FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security and compliance consulting within healthcare environments, with a strong focus on risk assessments, policy development, and technical controls. Proficient in translating complex security requirements into actionable recommendations while maintaining high standards of quality and client communication.
Highest-signal resume keywords
Security And Compliance ConsultingRisk Assessment And Gap AnalysisHITRUST, HIPAA/HITECH, NIST SP 800-53Identity And Access ManagementTechnical Controls Implementation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security AssessmentPolicy DevelopmentIncident ResponseVulnerability ManagementCloud TechnologiesConfiguration ManagementCompliance DocumentationData AnalysisTechnical WritingClient Relationship Management
Soft Skills
Strong Communication SkillsProactive Problem SolvingAttention To DetailTeam CollaborationTime Management
Tools & Technologies
Governance Risk And Compliance (GRC) ToolsCloud Security SolutionsVideo Conferencing ToolsClient-Server ArchitectureVirtualization Technologies
Certifications & Qualifications
HITRUST CCSFPSecurity+CISACRISCCISMCISSPCCISOCAPCIPMCIPP/US
Industry Keywords
Healthcare ComplianceRegulatory EnvironmentInformation SecurityBusiness ContinuityDisaster Recovery
Tech Stack
Tools & technologiesAWSAzureCloudCyber Security
About the role
Key responsibilities & impact- Support security and compliance consulting for cloud-based, hybrid, and on-premises healthcare environments
- Manage assigned priorities and tasks to meet delivery timelines, utilization expectations, and quality standards; raise schedule, scope, resource, or evidence issues early
- Support client SME interviews, workshops, readouts, and status meetings; co-facilitate assigned portions when appropriate
- Assist with developing System Security Plans, configuration management plans, information system security policies, rules of behavior, privacy impact analyses, IT contingency and business continuity plans, and incident response plans
- Support risk assessments, gap analyses, assessment readiness, system security plan development, policy and procedure development, and other consulting services
- Collect, organize, and interpret client information and evidence; map information to applicable requirements; identify compliance and risk implications
- Prepare, update, and quality-check client deliverables, including compliance documentation, reports, policies, procedures, plans, evidence matrices, and workpapers
- Support engagement planning by reviewing contractual requirements, agendas, data requests, action items, schedules, and assigned responsibilities
- Review technology, control evidence, and configurations related to cloud infrastructure, identity and access management, MFA, user access lifecycle, privileged access, access reviews, logging and monitoring, vulnerability management, incident response, endpoint security, and network security
- Support engagements involving business continuity and disaster recovery, incident response, and vendor risk management
- Translate technical requirements and security findings into clear, practical recommendations
- Contribute to reusable tools, templates, workpapers, methodologies, and process improvements
- Participate in internal knowledge sharing, peer review, and constructive feedback activities
- Maintain current knowledge of assigned frameworks, industry practices, and relevant technology and security topics
- Collaborate with project management, quality management, sales, and delivery teams to support customer satisfaction and successful project delivery
- Communicate professionally with clients, project leads, and Coalfire team members through email, video conferencing, and in-person meetings
- Explain technical requirements, evidence needs, control gaps, and recommendations clearly to technical and non-technical audiences
- Build professional relationships with client stakeholders and internal team members
- Document decisions, action items, risks, dependencies, and follow-up requirements accurately
- Use sound judgment, diplomacy, and discretion when working with sensitive client and patient-related information
- Work remotely using computers and video-conferencing tools
- Travel may be required based on engagement needs; up to 25% travel is uncommon
Requirements
What you’ll need- 3+ years of relevant experience in professional IT services, cybersecurity, technology risk, technology compliance, security assessment, or related consulting; 4+ years preferred
- At least 2 years of experience working with one or more security, privacy, risk, or compliance frameworks or regulations, preferably in healthcare or a highly regulated environment
- Bachelor’s degree from a four-year college or university in information technology, computer science, business, risk management, cybersecurity, or a related field; or an equivalent combination of education and work experience
- Experience facilitating or supporting security and compliance audits, risk assessments, gap analyses, advisory engagements, or assessment-readiness activities
- Experience working with healthcare, life-sciences, or other highly regulated environments is preferred
- Experience implementing technical controls or evaluating technology risk is highly valued
- Working knowledge of virtualization and cloud technologies
- Working knowledge of client-server and traditional on-premises architecture
- Working knowledge of identity and access management concepts, including authentication, MFA, least privilege, joiner/mover/leaver processes, privileged access, access reviews, and access-request workflows
- Working knowledge of security operations concepts, including incident response, vulnerability management, security logging and monitoring, endpoint or network security, and remediation tracking
- Familiarity with enterprise technology support processes, system administration, technical support, or help desk operations is preferred
- Familiarity with Governance Risk and Compliance (GRC) tools and information-security-related solutions, tools, and utilities
- Ability to evaluate evidence carefully, identify control or process concerns, and communicate risks and dependencies to an engagement lead
- Ability to support interviews and ask follow-up questions to clarify processes, identify gaps, and support root-cause analysis
- Ability to produce accurate, well-organized, client-ready written work
- Experience with one or more security, privacy, risk, or compliance frameworks is required, including HITRUST, HIPAA/HITECH, NIST SP 800-53, NIST SP 800-30, NIST CSF, ARC-AMPE, BSI C5, ISMAP, or other cloud and healthcare-related frameworks
- Strong written and verbal communication skills
- Strong consulting skills
- Strong personal initiative and ability to manage time, priorities, and deadlines
- High attention to detail and commitment to quality
- Ability to support or co-facilitate meetings and communicate effectively with small or large groups
- Ability to work collaboratively in a team-based delivery model and accept direction and feedback
- Proactive problem solving, adaptability, flexibility, and active learning
- Ability to handle sensitive information professionally and maintain appropriate confidentiality
- Relevant certifications are preferred; examples include HITRUST CCSFP, Security+, CISA, CRISC, CISM, CISSP, CCISO, CAP, CIPM, CIPP/US, CCSK, CCSP, AWS, Azure, or Google Cloud security certifications
- For engagements with a framework-specific credential requirement, the Consultant must hold the applicable credential or obtain it within the timeframe established by the practice
- Candidates without a relevant certification must demonstrate the ability to achieve a manager-prescribed certification within two years
Benefits
Comp & perks- Flexible work model allowing work from home or an office
- Paid parental leave
- Flexible time off
- Certification and training reimbursement
- Digital mental health and wellbeing support membership
- Comprehensive insurance options
- Employee resource groups
- In-person and virtual events
- Annual incentive, commission, and/or recognition programs may be available
- Relevant certifications and framework-specific credentials may be supported or required for client engagements
- Remote work environment
