Information Security Assurance Advisor

atMRORemoteUS flagUnited StatesFull-timeCybersecurity / Security EngineerMid-levelSenior$104k – $140k/year

Posted 7 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Develop, implement, and sustain information security policies, procedures, controls, and documentation.

• Lead the preparation and execution for HITRUST and SOC 2 Type II audits.

• Manage audit operations using the Vanta GRC platform.

• Apply relevant regulations, standards, and industry practices to mitigate risk, ensure audit readiness, and support compliance efforts.

• Define, update, and implement processes across teams in collaboration with pertinent functions.

• Identify best practices and promote ongoing improvements in information security processes.

• Document information security policies and processes while maintaining Information Security Management Systems.

• Conduct due diligence for third-party contracts and perform periodic third-party risk evaluations.

• Lead and complete information security assessments as assigned by clients.

• Oversee and support the information security risk management lifecycle.

• Ensure proper management of risk, compliance, and assurance from both internal and external viewpoints.

• Take ownership of the information security incident management program.

• Coordinate HITRUST readiness and validated assessments as well as SOC 2 Type II audits from planning through to report issuance.

• Configure frameworks and controls within Vanta; assign ownership; manage policies, documents, evidence, auditor access, requests, findings, and remediation actions.

• Maintain an always audit-ready control environment in line with HITRUST and SOC 2 requirements.

• Continuously enhance the phishing simulation program.

• Conduct Business Impact Analysis and Privacy Impact Analysis to determine and update relevant RTOs and RPOs.

• Design and engage in Business Continuity and Disaster Recovery initiatives.

• Update security training materials and facilitate training programs.

• Assist departments in gathering security metrics, performing analyses, and identifying opportunities for process enhancement.

• Prepare and distribute weekly, monthly, and quarterly reports for presentation to Infosec leadership.

• Keep procedures and playbooks for Infosec sub-teams current.


⛳️ Requirements

• Flexibility and readiness to transition to operational hands-on tasks as necessary.

• Capability to adapt to changing priorities, demands, and timelines through analytical and problem-solving skills.

• Experience in client management.

• Exceptional communication and presentation abilities.

• Hands-on experience managing at least one complete HITRUST readiness and validated assessment cycle, covering scoping, requirement interpretation, evidence validation, assessor coordination, gap remediation, and certification support.

• Hands-on experience managing at least one complete SOC 2 Type II examination cycle, including control mapping to the AICPA Trust Services Criteria, observation-period evidence, control-owner coordination, sample requests, auditor inquiries, exceptions, complementary user entity controls, subservice organization considerations, remediation, and report review.

• Practical experience using Vanta for executing audits, which encompasses framework and control administration, ownership assignments, system integrations and automated tests, policy and document management, evidence mapping and review, auditor collaboration, issue tracking, remediation workflows, and audit-readiness reporting.

• Knowledge or work experience with HIPAA, PCI DSS, TX-RAMP, NIST Cybersecurity Framework, and cross-framework control mapping (preferred).

• Bachelor's degree in Engineering or Technology (BE/B.Tech.) or a related technical field equivalent.

• Over 6 years of experience in information security assurance, GRC, compliance, or audit, including direct responsibility for coordinating HITRUST and SOC 2 Type II audits and utilizing Vanta for managing controls, evidence, auditor requests, findings, and remediation.


🏝️ Benefits

• Eligibility for annual cash bonuses.

• Medical insurance coverage.

• Dental insurance coverage.

• Vision insurance coverage.

• Life insurance coverage.

• 401(k) retirement plan.

People also viewed

AgelessRx7 hours ago

Senior Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$155k – $170k/year
ApplyView job
Xcelerate Solutions7 hours ago

Security Engineer – Intrusion Prevention Monitoring

US flagCalifornia, +1 more stateFull-timeCybersecurity / Security Engineer$94k – $149k/year
ApplyView job
OnePay9 hours ago

Security and Threat Operations Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$140k – $190k/year
ApplyView job
Halcyon9 hours ago

Senior Information Security Specialist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$120k – $160k/year
ApplyView job
Optiv11 hours ago

Security Advisor – Threat Exposure Management

US flagMinnesota, +3 more statesFull-timeCybersecurity / Security Engineer$200k – $250k/year
ApplyView job
Accenture Federal Services11 hours ago

Security Engineer – Vulnerability Management

US flagDistrict of Columbia, +1 more stateFull-timeCybersecurity / Security Engineer$106.3k – $221.1k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers