Full-Time

Information Security and Compliance Specialist

Information Security, Compliance

Posted on 7/7/2025

Chisholm Chisholm & Kilpatrick

Chisholm Chisholm & Kilpatrick

No salary listed

Providence, RI, USA

In Person

Category
IT & Security (1)
Requirements
  • Bachelor’s degree in information security, Computer Science, or a related field (Master’s preferred)
  • Minimum 5 years of experience in an information security role, preferably within a law firm, healthcare, or highly regulated environment
  • Deep understanding of state data security laws and regulations, HIPAA data security requirements and experience preparing for or managing SOC 2 Type II audits
  • Familiarity with NIST, ISO 27001, or COBIT frameworks
  • Experience with security tools (SIEM, endpoint protection, DLP, MFA, etc.)
  • Experience with the incident response life cycle
  • Excellent communication skills and ability to work with legal, technical staff and non-technical staff
Responsibilities
  • Develop and maintain the firm’s Information Security Management Program (ISMP)
  • Establish and enforce data governance and cybersecurity policies in accordance with HIPAA, SOC 2, and relevant state laws
  • Own documentation of controls, risk assessments, audit responses, and security-related protocols
  • Lead regular risk assessments and threat modeling initiatives
  • Manage the SOC 2 Type II audit process, partnering with third-party auditors and internal stakeholders
  • Oversee HIPAA compliance, including breach notification protocols, security risk analysis, and access control
  • Monitor cloud platforms, email, file sharing, and endpoints for data security compliance
  • Implement and maintain tools such as SIEM, MFA, and endpoint protection solutions
  • Evaluate third-party vendors for security posture and compliance alignment
  • Deliver firm-wide HIPAA security training and ongoing security awareness initiatives
  • Foster a culture of compliance through education and stakeholder engagement
  • Respond to incidents as needed, including triage, containment, and remediation support
  • Maintain up-to-date knowledge of industry trends, emerging threats, and best practices
Desired Qualifications
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified HIPAA Security Professional (CHSP) or equivalent
  • SOC 2 implementation or auditing experience
Chisholm Chisholm & Kilpatrick

Chisholm Chisholm & Kilpatrick

View

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

INACTIVE