Job Overview
As our Senior Cyber Security Consultant, you'll guide the design and implementation of secure solutions and services in the cloud, driving the configuration of cloud-based security capabilities that reduce risk to an acceptable level.
You'll make sure stakeholder security requirements are addressed in every aspect of the enterprise architecture – from reference models to segment and cloud solution architectures.
This Senior Cyber Security Consultant combines deep knowledge of cybersecurity frameworks with hands-on experience in governance, risk, and compliance (GRC) operations, and excels at clear communication and high-quality documentation, and actively supports security awareness and responsible HIPAA and HITRUST initiatives.
Key Responsibilities
Security Strategy & Program Development
Compliance & Certifications
Cloud Security (Google Cloud Platform)
Incident Response & Threat Management
Vendor & Client Security
Security Strategy & Program Development
- Develop and implement an enterprise information security program aligned with healthcare industry standards and business objectives.
- Establish and maintain security policies, standards, and procedures across the organization.
- Build and maintain a risk management framework to identify, assess, and mitigate information security risks.
- Report security posture, metrics, and program progress directly to the CEO.
Compliance & Certifications
- Lead and manage HIPAA compliance efforts, including risk assessments, policy development, and workforce training.
- Own the HITRUST certification process — managing assessments, remediation, and ongoing maintenance.
- Oversee SOC 2 readiness and audit support, coordinating with external auditors and internal stakeholders.
- Maintain awareness of evolving regulatory requirements impacting healthcare technology companies.
Cloud Security (Google Cloud Platform)
- Design and enforce security controls within Google Cloud Platform (Google Cloud Platform), including IAM, data encryption, network security, and logging.
- Conduct regular cloud security assessments and ensure configurations align with CIS benchmarks and healthcare compliance requirements.
- Partner with engineering teams to embed security into the software development lifecycle (DevSecOps).
Incident Response & Threat Management
- Develop and maintain an incident response plan; lead response efforts for security events and breaches.
- Monitor the threat landscape for risks relevant to healthcare technology and proactively address vulnerabilities.
- Oversee security awareness training and phishing simulation programs for employees.
Vendor & Client Security
- Review and negotiate security terms in vendor contracts and business associate agreements.
- Serve as the primary security contact for clients and prospects — supporting security questionnaires, audits, and due diligence requests.
- Evaluate third-party vendors for security risk prior to onboarding.
Qualifications
Required
Preferred
Required
- 5+ years of information security experience, with at least 3 years in a healthcare or health IT environment.
- Demonstrated hands-on experience with HIPAA compliance, including risk assessments and policy development.
- Direct experience managing or participating in HITRUST assessments (e1, i1, or r2).
- Experience with SOC 2 Type I or Type II audits.
- Hands-on experience securing workloads in Google Cloud Platform (Google Cloud Platform).
- Strong understanding of security frameworks including NIST CSF, ISO 27001, and CIS Controls.
- Excellent written and verbal communication skills — able to translate technical risk into business terms for executive audiences.
Preferred
- Industry certifications such as CISSP, CISM, HCISPP, CompTIA Security+, or equivalent.
- Experience working with early-stage or growth-stage healthcare technology companies.
- Familiarity with EHR/EMR platforms, HL7/FHIR standards, or healthcare interoperability.
- Experience advising executive leadership or boards on information security strategy.