信息安全保证顾问
Information Security Assurance Advisor
概述
信息安全管理顾问负责制定、实施和维护信息安全政策、流程、控制措施和证据;领导HITRUST和SOC 2 Type II审查的准备和执行;通过Vanta GRC平台管理审计活动;推动合规性,并帮助在MRO内部维持以安全为中心的文化。
职责
- 应用适用的法规、标准和行业实践,包括HITRUST CSF、AICPA信任服务准则(SOC 2 Type II)、HIPAA、TX-RAMP、PCI DSS和NIST框架,以管理风险、保持审计准备并支持合规性。
- 在与相关部门协商后,跨所有团队进行流程定义/更新和部署。
- 识别最佳实践,推动持续的信息安全相关流程改进,并促进信息安全流程变更的实施。
- 记录已确定的信息安全政策和流程,以确保符合法律、监管和安全标准(例如HITRUST、SOC-2、HIPAA、TX-RAMP、PCI-DSS等),并维护信息安全管理系统。
- 对第三方合同进行尽职调查,并定期进行第三方风险评估。
- 推动并完成客户分配给MRO的信息安全评估。
- 管理和支持MRO内的信息安全风险管理生命周期。
- 确保从内部和外部角度对风险、合规性和保证进行适当处理。
- 负责并推动MRO的信息安全事件管理计划。
- 领导并协调HITRUST准备和验证评估以及SOC 2 Type II审查,从规划到报告发布,包括范围定义、控制负责人协调、证据收集和质量审查、演练、抽样支持、审计师请求、异常管理、补救跟踪和管理层状态报告。
- 使用Vanta作为主要的GRC和审计管理平台,配置框架和控制措施,指派控制负责人,管理政策和文档,监控自动化测试和集成,收集和映射证据,管理审计师访问和请求,跟踪发现的问题,并在审计完成前推动及时补救。
- 通过监控证据状态、测试结果、控制表现、开放差距和补救承诺,保持HITRUST和SOC 2持续的审计准备环境。
查看英文原文
Overview
TheInformation Security Assurance Advisor develops, implements, and maintains information security policies, procedures, controls, and evidence; leads audit readiness and execution for HITRUST and SOC 2 Type II examinations; administers audit activities through the Vanta GRC platform; drives compliance; and helps maintain a security-focused culture across MRO.
Responsibilities
- Apply applicable regulations, standards, and industry practices—including HITRUST CSF, AICPA Trust Services Criteria for SOC 2 Type II, HIPAA, TX-RAMP, PCI DSS, and NIST frameworks—to manage risk, maintain audit readiness, and support compliance.
- Perform process definition/update and deployment across all teams in consultation with the respective functions.
- Identify best practices, drive continuous information security related process improvement and facilitate deployment of information security process changes
- Document the identified Information Security Policies and processes to ensure compliance with legal, regulatory and security standards (e.g. HITRUST, SOC-2, HIPAA, TX-RAMP, PCI-DSS, etc.) and maintain the Information Security Management Systems.
- Perform due diligence for third party contracts and perform periodic 3rd party Risk Assessments.
- Drive and complete Information Security Assessments assigned to MRO by its clients.
- Manage and support Information Security Risk Management Lifecycle across MRO.
- Ensure appropriate treatment of risk, compliance, and assurance from internal and external perspective.
- Own and drive the Information Security Incident Management Program at MRO.
- Lead and coordinate HITRUST readiness and validated assessments and SOC 2 Type II examinations from planning through report issuance, including scope definition, control-owner coordination, evidence collection and quality review, walkthroughs, sampling support, auditor requests, exception management, remediation tracking, and leadership status reporting.
- Use Vanta as the primary GRC and audit management platform to configure frameworks and controls, assign control owners, manage policies and documents, monitor automated tests and integrations, collect and map evidence, manage auditor access and requests, track findings, and drive timely remediation through audit completion.
- Maintain a continuously audit-ready control environment by monitoring evidence status, testing results, control performance, open gaps, and remediation commitments across HITRUST and SOC 2 requirements.
- Drive the phishing simulation program at MRO and focus on its continual improvement.
- Drive Business Impact Analysis, Privacy Impact Analysis across MRO to determine and update applicable RTOs and RPOs.
- Design and participate in Business Continuity & Disaster Recovery efforts across MRO.
- Maintain and update security training material and conduct training programs to coach and guide the teams in deploying the policies and processes
- Supporting departments in collecting security specific metrics, conducting analysis and identifying actions for process improvement
- Prepare and circulate weekly, monthly and quarterly reports for the Infosec team and present it to Infosec leadership team.
- Ensure procedures and playbooks for all sub teams within Infosec team is always up to date.
Qualifications
General Skills:
- Flexibility and ability to shift to operational hands-on activities as needed
- Conform to shifting priorities, demands and timelines through analytical and problem-solving capabilities
- Client management experience
- Speed and quality of deliverable is the key
- Excellent communication and presentation skills
Technical/Domain Skills:
- Required: Demonstrated hands-on experience managing at least one complete HITRUST readiness and validated assessment cycle, including scoping, requirement interpretation, evidence validation, assessor coordination, gap remediation, and certification support.
- Required: Demonstrated hands-on experience managing at least one complete SOC 2 Type II examination cycle, including control mapping to the AICPA Trust Services Criteria, observation-period evidence, control-owner coordination, sample requests, auditor inquiries, exceptions, complementary user entity controls, subservice organization considerations, remediation, and report review.
- Required: Demonstrated practical experience using Vanta to execute audits—not solely view dashboards—including framework and control administration, ownership assignments, system integrations and automated tests, policy and document management, evidence mapping and review, auditor collaboration, issue tracking, remediation workflows, and audit-readiness reporting.
- Preferred: Knowledge or work experience with HIPAA, PCI DSS, TX-RAMP, NIST Cybersecurity Framework, and cross-framework control mapping.
Education:
· Bachelor's degree in Engineering or Technology (BE/B.Tech.) or an equivalent degree in a related technical field.
Work Experience (Required):6+ years of information security assurance, GRC, compliance, or audit experience, including direct responsibility for coordinating HITRUST and SOC 2 Type II audits and using Vanta to manage controls, evidence, auditor requests, findings, and remediation.
Total CompensationBase pay is one element of the total compensation package. Eligible employees may also receive an annual cash bonus and have access to a comprehensive benefits offering, including medical, dental, vision, life insurance, and a 401(k) plan.
Salary Range It is not typical for an individual to be hired at or near the top of the range. Individual pay may be influenced by factors such as skills, qualifications, experience, licensure, certifications, geographic location, and internal equity.
Applicant Privacy Notice
Pay Range
USD $104,000.00 - USD $140,000.00 /Yr.Originally posted on Himalayas