Prescient Security Logo

Prescient Security

HITRUST CSF Assessor

Posted 25 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Lead and perform HITRUST Gap, Readiness, and Validated Assessments. Define scope, test controls, validate evidence in MyCSF, produce readiness and validated reports, advise clients on remediation, and ensure compliance with HITRUST methodology and related frameworks.
The summary above was generated by AI

HITRUST Lead Auditor, Remote, India

At Prescient Security, we are on a mission to simplify security and compliance.

Our core values are:

  • Bring Order to Chaos
  • Be Accountable & See it Through
  • 1000% With You
  • Support & Collaborate
  • Think Outside the Box

Summary:

The HITRUST Assessor is responsible for conducting Gap Assessments, Readiness Assessments, and Validated Assessments against the HITRUST Common Security Framework (CSF). The role involves close collaboration with client organizations to evaluate, guide, and validate their security posture and compliance with HITRUST requirements.

The Assessor ensures that all assessment activities are performed in accordance with HITRUST methodology, quality standards, and applicable regulatory expectations.

Essential Duties and Responsibilities:

  • Define assessment scope, objectives, and applicable HITRUST CSF controls based on organization type and regulatory factors.
  • Conduct kick-off meetings with clients to explain assessment approach, timelines, and expectations.
  • Identify key stakeholders, systems, locations, and data flows within scope.
  • Develop assessment plans, including timelines, resource allocation, and milestones.
  • Perform initial gap analysis to identify control deficiencies against HITRUST CSF requirements.
  • Evaluate current state of:
    • Policies and procedures
    • Security controls implementation
    • Risk management practices
  • Provide actionable recommendations and remediation roadmap.
  • Support client in prioritization of gaps based on risk and compliance impact.
  • Assess the organization’s preparedness for HITRUST Validated Assessment.
  • Validate implementation status of controls and supporting evidence.
  • Identify residual gaps and weaknesses.
  • Provide detailed readiness report including:
    • Control maturity levels
    • Missing evidence
    • Improvement recommendations
  • Guide clients on documentation and evidence expectations.
  • Perform formal HITRUST CSF Validated Assessment in accordance with HITRUST guidelines.
  • Evaluate control implementation across domains such as:
    • Information Security
    • Risk Management
    • Access Control
    • Incident Management
    • Business Continuity
  • Conduct control testing and validation, including:
    • Sampling techniques
    • Evidence verification
    • Interviews with stakeholders
  • Ensure accuracy and completeness of assessment data in HITRUST tools (e.g., MyCSF).
  • Review client-provided documentation including:
    • Policies, SOPs, and standards
    • Risk assessments and treatment plans
    • Logs, reports, and system configurations
  • Ensure documentation:
    • Meets HITRUST CSF requirements
    • Is consistent, complete, and up to date
  • Identify documentation gaps and inconsistencies.
  • Act as a trusted advisor to clients throughout the engagement.
  • Provide guidance on:
    • Control implementation strategies
    • Industry best practices
    • Compliance alignment (e.g., ISO 27001, SOC 2, HIPAA)
  • Support clients in remediation planning and closure of findings.
  • Clarify HITRUST requirements without compromising assessor independence.
  • Conduct on-site or remote assessments as required.
  • Perform:
    • Physical security walkthroughs
    • System demonstrations
    • Interviews with process owners
  • Collect and validate audit evidence to support control effectiveness.
  • Prepare comprehensive assessment reports, including:
    • Control scores and maturity ratings
    • Observations and findings
    • Non-conformities and gaps
  • Ensure quality, accuracy, and traceability of all assessment outputs.
  • Submit validated assessment to HITRUST via required platforms.
  • Address QA feedback and HITRUST queries during review process.
  • Ensure assessments comply with:
    • HITRUST CSF methodology
    • Internal QA requirements
    • Ethical and independence standards
  • Participate in internal peer reviews and quality checks.
  • Maintain assessment documentation and audit trail.
  • Stay updated with:
    • HITRUST CSF updates
    • Regulatory changes
    • Emerging cybersecurity risks
  • Contribute to:
    • Internal knowledge base
    • Methodology improvements
    • Training and mentoring junior assessors

Work Skills and Qualifications:

  • Strong understanding of:
    • HITRUST CSF
    • Information Security frameworks (ISO 27001, NIST, SOC 2)
  • Risk assessment and control evaluation techniques
  • Audit and compliance methodologies
  • Analytical and problem-solving skills
  • Report writing and documentation expertise
  • Stakeholder management
  • Attention to detail
  • Professional skepticism
  • Communication and client handling skills
  • Integrity and ethical conduct

NOTE: This job description is not intended to be all-inclusive. Employee may perform other related duties as negotiated to meet the ongoing needs of the organization.

Prescient Security provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age disability or genetics.

Similar Jobs

46 Minutes Ago
Easy Apply
Remote
USA
Easy Apply
186K-219K Annually
Senior level
186K-219K Annually
Senior level
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Design, build, and operate secure, low-latency authentication and authorization services using Go and gRPC. Own capabilities spanning OAuth, sessions, tokens, 2FA, account recovery, and edge authorization. Lead complex technical initiatives, improve integration tooling, collaborate with product, security, fraud, and infrastructure teams, and mentor engineers while maintaining strong observability, reliability, and security standards.
Top Skills: 2FaBiometric AuthenticationDistributed SystemsDynamoDBGenerative AiGoGrpcJwtOauth 2.0ObservabilityOpenid ConnectPasskeysPkceProtocol BuffersRedisSlos
46 Minutes Ago
Easy Apply
Remote
USA
Easy Apply
180K-212K Annually
Senior level
180K-212K Annually
Senior level
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Own the strategy and roadmap for enterprise identity and multi-user capabilities, including RBAC, organization management, SSO, provisioning, authentication, and account security. Lead cross-functional launches with engineering, security, legal, privacy, and customer experience teams. Define platform vision, address vulnerabilities, establish privileged-access safeguards, and translate complex identity requirements into intuitive experiences for business and consumer customers.
Top Skills: Generative AiJit ProvisioningMfaOauthOidcRbacSAMLScimSession ManagementSso
48 Minutes Ago
Easy Apply
Remote
USA
Easy Apply
Senior level
Senior level
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Owns FP&A for Coinbase Platform leadership, including annual budgeting, rolling forecasts, monthly planning, month-end variance analysis, financial modeling, and business reviews. Partners with senior stakeholders to guide OpEx planning, resource allocation, investment decisions, and risk assessment. Uses SQL, planning systems, visualization tools, and generative AI to analyze financial and operational data and improve decision-making.
Top Skills: AnaplanGeminiGenerative AiGleanLibrechatLookerNetSuiteSQLTableau

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account