Назад
Company hidden
обновлено 5 дней назад

IT Auditor

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT Auditor (Cybersecurity and Compliance): Evaluating technology controls, IT risks, and cybersecurity practices across healthcare operations with an accent on HIPAA, SOX, NIST CSF, vendor risk, and IT governance. Focus on conducting audits and assessments, testing IT general controls, identifying emerging risks, and validating remediation of findings.

Location: Remote, USA

Company

hirify.global is a healthcare services holding company supporting home health, hospice, and senior living operations through independent subsidiaries across the United States.

What you will do

  • Perform IT audits and risk assessments covering infrastructure, cloud services, cybersecurity, identity and access management, disaster recovery, business continuity, and vendor risk.
  • Conduct process and system walkthroughs, evaluate technology control design and operating effectiveness, and recommend improvements.
  • Assess compliance with HIPAA Security Rule requirements, NIST CSF, internal policies, and other regulatory or industry frameworks.
  • Participate in cybersecurity reviews covering governance, vulnerability management, incident response, security monitoring, and identity management.
  • Support SOX compliance through IT General Controls testing, application control reviews, evidence collection, and external audit coordination.
  • Prepare audit workpapers and reports, communicate findings to stakeholders, and follow up on remediation plans.

Requirements

  • Bachelor’s degree in information systems, information technology, cybersecurity, accounting, finance, healthcare administration, or a related field.
  • At least three years of experience in IT auditing, information security, risk management, compliance, cybersecurity, or a related discipline.
  • Experience evaluating technology controls, information security practices, and IT governance processes.
  • Understanding of cybersecurity principles, risk management methodologies, and internal control frameworks.
  • Strong analytical, organizational, problem-solving, written communication, and verbal communication skills.
  • Ability to manage multiple projects and priorities in a dynamic environment.

Nice to have

  • IT audit experience in healthcare, healthcare services, or another regulated industry.
  • Familiarity with NIST CSF, HIPAA Security Rule, COBIT, and other IT governance and security frameworks.
  • Experience with Microsoft 365, Azure, Entra ID, cloud security, cybersecurity operations, or identity and access management.
  • Experience supporting SOX programs, IT General Controls testing, external auditors, regulators, or compliance assessors.
  • CISA, CRISC, CISSP, CIA, CPA, or HCISPP certification.

Culture & Benefits

  • Remote work supporting healthcare organizations through governance, risk management, cybersecurity, and technology initiatives.
  • Medical, dental, and vision plans.
  • 401(k) retirement savings plan with company match.
  • Professional development through free online courses, training sessions, and seminars.
  • Employee recognition through the Moments of Truth Program and a culture based on CAPLICO values.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →