Full-Time

Senior Consultant

HITRUST Assessment

Confirmed live in the last 24 hours

Coalfire

Coalfire

1,001-5,000 employees

Cybersecurity advisory and managed services provider

Compensation Overview

$86k - $148k/yr

Senior

Remote in USA

Remote

Candidates must be based in the United States.

Category
IT Consulting
Consulting
Required Skills
Excel/Numbers/Sheets
Requirements
  • 5+ Years of IT security and compliance assessment experience
  • Security Certifications such as CISSP, CISA, CISM, CCSFP, HCISPP, or CIPP
  • Bachelor's degree (four-year college or university) or equivalent combination of education and work experience. Degree preferably in Information Systems or Business.
  • Subject matter expertise in the healthcare industry, including proven experience working with the HITRUST Common Security Framework (CSF), as well as the HIPAA Security and Privacy Rules.
  • Working knowledge of IT security frameworks and regulations such as NIST, ISO, CSF, HIPAA, HITECH, HITRUST and Security Breach Notification
  • Solid understanding of IT Risk Assessment methodologies either quantitative or qualitative or both
  • A solid understanding of IT security technologies including network and application security, firewalls, access management, and data protection
  • Experience and knowledge of Healthcare operations, common applications and business processes
  • Experience assessing IT security threats, vulnerabilities and IT Security audit procedures
  • Experience and success in delivering client engagements on-time and within budget
  • Strong written and verbal communication skills including the ability to explain technical matters to a non-technical audience
  • Strong Consulting skills; ability to advise and challenge the status quo while building strong relationships
  • Ability to build high-trust relationship and credibility quickly
  • Ability to lead projects successfully and delegate up and across
  • Strong attention to detail
  • Strong problem solving, decision making, organizational and analytical skills
  • Ability to prioritize and manage multiple initiatives/projects.
  • Ability to be self-driven and have strong independent initiative.
  • Strong excel skills with ability to develop worksheets with complex formulas
  • Ability to facilitate meetings to small or large groups
  • Diplomatic and broad minded
Responsibilities
  • Leads audits/assessments including audit plan preparation, review of documentation and evidence, evaluation of procedures, and client interviews.
  • Work collaboratively with a team of assessors as a HIPAA or HITRUST compliance specialist and assist with the planning of assessments to our clients.
  • Prepare, review and approve assessment reports.
  • Manage priorities, tasks and hours on projects in conjunction with the project manager to achieve delivery utilization targets.
  • Ensures quality products and services are delivered on time.
  • Escalates client and project issues to management in a timely manner to inform and engage the necessary resources to address the issue
  • Provide mentorship to team members in areas of audit, assessment, technical review and writing.
  • Interfaces with clients through entire engagement, interacting will all levels of client organizations. Establish and maintain positive collaborative relationships with clients and stakeholders
  • Continuous professional development in maintaining industry specific certifications. Maintains strong depth of knowledge in the practice area.
  • Collaborates with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.
  • Establishes account relationships and identifies upsell and cross sell opportunities and escalates to sales
  • Participation at conferences, blogs, white papers, speaking engagements, and other evangelical activities related to IT security
  • Travel typically 15-20%
  • Ability to be successful in a remote environment.
Desired Qualifications
  • Experience assessing security vulnerabilities using other frameworks such as PCI-DSS, FedRAMP, ISO, SOC, etc.

Coalfire provides cybersecurity advisory services to help businesses safeguard their digital assets and enhance their security protocols. The company focuses on cloud technology and creates scalable security programs tailored to the needs of its clients, which include large enterprises, SaaS providers, and organizations in regulated sectors like healthcare and finance. Coalfire's services encompass cybersecurity risk assessments, threat and vulnerability management, compliance assessments, and third-party risk management. They also offer cloud security consulting and managed services to ensure clients' cloud environments are secure and compliant. Unlike many competitors, Coalfire emphasizes specialized services such as HIPAA compliance and HITRUST certification guidance. The company's goal is to advance cybersecurity practices while supporting education in the field through initiatives like the Richard E. Dakin Fund.

Company Size

1,001-5,000

Company Stage

Series B

Total Funding

$9.4M

Headquarters

Westminster, Colorado

Founded

2001

Simplify Jobs

Simplify's Take

What believers are saying

  • Growing demand for FedRAMP services boosts Coalfire's market position.
  • Partnerships with Snyk and Tenable enhance Coalfire's threat-focused security offerings.
  • Expansion of Cyber Security On-Demand services provides flexible risk reduction solutions.

What critics are saying

  • Rapid office expansion may lead to operational inefficiencies.
  • Integration challenges with Snyk could affect client satisfaction.
  • FedRAMP process delays could harm Coalfire's reputation.

What makes Coalfire unique

  • Coalfire specializes in IT Governance, Risk, and Compliance for diverse industries.
  • The company offers cloud security consulting and managed services for secure environments.
  • Coalfire's partnerships enhance threat-informed application and code security development.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Remote Work Options

Parental Leave

Unlimited Paid Time Off

Professional Development Budget

Mental Health Support

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

0%

2 year growth

0%
Security Info Watch
Jun 6th, 2025
Forescout announces Coalfire partnership to accelerate FedRAMP authorization

Forescout Technologies, Inc. today announced a strategic partnership with Coalfire to accelerate the FedRAMP Authorization to Operate (ATO) processes for Forescout Cloud Services.

BizWest
Sep 11th, 2024
Exabeam appoints chief customer success officer

BROOMFIELD - Kish Dill has been appointed as chief customer success officer for Exabeam Inc., a global cybersecurity company.

BizWest
Aug 23rd, 2024
Sovrn hires pair of executives

Coalfire hires pair of execsWESTMINSTER - Coalfire Systems Inc., a Westminster-based cybersecurity firm, has hired Chris Kloes as chief...

PR Newswire
Aug 5th, 2024
Coalfire And Snyk Partner To Drive Threat-Informed Application And Code Development

This partnership brings Coalfire's hacker expertise as a managed service for optimizing application securityLAS VEGAS, Aug. 5, 2024 /PRNewswire/ -- BLACK HAT CONFERENCE -- Coalfire , an industry-leading cybersecurity services and solutions company, today announced a partnership with Snyk , the leader in developer security, to operationalize application and code security faster than ever. This partnership brings Coalfire's hackers and defenders to the critical work of detecting and stopping vulnerabilities in the code development phase and beyond. Combining Snyk's leading Developer Security Platform with Coalfire's hacker expertise provides a threat-informed view of vulnerabilities, enabling enterprises to more rapidly address the most pressing flaws in their code and applications.Organizations of all sizes often struggle with enabling their security teams to reduce risk in their development environments, whether in proprietary code, open source modules, containers, or Infrastructure as Code. Snyk's world class platform enables developer teams to identify and fix those vulnerabilities and misconfigurations from the integrated development environment (IDE) to the operation of their cloud environments. The addition of Coalfire's hackers and defenders brings in a threat-informed perspective to prioritize the remediation of those vulnerabilities, which optimizes security outcomes for customers.Through this partnership, Coalfire's experts assist clients with deployment of the Snyk platform, implementing Snyk best practices, facilitating comprehensive testing, reviewing scan results and prioritizing vulnerabilities, as well as providing expert guidance on risk management and secure coding

The Software Report
Aug 5th, 2024
Procore Technologies Initiates FedRAMP Authorization Process to Enhance Security Compliance

Procore has partnered with Coalfire, a renowned cybersecurity and compliance services company, to ensure that its customers benefit from standardized security and continuous monitoring across its product suite, efficiently achieving audit-ready status.