665,268open jobs
38,876companies
100,271added this week
Browse all
Salary
$104k – $140k per year
Location
In office
Seniority
Senior · 6+ years exp
Overview
Company
Impact
Profile match
MRO empowers healthcare organizations with proven, enterprise-wide solutions for the secure management of clinical data across the entire lifecycle.

Overview

The Information Security Assurance Advisor develops, implements, and maintains information security policies, procedures, controls, and evidence; leads audit readiness and execution for HITRUST and SOC 2 Type II examinations; administers audit activities through the Vanta GRC platform; drives compliance; and helps maintain a security-focused culture across MRO.

Responsibilities

  • Apply applicable regulations, standards, and industry practices-including HITRUST CSF, AICPA Trust Services Criteria for SOC 2 Type II, HIPAA, TX-RAMP, PCI DSS, and NIST frameworks-to manage risk, maintain audit readiness, and support compliance.
  • Perform process definition/update and deployment across all teams in consultation with the respective functions.
  • Identify best practices, drive continuous information security related process improvement and facilitate deployment of information security process changes
  • Document the identified Information Security Policies and processes to ensure compliance with legal, regulatory and security standards (e.g. HITRUST, SOC-2, HIPAA, TX-RAMP, PCI-DSS, etc.) and maintain the Information Security Management Systems.
  • Perform due diligence for third party contracts and perform periodic 3rd party Risk Assessments.
  • Drive and complete Information Security Assessments assigned to MRO by its clients.
  • Manage and support Information Security Risk Management Lifecycle across MRO.
  • Ensure appropriate treatment of risk, compliance, and assurance from internal and external perspective.
  • Own and drive the Information Security Incident Management Program at MRO.
  • Lead and coordinate HITRUST readiness and validated assessments and SOC 2 Type II examinations from planning through report issuance, including scope definition, control-owner coordination, evidence collection and quality review, walkthroughs, sampling support, auditor requests, exception management, remediation tracking, and leadership status reporting.
  • Use Vanta as the primary GRC and audit management platform to configure frameworks and controls, assign control owners, manage policies and documents, monitor automated tests and integrations, collect and map evidence, manage auditor access and requests, track findings, and drive timely remediation through audit completion.
  • Maintain a continuously audit-ready control environment by monitoring evidence status, testing results, control performance, open gaps, and remediation commitments across HITRUST and SOC 2 requirements.
  • Drive the phishing simulation program at MRO and focus on its continual improvement.
  • Drive Business Impact Analysis, Privacy Impact Analysis across MRO to determine and update applicable RTOs and RPOs.
  • Design and participate in Business Continuity & Disaster Recovery efforts across MRO.
  • Maintain and update security training material and conduct training programs to coach and guide the teams in deploying the policies and processes
  • Supporting departments in collecting security specific metrics, conducting analysis and identifying actions for process improvement
  • Prepare and circulate weekly, monthly and quarterly reports for the Infosec team and present it to Infosec leadership team.
  • Ensure procedures and playbooks for all sub teams within Infosec team is always up to date.

Qualifications

General Skills:

  • Flexibility and ability to shift to operational hands-on activities as needed
  • Conform to shifting priorities, demands and timelines through analytical and problem-solving capabilities
  • Client management experience
  • Speed and quality of deliverable is the key
  • Excellent communication and presentation skills

Technical/Domain Skills:

  • Required: Demonstrated hands-on experience managing at least one complete HITRUST readiness and validated assessment cycle, including scoping, requirement interpretation, evidence validation, assessor coordination, gap remediation, and certification support.
  • Required: Demonstrated hands-on experience managing at least one complete SOC 2 Type II examination cycle, including control mapping to the AICPA Trust Services Criteria, observation-period evidence, control-owner coordination, sample requests, auditor inquiries, exceptions, complementary user entity controls, subservice organization considerations, remediation, and report review.
  • Required: Demonstrated practical experience using Vanta to execute audits-not solely view dashboards-including framework and control administration, ownership assignments, system integrations and automated tests, policy and document management, evidence mapping and review, auditor collaboration, issue tracking, remediation workflows, and audit-readiness reporting.
  • Preferred: Knowledge or work experience with HIPAA, PCI DSS, TX-RAMP, NIST Cybersecurity Framework, and cross-framework control mapping.

Education:

  • Bachelor's degree in Engineering or Technology (BE/B.Tech.) or an equivalent degree in a related technical field.

Work Experience (Required): 6+ years of information security assurance, GRC, compliance, or audit experience, including direct responsibility for coordinating HITRUST and SOC 2 Type II audits and using Vanta to manage controls, evidence, auditor requests, findings, and remediation.

Total CompensationBase pay is one element of the total compensation package. Eligible employees may also receive an annual cash bonus and have access to a comprehensive benefits offering, including medical, dental, vision, life insurance, and a 401(k) plan.

Salary Range It is not typical for an individual to be hired at or near the top of the range. Individual pay may be influenced by factors such as skills, qualifications, experience, licensure, certifications, geographic location, and internal equity.

Applicant Privacy Notice

Pay Range

USD $104,000.00 - USD $140,000.00 /Yr.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
665,268 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$32k – $44k per year • In office • 1+ year exp • High School Diploma • Lafayette
Cybersecurity
HIPAA
Apply
$32k – $44k per year • In office • 1+ year exp • High School Diploma • Colorado Springs
Cybersecurity
HIPAA
Apply
$36k – $40k per year • In office • 1+ year exp • High School Diploma • Grand Rapids
Cybersecurity
HIPAA
Apply
Principal AI Engineer 3 hours ago
$180k – $200k per year • In office • Bachelor's Degree
Python
Databases
PostgreSQL
Weaviate
pgvector
Pinecone
Google BigQuery
BigQuery
AI/ML
LangChain
LlamaIndex
Vertex AI
Embeddings
Prompt Engineering
Multimodal AI
NLP
AWS Bedrock
LLM
RAG
Hallucination
Hybrid Search
Amazon SageMaker
Human-in-the-Loop
LLM Guardrails
DevOps
GCP
Azure
CI/CD
AWS
Vector
Cybersecurity
HIPAA
Apply
$32k – $44k per year • In office • 1+ year exp • High School Diploma
Cybersecurity
HIPAA
Apply
$88k – $118k per year • Remote • 5+ years exp • Bachelor's Degree
Apply
$32k – $44k per year • In office • 1+ year exp • High School Diploma • Lafayette
Cybersecurity
HIPAA
Apply
$32k – $44k per year • In office • 1+ year exp • High School Diploma • Colorado Springs
Cybersecurity
HIPAA
Apply
$36k – $40k per year • In office • 1+ year exp • High School Diploma • Grand Rapids
Cybersecurity
HIPAA
Apply
Principal AI Engineer 3 hours ago
$180k – $200k per year • In office • Bachelor's Degree
Python
Databases
PostgreSQL
Weaviate
pgvector
Pinecone
Google BigQuery
BigQuery
AI/ML
LangChain
LlamaIndex
Vertex AI
Embeddings
Prompt Engineering
Multimodal AI
NLP
AWS Bedrock
LLM
RAG
Hallucination
Hybrid Search
Amazon SageMaker
Human-in-the-Loop
LLM Guardrails
DevOps
GCP
Azure
CI/CD
AWS
Vector
Cybersecurity
HIPAA
Apply
See all jobs
This is one of many
665,268 more open roles from verified company boards, updated every day.