RSI Security

HITRUST Consultant

TAC - Remote - Contracted

 Location: 100% Remote
Type: Contractor - Part Time, Project based
Pay: Based on experience, education, geographic location, and market rates.
Travel: None

*** Please ensure you read through the entire job posting and you also understand the work model, expectations, requirements, location, and qualification requirements for this role. ***

About Us:
RSI Security is a leading cybersecurity compliance firm that specializes in providing comprehensive security assessment, advisory, and technical security testing services. We support organizations in navigating the complex cybersecurity landscape, ensuring they achieve and maintain compliance while managing risks effectively.

Position Summary:
The Certified HITRUST CSF Practitioner (CCSFP) Consultant plays a critical role in guiding organizations through HITRUST CSF compliance. This role involves conducting comprehensive readiness assessments, performing gap analyses, and developing detailed remediation plans to enhance security and privacy controls. The consultant assists in implementing security controls, developing policies and procedures, and creating awareness programs to align client organizations with HITRUST CSF standards. Additionally, the consultant supports internal audits and prepares clients for the HITRUST certification process, acting as a liaison to ensure accurate and complete documentation.

Roles & Responsibilities:

  • HITRUST Readiness Assessment: Conduct comprehensive readiness assessments to evaluate an organization's current compliance posture against HITRUST CSF (Common Security Framework) requirements.
  • Gap Analysis and Remediation Planning: Identify gaps in existing security and privacy controls, develop a detailed remediation plan, and provide guidance on how to address these deficiencies to meet HITRUST standards.
  • Implementation of Security Controls: Assist clients in designing, implementing, and optimizing security controls that align with HITRUST CSF to strengthen their overall information security posture.
  • Policy and Procedure Development: Create or refine security policies and procedures to ensure they meet HITRUST CSF requirements and align with the organization’s compliance objectives.
  • Training and Awareness: Provide training and education to client teams about HITRUST requirements, best practices, and processes to maintain compliance and build a culture of security awareness.
  • Internal Audit and Verification Support: Conduct internal audits to prepare clients for official HITRUST validations, providing detailed feedback and recommendations for improvement.
  • Support During HITRUST Certification Process: Act as a liaison and advisor during the official HITRUST certification process, ensuring that all required documentation and evidence are accurately compiled and submitted.

Qualifications:

  • Educational Background: A strong foundation in information security, IT, or a related field. While not always mandatory, a bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a similar field is beneficial.
  • Industry Experience: Relevant work experience in information security, compliance, risk management, or IT auditing. Many CCSFP candidates have several years of professional experience in roles such as security analyst, compliance officer, or IT auditor.
  • HITRUST Training: Completion of the official HITRUST CCSFP training course. This training provides in-depth knowledge about the HITRUST CSF framework, its structure, requirements, and how to apply it in various organizational settings.
  • Understanding of Security Frameworks: Familiarity with common security frameworks and standards such as ISO/IEC 27001, NIST 800-53, HIPAA, and PCI DSS. This knowledge helps in understanding how HITRUST CSF maps to and integrates with these frameworks.
  • Technical and Analytical Skills: Proficiency in assessing and implementing security controls, conducting risk assessments, and analyzing gaps in security and compliance.
  • Certification Exam: Successful completion of the HITRUST CCSFP certification exam, which tests knowledge of the HITRUST CSF framework, its implementation, and related compliance practices.
  • Ongoing Professional Development: While not a qualification for initial certification, maintaining CCSFP certification typically requires continuing education to stay current with HITRUST updates and evolving security and compliance standards.

Our commitment to equity, equal opportunity, inclusion, and diversity is part of our broader commitment to respecting fundamental human rights across our value chain. RSI Security is proud to be an Equal Opportunity Employer. The Company will consider for employment qualified applicants with arrest and conviction records.

Equal Opportunity Employer/Veterans/Disabled

For more information on RSI Security, please visit our website - www.rsisecurity.com or our social media RSI Security LinkedIn. On our career site, you will find some of the key steps you can expect to guide you along the way. 

Apply: HITRUST Consultant
* Required fields
First name*
Last name*
Email address*
Location *
Phone number*
Resume*

Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or paste resume

Paste your resume here or attach resume file

Please acknowledge your understanding and compliance with the following:
1) We ask you to write out answers to evaluate your communication skills.
2) You are able to comply with our requests for written answers and will not leave blank nor write nothing (ex: n/a, -, "see resume", etc.)
3) There are two assessments you must complete as part of our application process. If you meet the qualifications of the role, you will be sent an email with the links to complete these assessments. Keep an eye on your inbox, spam and junk folders and compete in a timely manner.*
Are you legally authorized to work in your current country of residence for any employer?*
Will you now, or in the future, require sponsorship for employment visa status (e.g., H-1B, O-1, F-1, OPT, STEM, E-9, etc.) to work in your current country of residence?*
Are you comfortable accepting a part-time, project based role with 0-20 hours per week expected?*
Are you able to commit 0-20 hours a week to perform successfully?*
If offered the role, what would your anticipated notice period be?*
Have you completed the following certification?:
HITRUST Training: Completion of the official HITRUST CCSFP training course.*
Do you posses a deep understanding of security frameworks such as: ISO/IEC 27001, NIST 800-53, HIPAA, and PCI DSS*
Can you confirm your ability to maintain CCSFP certification, which typically requires continuing education to stay current with HITRUST updates and evolving security and compliance standards?*
Do you hold a current CCSFP certification?*
Is your CCSFP certification demonstrated on your resume?*
Based on what you read in the job description, your geographical location, and your level of experience, what are your salary/hourly pay requirements for this role?*
Have you read through the entire job posting? Do you understand the work model, expectations, requirements, location, compensation, and qualification requirements for this role?*
The following questions are entirely optional.
To comply with government Equal Employment Opportunity and/or Affirmative Action reporting regulations, we are requesting (but NOT requiring) that you enter this personal data. This information will not be used in connection with any employment decisions, and will be used solely as permitted by state and federal law. Your voluntary cooperation would be appreciated. Learn more.
Gender
Race/Ethnicity

Invitation for Job Applicants to Self-Identify as a U.S. Veteran
  • A “disabled veteran” is one of the following:
    • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
    • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Veteran status
I IDENTIFY AS ONE OR MORE OF THE CLASSIFICATIONS OF PROTECTED VETERAN LISTED ABOVE
I AM NOT A PROTECTED VETERAN
I DON’T WISH TO ANSWER

Voluntary Self-Identification of Disability
Voluntary Self-Identification of Disability Form CC-305
OMB Control Number 1250-0005
Expires 04/30/2026
Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Please check one of the boxes below:
YES, I HAVE A DISABILITY, OR HAVE HAD ONE IN THE PAST
NO, I DO NOT HAVE A DISABILITY AND HAVE NOT HAD ONE IN THE PAST
I DO NOT WANT TO ANSWER

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

Name Date
Human Check*