Назад
Company hidden
1 день назад

Information Risk Consultant (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle/senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Information Risk Consultant (Cybersecurity): Conducting comprehensive information risk assessments and driving the adoption of security policies and controls with an accent on GRC frameworks and AI governance. Focus on identifying business risks, implementing remediation strategies, and ensuring compliance with HITRUST, NIST, and ISO standards.

Location: Remote (Must be based in Pennsylvania, USA)

Company

hirify.global is a large healthcare and insurance corporation focused on integrating health services and advanced information security.

What you will do

  • Conduct information risk assessments, analyze documentation, and interview stakeholders to identify business risks.
  • Develop risk scoring based on threat, vulnerability, likelihood, and impact.
  • Manage the risk register, tracking exceptions, risk acceptance, and corrective action plans.
  • Partner with project teams to integrate security architecture and remediation into solution designs.
  • Develop and maintain procedural documentation aligned with PCI-DSS, HITRUST, and ISO 27001 standards.
  • Prepare and present risk analysis and solution decks to various levels of management.

Requirements

  • Bachelor's degree in Information Security, Computer Science, or a related field.
  • 3-7 years of experience in Information Security, Risk Management, or IT.
  • 1-3 years of specialized experience in GRC functions.
  • Must be based in Pennsylvania, USA.
  • Knowledge of NIST Risk Assessment methodology, HIPAA, HITECH, and COBIT.
  • Familiarity with IPS, firewalls, DLP, SIEM, and virtualization platforms.

Nice to have

  • Industry certifications: CISSP, CISM, CISA, CEH, or GSEC.
  • Experience with GRC tools such as ARCHER.
  • Experience supporting SSAE 16 or SOC 2 Security Trust Principle audits.
  • Familiarity with AI governance frameworks like NIST AI RMF or ISO/IEC 42001.

Culture & Benefits

  • Work-from-home arrangement for residents of Pennsylvania.
  • Opportunity to work within a high-performance, multi-discipline technical environment.
  • Exposure to cutting-edge secure AI adoption practices and governance.
  • Structured corporate environment with clear compliance and ethical standards.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →