
Information Security Assurance Advisor
Posted 7 hours ago

Posted 7 hours ago
This is a fully remote position, open to applicants in United States.
• Develop, implement, and sustain information security policies, procedures, controls, and documentation.
• Lead the preparation and execution for HITRUST and SOC 2 Type II audits.
• Manage audit operations using the Vanta GRC platform.
• Apply relevant regulations, standards, and industry practices to mitigate risk, ensure audit readiness, and support compliance efforts.
• Define, update, and implement processes across teams in collaboration with pertinent functions.
• Identify best practices and promote ongoing improvements in information security processes.
• Document information security policies and processes while maintaining Information Security Management Systems.
• Conduct due diligence for third-party contracts and perform periodic third-party risk evaluations.
• Lead and complete information security assessments as assigned by clients.
• Oversee and support the information security risk management lifecycle.
• Ensure proper management of risk, compliance, and assurance from both internal and external viewpoints.
• Take ownership of the information security incident management program.
• Coordinate HITRUST readiness and validated assessments as well as SOC 2 Type II audits from planning through to report issuance.
• Configure frameworks and controls within Vanta; assign ownership; manage policies, documents, evidence, auditor access, requests, findings, and remediation actions.
• Maintain an always audit-ready control environment in line with HITRUST and SOC 2 requirements.
• Continuously enhance the phishing simulation program.
• Conduct Business Impact Analysis and Privacy Impact Analysis to determine and update relevant RTOs and RPOs.
• Design and engage in Business Continuity and Disaster Recovery initiatives.
• Update security training materials and facilitate training programs.
• Assist departments in gathering security metrics, performing analyses, and identifying opportunities for process enhancement.
• Prepare and distribute weekly, monthly, and quarterly reports for presentation to Infosec leadership.
• Keep procedures and playbooks for Infosec sub-teams current.
• Flexibility and readiness to transition to operational hands-on tasks as necessary.
• Capability to adapt to changing priorities, demands, and timelines through analytical and problem-solving skills.
• Experience in client management.
• Exceptional communication and presentation abilities.
• Hands-on experience managing at least one complete HITRUST readiness and validated assessment cycle, covering scoping, requirement interpretation, evidence validation, assessor coordination, gap remediation, and certification support.
• Hands-on experience managing at least one complete SOC 2 Type II examination cycle, including control mapping to the AICPA Trust Services Criteria, observation-period evidence, control-owner coordination, sample requests, auditor inquiries, exceptions, complementary user entity controls, subservice organization considerations, remediation, and report review.
• Practical experience using Vanta for executing audits, which encompasses framework and control administration, ownership assignments, system integrations and automated tests, policy and document management, evidence mapping and review, auditor collaboration, issue tracking, remediation workflows, and audit-readiness reporting.
• Knowledge or work experience with HIPAA, PCI DSS, TX-RAMP, NIST Cybersecurity Framework, and cross-framework control mapping (preferred).
• Bachelor's degree in Engineering or Technology (BE/B.Tech.) or a related technical field equivalent.
• Over 6 years of experience in information security assurance, GRC, compliance, or audit, including direct responsibility for coordinating HITRUST and SOC 2 Type II audits and utilizing Vanta for managing controls, evidence, auditor requests, findings, and remediation.
• Eligibility for annual cash bonuses.
• Medical insurance coverage.
• Dental insurance coverage.
• Vision insurance coverage.
• Life insurance coverage.
• 401(k) retirement plan.
AgelessRx
Xcelerate Solutions
OnePay
Halcyon
Get handpicked remote jobs straight to your inbox weekly.