Information Security Analyst / IT Auditor

HITRUST
United States
11 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Unix Control Objectives for Information and Related Technology (COBIT) Cyber Security Disaster Recovery Information Technology Audit Windows Servers IT General Controls (ITGC)

Requirements

We are looking for a strong communicator to work with our assessors in a straightforward manner. This job is not about rubber stamping the product but rather ensuring quality. If you enjoy working in a structured environment and you have an analytical mindset, this could be the perfect match. The ideal candidate will have a background in public accounting IT audit and will be able to demonstrate IT security or security assessment experience., * This position requires 3 to 7 years of experience performing and reviewing IT audits, such as Infrastructure Audits, IT Security Reviews, IT general controls reviews, SOC 2 reports, etc.

  • Strong knowledge of security risk management, analysis and assessment concepts and their application
  • Strong knowledge of technology platforms (i.e., UNIX, Windows Server, AWS, etc.), networks, and infrastructure
  • Good understanding of AI security concepts, risks, governance, and controls
  • Good understanding of Business Continuity and Disaster Recovery (BC/DR) concepts
  • Must be technically proficient in performing assigned duties at a solid level of independence under minimal supervision while working within a team environment
  • Ability to manage multiple assessments simultaneously and adapt to shifting priorities
  • Strong analytical skills are required; you must be very detail-oriented with an ability to develop and apply complex concepts
  • Interpersonal project management skills; ability to organize and track project tasks
  • Bachelor’s degree or equivalent work experience, * Public accounting experience in an IT audit role
  • Familiarity with the HITRUST CSF or another security framework methodology, such as NIST, ISO, COBIT, ITIL, etc.
  • HITRUST certifications, including Certified CSF Practitioner (CCSFP) and Certified HITRUST Quality Professional (CHQP)
  • CISA, HCISPP, CISM, CIA, CISSP, or similar certification

About the company

HITRUST is the leader in validated cybersecurity assurance used in third-party risk management and compliance. HITRUST delivers assurance and certification programs for the application and independent validation of security, privacy, and AI controls, harmonized across more than 60 authoritative standards and frameworks. Its threat-adaptive approach combines tiered, selectable assessments (e1, i1, r2, and AI), an ecosystem of over 100 independent assessment firms, centralized quality assurance, standardized reporting, and a powerful SaaS platform to enable consistent, defensible, and scalable assurance. HITRUST delivers the only assurance certification with defensible proof of security, demonstrated by a 99.62% breach-free rate among certified environments in the 2026 Trust Report. For nearly 20 years, HITRUST has defined the standard for trustworthy cybersecurity proof, helping organizations demonstrate measurable cybersecurity resilience across their enterprises and third-party ecosystems.

HITRUST is an equal opportunity employer that is committed to diversity and inclusion in the workplace.

We prohibit discrimination and harassment of any kind based on race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on recruiting.paylocity.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

4:07 min

Building and running Windows containers locally on Windows servers

Don Schenck Don Schenck · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

2:37 min

Consolidating local servers into a single terminal window

Stacy Cashmore · WWC 2022

Videos

See all

Related articles

See all