> Markdown version of [/jobs/ext/2025720-it-security-specialist-i](https://www.wearedevelopers.com/jobs/ext/2025720-it-security-specialist-i). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Specialist I - **Company:** KYYBA, Inc - **Location:** Detroit, MI, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Databases, Information Technology Audit, Smartsuite, IT General Controls (ITGC) - **Published:** August 11, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/it-security-specialist-i-detroit-mi-usa-58901237 ## About the Role MI, and reporting materials that meet HITRUST standards * Utilize GRC tools to manage remediation plans and documentation * Support audits, assessments, and third-party reviews * Build relationships to foster teamwork and collaboration * Contribute to initiatives and projects related to governance and security Tasks * 4-5 years of IT compliance, IT assessments, or IT audit experience * Knowledge of HITRUST CSF, NIST CSF, ISO/IEC 27001, COBIT * Strong written and verbal communication and critical thinking * Experience coordinating and executing the audit lifecycle * Experience testing IT controls across systems, databases, apps, and OS * Ability to tailor communication to audience * Problem-solving, decision-making under pressure, and professional demeanor * Strong organizational skills and adaptability to changing priorities * Self-directed with minimal guidance Key requirements * ## Description Experteer Overview In this role you support the security governance program for a major health care payer, focusing on HITRUST CSF compliance and risk mitigation. You will document adherence to governance requirements across policies, controls, and training, and prepare dashboards and metrics for leadership. You collaborate with cross-functional teams to strengthen controls and participate in audits and third-party reviews. This position offers hands-on exposure to risk assessment, remediation, and governance processes in a healthcare/compliance context. Compensation / Benefits * Assist in executing security framework compliance and governance activities * Document evidence of governance adherence across policies, controls, and training * Evaluate design and operation effectiveness against HITRUST CSF and identify improvements * Interview SMEs, analyze evidence, and perform testing * Collaborate with cross-functional teams to mitigate risks and ensure compliance * Produce documentation and reporting materials that meet HITRUST standards * Utilize GRC tools to manage remediation plans and documentation * Support audits, assessments, and third-party reviews * Build relationships to foster teamwork and collaboration * Contribute to initiatives and projects related to governance and security Tasks * 4-5 years of IT compliance, IT assessments, or IT audit experience * Knowledge of HITRUST CSF, NIST CSF, ISO/IEC 27001, COBIT * Strong written and verbal communication and critical thinking * Experience coordinating and executing the audit lifecycle * Experience testing IT controls across systems, databases, apps, and OS * Ability to tailor communication to audience * Problem-solving, decision-making under pressure, and professional demeanor * Strong organizational skills and adaptability to changing priorities * Self-directed with minimal guidance Key requirements * ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)