Senior Consultant, HITRUST

Job Locations US-Remote | US-CO-Westminster | US-GA-Alpharetta | US-VA-Reston
Regular Full-Time

About Coalfire

Leading cloud infrastructure providers, SaaS providers, and enterprises turn to Coalfire for help solving their toughest cybersecurity problems. Through the combination of extensive cloud expertise, technology, and innovative and holistic approaches, Coalfire empowers clients to achieve their business objectives, use security and compliance to their advantage, and fuel their continued success. Coalfire has been a cybersecurity thought leader for 20 years and has offices throughout the United States and Europe.

What you'll do

The Senior Consultant will work as part of a team assessing the security and compliance of client firms against regulatory and industry requirements and standards, and against security best practice frameworks. This role will have an expert understanding of framework requirements, perform audit/assessments, and develop reports for clients. They will work closely with Project Managers, Directors and other Delivery team members to effectively manage project timelines and deliverables


A Senior Consultant at Coalfire will help enhance our clients’ security posture, working with a wide range of clients to ensure that business and customer data is protected. This role will evaluate the design and effectiveness of technology controls throughout the business cycle and will help identify performance improvement opportunities. As a senior member of the team, this role will also be responsible for enhancing engagement methodology, improving internal processes and overseeing and reviewing the work of Associates and Consultants.


This role facilitates Security Control Assessments and other advanced-level monitoring activities, often within cloud-based environments. To succeed, he/she will need a strong understanding of technical and non-technical security related system controls and an understanding of the various testing methods utilized to ascertain the effectiveness of those controls. The role works in a team atmosphere with an experienced Technical Project Lead, and is assigned technical sections and expected to create client-ready deliverables.


  • Leads audits/assessments including audit plan preparation, review of documentation and evidence, evaluation of procedures, and client interviews.
  • Maintains strong depth of knowledge in one or more cybersecurity frameworks.
  • Prepare, review and approve assessment reports.
  • Manage priorities, tasks and hours on projects in conjunction with the project manager to achieve delivery utilization targets.
  • Ensures quality products and services are delivered on time.
  • Escalates client and project issues to management in a timely manner to inform and engage the necessary resources to address the issue
  • Provide mentorship to team members in areas of audit, assessment, technical review and writing.
  • Interfaces with clients through entire engagement, interacting with all levels of client organizations
  • Establish and maintain positive collaborative relationships with clients and stakeholders
  • Continuous professional development in maintaining industry specific certifications. Maintains strong depth of knowledge in the practice area.
  • Collaborates with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.
  • Establishes account relationships and identifies upsell and cross sell opportunities and escalates to sales.
  • Draft audit programs that sufficiently address both the required objectives of the regulatory body and the complexity of the client environment
  • Leads interview and inquiry walkthroughs with clients to determine the conformity of environments against stated requirements
  • Assess security vulnerabilities against the appropriate security frameworks
  • Pursues and corroborates conclusions derived from inquiry procedures with client while ensuring diligent interview notes are captured
  • Offline and remote evidence inspection of client provided documentation; appropriately mark artifacts requiring follow-up or additional clarification
  • Educate and interpret compliance activities for clients
  • Understands how to apply quality standards and adheres to a minimum benchmark for quality assurance throughout the documentation of each work product or deliverable
  • Provides advice to customers on issues affecting the scope of work in a manner that provides additional value
  • Develop documentation and author recommendations associate with your findings on how to improve the customer’s security posture in accordance with appropriate controls

What you'll bring

  • The ability to evaluate the design and effectiveness of technology controls throughout the business cycle
  • Demonstrated ability to structure and lead projects successfully
  • Strong written and verbal communication skills, with the ability to communicate succinctly and instill confidence with internal stakeholders and external customers
  • Excellent Consulting skills: ability to advise and challenge the status quo while building strong relationships
  • Ability to build high-trust relationships, rapport and credibility quickly
  • Strong personal initiative to appropriately manage time, and manage time of others, to meet deadlines
  • Ability to shift focus frequently while maintaining excellent quality
  • Skill and will to train and mentor junior staff
  • Computer and typing skills that permit rapid data collection and note taking
  • Ability to facilitate meetings to small or large groups
  • Public speaking and executive presence that solicits attention
  • Inquisitive and curious nature with the ability to effectively probe for deeper information
  • Diplomatic and broad minded
  • Strong technical researcher
  • Expertise in security frameworks and regulatory requirements (such as SOC 2, ISO, NIST, COBIT, HIPAA/HITECH, HITRUST or PCI)
  • Experience working with technologies hosted via cloud computing environments (e.g., Amazon Web Services, Microsoft Azure, Google Cloud Platform
  • Bachelor's degree (four-year college or university) or equivalent combination of education and work experience. Degree preferably in Information Systems, CIS, MIS or IT

Bonus Points

  • AWS Solution Architect or other CSP certification
  • At least one information security certification, such as CISSP, CISA, or CIA (or willing to obtain one of these certifications)

Why you'll want to join us

Our people make Coalfire great. We work together on interesting things and achieve exceptional results. We act as trusted advisors to our customers and are committed to client-focused innovation as well as innovation in the industries that we serve. Coalfire offers our people the chance to grow professionally with colleagues they like and respect while tackling challenges that stretch their minds and expand their skill sets. We’re connected by our desire to innovate and our goal of helping to make the world a more secure place. 


Coalfire’s high energy, challenging, and fast-paced work environment will keep you engaged and motivated. Work-life balance is a core priority at Coalfire – we work hard and we play hard, and the two often overlap. We host family-friendly events and happy hours along with professional meetups and informal networking sessions, and we’re active in our communities. Plus, we offer great benefits, including:


  • Health, dental, and vision insurance with an employer contribution
  • Flexible paid time off (employees are encouraged to spend four weeks away from the office each year)
  • A generous 401(k) plan
  • Stock Appreciation Rights (SARs)
  • A corporate wellness program
  • Tuition reimbursement
  • A kitchen stocked with snacks, coffee, and tasty beverages


Coalfire is an EEO employer. We celebrate diversity and are committed to respecting one another, embracing individual differences, and creating an inclusive environment for all employees.

At Coalfire, equal opportunity and pay equity is integral to the way we do business. A reasonable estimate of the compensation range for this role is $86,000 to $148,000 based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs.





Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed

Need help finding the right job?

We can recommend jobs specifically for you! Click here to get started.