Information Security Assurance Advisor

Jobtailor

Deutschland

Remote

EUR 80.000 - 120.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Hebe dich für diese Rolle von der Masse ab — erstelle in etwa einer Minute einen maßgeschneiderten Lebenslauf und ein Anschreiben.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Jobtailor is seeking an experienced information security professional to lead HITRUST readiness and SOC 2 Type II audits, coordinating across teams and clients. You will manage policy development, risk assessment, and evidence collection using Vanta, ensuring a continuously audit-ready control environment.

The role requires 6+ years in information security assurance or audit, strong communication, and hands-on experience with HITRUST and SOC 2 Type II examinations.

Qualifikationen

  • Bachelor's degree in a technical field or related discipline.
  • 6+ years of information security assurance, GRC, compliance, or audit experience.
  • Hands-on experience coordinating HITRUST readiness and SOC 2 Type II audits and using Vanta to manage controls and evidence.

Aufgaben

  • Develop, implement, and maintain information security policies, procedures, controls, and evidence.
  • Lead audit readiness and execution for HITRUST and SOC 2 Type II examinations.
  • Administer audit activities through the Vanta GRC platform.
  • Apply regulations, standards, and industry practices to manage risk and support compliance.
  • Define, update, and deploy processes across teams in consultation with relevant functions.
  • Drive and complete information security assessments assigned by clients.
  • Own and drive the information security incident management program.
  • Coordinate HITRUST readiness and validated assessments and SOC 2 Type II examinations from planning through report issuance.

Kenntnisse

Audit management
Client management
Communication
Analytical thinking
Problem-solving

Ausbildung

Bachelor's degree in Engineering or Technology

Tools

Vanta
GRC Platforms
Audit Management Tools

Jobbeschreibung


  • Develop, implement, and maintain information security policies, procedures, controls, and evidence

  • Lead audit readiness and execution for HITRUST and SOC 2 Type II examinations

  • Administer audit activities through the Vanta GRC platform

  • Apply regulations, standards, and industry practices to manage risk, maintain audit readiness, and support compliance

  • Define, update, and deploy processes across teams in consultation with relevant functions

  • Identify best practices and drive continuous information security process improvement

  • Document information security policies and processes and maintain Information Security Management Systems

  • Perform due diligence for third-party contracts and periodic third-party risk assessments

  • Drive and complete information security assessments assigned by clients

  • Manage and support the information security risk management lifecycle

  • Ensure appropriate treatment of risk, compliance, and assurance from internal and external perspectives

  • Own and drive the information security incident management program

  • Coordinate HITRUST readiness and validated assessments and SOC 2 Type II examinations from planning through report issuance

  • Configure frameworks and controls in Vanta; assign owners; manage policies, documents, evidence, auditor access, requests, findings, and remediation

  • Maintain a continuously audit-ready control environment across HITRUST and SOC 2 requirements

  • Drive and continuously improve the phishing simulation program

  • Drive Business Impact Analysis and Privacy Impact Analysis to determine and update applicable RTOs and RPOs

  • Design and participate in Business Continuity and Disaster Recovery efforts

  • Maintain security training materials and conduct training programs

  • Support departments in collecting security metrics, conducting analysis, and identifying process improvements

  • Prepare and circulate weekly, monthly, and quarterly reports and present them to Infosec leadership

  • Keep procedures and playbooks for Infosec sub-teams up to date


Requirements


  • Flexibility and ability to shift to operational hands-on activities as needed

  • Ability to conform to shifting priorities, demands, and timelines through analytical and problem-solving capabilities

  • Client management experience

  • Excellent communication and presentation skills

  • Hands-on experience managing at least one complete HITRUST readiness and validated assessment cycle, including scoping, requirement interpretation, evidence validation, assessor coordination, gap remediation, and certification support

  • Hands-on experience managing at least one complete SOC 2 Type II examination cycle, including control mapping to the AICPA Trust Services Criteria, observation-period evidence, control-owner coordination, sample requests, auditor inquiries, exceptions, complementary user entity controls, subservice organization considerations, remediation, and report review

  • Practical experience using Vanta to execute audits, including framework and control administration, ownership assignments, system integrations and automated tests, policy and document management, evidence mapping and review, auditor collaboration, issue tracking, remediation workflows, and audit-readiness reporting

  • Knowledge or work experience with HIPAA, PCI DSS, TX-RAMP, NIST Cybersecurity Framework, and cross-framework control mapping (preferred)

  • Bachelor's degree in Engineering or Technology (BE/B.Tech.) or an equivalent degree in a related technical field

  • 6+ years of information security assurance, GRC, compliance, or audit experience, including direct responsibility for coordinating HITRUST and SOC 2 Type II audits and using Vanta to manage controls, evidence, auditor requests, findings, and remediation


Demonstrates expertise in managing information security policies, compliance frameworks, and audit processes, particularly in HITRUST and SOC 2 Type II environments. Proficient in utilizing Vanta for audit execution and maintaining a continuously audit-ready control environment.


Highest-signal resume keywords


  • HITRUST Readiness Management

  • SOC 2 Type II Examination Management

  • Vanta GRC Platform Administration

  • Information Security Risk Management

  • Compliance with HIPAA and PCI DSS


ATS Optimization Keywords

Hard Skills


  • Information Security Policies

  • Audit Readiness

  • Risk Management

  • Continuous Process Improvement

  • Third-Party Risk Assessment

  • Incident Management

  • Business Continuity Planning

  • Disaster Recovery

  • Security Metrics Analysis

  • Control Mapping


Soft Skills


  • Analytical Problem-Solving

  • Client Management

  • Excellent Communication

  • Presentation Skills

  • Flexibility


Industry Keywords


  • HITRUST

  • SOC 2 Type II

  • NIST Cybersecurity Framework

  • TX-RAMP

  • Cross-Framework Control Mapping


Tools & Technologies


  • Vanta

  • GRC Platforms

  • Audit Management Tools

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Information Security Specialist
Senior Information Security Specialist

Jobtailor • Deutschland

Remote
EUR 70.000 - 110.000
Trust & Assurance Lead
Trust & Assurance Lead

Jobtailor • Deutschland

Remote
EUR 120.000 - 180.000
Platform Information Security Officer, Diagnostics Platform
Platform Information Security Officer, Diagnostics Platform

Jobtailor • Deutschland

Remote
EUR 180.000 - 240.000
Senior Project Manager – Certified
Senior Project Manager – Certified

Jobtailor • Deutschland

Remote
EUR 70.000 - 100.000
Security Advisor – Threat Exposure Management
Security Advisor – Threat Exposure Management

Jobtailor • Deutschland

Remote
EUR 110.000 - 140.000
Information Security Consultant
Information Security Consultant

Jobtailor • Lübeck

Vor Ort
EUR 60.000 - 80.000
Security Policy and Compliance Manager
Security Policy and Compliance Manager

Jobtailor • Deutschland

Remote
EUR 78.000 - 103.000
Security Engineer – Vulnerability Management
Security Engineer – Vulnerability Management

Jobtailor • Deutschland

Remote
EUR 70.000 - 110.000
Temporary Intern – Technical Project Manager
Temporary Intern – Technical Project Manager

Jobtailor • Deutschland

Hybrid
EUR 70.000 - 95.000
Senior Test Analyst
Senior Test Analyst

Jobtailor • Deutschland

Remote
EUR 50.000 - 70.000