚 Education

🤝 Non-profit

IT & Security Manager securing systems, devices, identity, and networks for FAR.AI, a nonprofit AI safety research institute. Building scalable internal IT and security operations.

🔥 14 hours ago

Horizon Industries, Limited

201 - 500

💼 Consulting

☁️ SaaS

🔒 Cybersecurity

Cybersecurity Specialist supporting DISA enterprise software systems at Horizon Industries, an IT and management consulting firm. Providing information assurance and security engineering in an agile environment.

🔥 14 hours ago

Sentara Health

10,000+ employees

🏥 Healthcare

⚕️ Healthcare Insurance

Senior Cyber Security Engineer securing Sentara Health’s Microsoft enterprise ecosystem. Designing Microsoft 365, Azure, Intune, and Defender controls across regulated healthcare environments.