Serve as a key contributor in the execution of HITRUST assessments by evaluating client evidence, performing control testing, and assessing compliance with the HITRUST CSF across multiple maturity levels. Support readiness, validated, interim, and remediation validation assessments by documenting testing outcomes, identifying control gaps, and contributing to scoring and assessment deliverables. Collaborate with clients and internal project teams to manage evidence collection, track assessment progress, and ensure timely resolution of open items while maintaining adherence to HITRUST methodologies, MyCSF workflows, quality standards, and project timelines.
- 3-5 years of experience in cybersecurity, IT audit, GRC, compliance, risk management, or security assurance.
- Hands-on experience in control testing, evidence review, and assessing the design, implementation, and operating effectiveness of security and compliance controls.
- Exposure to HITRUST CSF assessments, readiness reviews, gap assessments, or validated assessment support.
- Ability to review and analyze policies, procedures, system configurations, reports, logs, tickets, screenshots, and other audit evidence to identify control gaps and compliance risks
- Strong analytical, documentation, and communication skills with a keen attention to detail and the ability to clearly articulate findings and recommendations.
- Strong written and verbal communication skills.
- Experience with security and compliance frameworks such as HITRUST, ISO 27001/27701, SOC 2, HIPAA, NIST, and CMMC.
- Hands-on exposure to compliance assessments, readiness reviews, control testing, and control mapping activities.
- Knowledge of cloud security and assessments across AWS, Microsoft Azure, or Google Cloud platforms.
- Understanding of key cybersecurity areas including vulnerability management, access controls, incident response, risk management, vendor risk management, and regulatory frameworks such as FedRAMP and EU CRA.
- Review and evaluate client-provided evidence against HITRUST CSF requirements, identifying control gaps, deficiencies, inconsistencies, and areas requiring clarification.
- Perform and support HITRUST control testing across various maturity levels, including policy, procedure, implemented, measured, and managed controls.
- Document testing results, observations, compliance findings, and assessor notes to support accurate and consistent assessment outcomes.
- Assist in HITRUST readiness assessments, validated assessments, interim assessments, and remediation validation activities under the guidance of senior assessors.
- Support HITRUST scoring activities and contribute to the preparation of assessment-related documentation and deliverables.
- Collaborate with project teams and clients to manage evidence requests, track open items, monitor responses, and ensure timely completion of assessment activities.
- Participate in internal quality reviews while maintaining adherence to HITRUST methodologies, MyCSF workflows, project timelines, and quality standards