All Jobs Vacancy

Senior Cyber Security Consultant

Posted 2 days ago by Arraya Solutions

Job Overview

As our Senior Cyber Security Consultant, you'll guide the design and implementation of secure solutions and services in the cloud, driving the configuration of cloud-based security capabilities that reduce risk to an acceptable level.

You'll make sure stakeholder security requirements are addressed in every aspect of the enterprise architecture – from reference models to segment and cloud solution architectures.

This Senior Cyber Security Consultant combines deep knowledge of cybersecurity frameworks with hands-on experience in governance, risk, and compliance (GRC) operations, and excels at clear communication and high-quality documentation, and actively supports security awareness and responsible HIPAA and HITRUST initiatives.

Key Responsibilities

Security Strategy & Program Development

Compliance & Certifications

Cloud Security (Google Cloud Platform)

Incident Response & Threat Management

Vendor & Client Security

Security Strategy & Program Development

  • Develop and implement an enterprise information security program aligned with healthcare industry standards and business objectives.
  • Establish and maintain security policies, standards, and procedures across the organization.
  • Build and maintain a risk management framework to identify, assess, and mitigate information security risks.
  • Report security posture, metrics, and program progress directly to the CEO.

Compliance & Certifications

  • Lead and manage HIPAA compliance efforts, including risk assessments, policy development, and workforce training.
  • Own the HITRUST certification process — managing assessments, remediation, and ongoing maintenance.
  • Oversee SOC 2 readiness and audit support, coordinating with external auditors and internal stakeholders.
  • Maintain awareness of evolving regulatory requirements impacting healthcare technology companies.

Cloud Security (Google Cloud Platform)

  • Design and enforce security controls within Google Cloud Platform (Google Cloud Platform), including IAM, data encryption, network security, and logging.
  • Conduct regular cloud security assessments and ensure configurations align with CIS benchmarks and healthcare compliance requirements.
  • Partner with engineering teams to embed security into the software development lifecycle (DevSecOps).

Incident Response & Threat Management

  • Develop and maintain an incident response plan; lead response efforts for security events and breaches.
  • Monitor the threat landscape for risks relevant to healthcare technology and proactively address vulnerabilities.
  • Oversee security awareness training and phishing simulation programs for employees.

Vendor & Client Security

  • Review and negotiate security terms in vendor contracts and business associate agreements.
  • Serve as the primary security contact for clients and prospects — supporting security questionnaires, audits, and due diligence requests.
  • Evaluate third-party vendors for security risk prior to onboarding.

Qualifications

Required

Preferred

Required

  • 5+ years of information security experience, with at least 3 years in a healthcare or health IT environment.
  • Demonstrated hands-on experience with HIPAA compliance, including risk assessments and policy development.
  • Direct experience managing or participating in HITRUST assessments (e1, i1, or r2).
  • Experience with SOC 2 Type I or Type II audits.
  • Hands-on experience securing workloads in Google Cloud Platform (Google Cloud Platform).
  • Strong understanding of security frameworks including NIST CSF, ISO 27001, and CIS Controls.
  • Excellent written and verbal communication skills — able to translate technical risk into business terms for executive audiences.

Preferred

  • Industry certifications such as CISSP, CISM, HCISPP, CompTIA Security+, or equivalent.
  • Experience working with early-stage or growth-stage healthcare technology companies.
  • Familiarity with EHR/EMR platforms, HL7/FHIR standards, or healthcare interoperability.
  • Experience advising executive leadership or boards on information security strategy.
Rate:
Not specified
Location:
Remote
IR35 Status:
Not specified
Remote Status:
Remote
Industry:
Cybersecurity
Seniority Level:
Senior

Take-Home Pay

Not Available

Visit calculators for additional details

Create a free account to view the take-home pay for this contract

Share job