Experienced HITRUST Assessment Manager
Insight Assurance
2d ago
0ManagementArgentinahimalayas
HITRUSTSecurity-Testing-ManagerSenior-Security-Certification-ManagerSenior-Information-Assurance-ManagerIT-Audit-ManagerManager
Job Description
*This is a remote position for candidates in LATAMInsight Assurance is a global audit firm on a mission to transform how organizations achieve cybersecurity and compliance. Founded by former Big 4 (EY) professionals, we deliver next-generation audit services across SOC 2, ISO 27001, PCI DSS, HITRUST, CMMC, and FedRAMP frameworks.We’re not your traditional audit firm — we’re tech-enabled, leveraging compliance automation and advanced collaboration tools to make audits faster, smarter, and more impactful for our clients.Recognized on the Inc. 5000 and Fast 50 lists, Insight Assurance is one of the fastest-growing global audit firms, with 180+ professionals supporting nearly 2,000 clients across the Americas, EMEA, and APAC.JOB PURPOSE The HITRUST Assessment Manageris responsible for leading and managing HITRUST readiness and validated assessment engagements for clients, with a focus on healthcare and other highly regulated industries. This role combines hands-on assessment work with people leadership, overseeing a Panama-based team that supports global clients. It ensures high-quality deliverables, efficient project execution, and a consistent, standards-driven approach aligned with the HITRUST CSF and related frameworks.DUTIES AND RESPONSIBILITIES Engagement Delivery & Client ManagementLead multiple concurrent HITRUST readiness and validated assessment engagements from planning through reporting.Develop and execute assessment plans, including scope, objectives, timelines, and resource allocation.Conduct and oversee comprehensive risk and gap assessments against the HITRUST CSF, including control design and operating effectiveness testing.Review client policies, procedures, technical configurations, and evidence to evaluate conformance with HITRUST CSF, HIPAA, and related regulatory expectations.Develop clear, actionable remediation recommendations and roadmaps to support clients’ certification or recertification efforts.Team Leadership & People ManagementDirectly supervise a team of HITRUST assessors/consultants, including assigning work, providing coaching, and performing performance feedback and periodic evaluations.Review and quality-check team deliverables (workpapers, test results, reports) to ensure alignment with firm methodology and HITRUST requirements.Provide ongoing training, mentoring, and technical guidance to develop the team’s HITRUST, security, and audit capabilities.Help build a positive, collaborative culture that emphasizes quality, client service, and continuous improvement.Methodology, Quality, and Process ImprovementContribute to the design, enhancement, and maintenance of the firm’s HITRUST methodology, templates, and work programs in alignment with the HITRUST Assessment Handbook and Risk Management Handbook.Stay current on HITRUST CSF updates, emerging guidance, and related frameworks (e.g., NIST, ISO 27001, SOC 2, HIPAA) and translate changes into internal procedures and client guidance.Support internal quality assurance reviews and remediation of identified process gaps.Collaborate with cross-functional teams (e.g., SOC, ISO, PCI) to promote consistent, integrated service delivery.Business Support & Practice Development (as applicable)Assist leadership in estimating the level of effort, scoping new engagements, and contributing to proposals and statements of work.Participate in client presentations, onboarding calls, and status meetings.Contribute to thought leadership (e.g., internal training, knowledge articles, or external content) related to HITRUST, cybersecurity, and risk management.SKILLSTechnical SkillsDeep understanding of the HITRUST CSF, assessment types (e.g., e1, i1, r2), and certification lifecycle (readiness, validated assessment, interim assessment, recertification).Strong knowledge of information security and privacy principles, particularly in healthcare or other regulated environments (HIPAA/HITECH, GDPR, NIST 800-53, ISO 27001, SOC 2, PCI, etc.).Experience evaluating and testing administrative, technical, and physical security controls in on-prem, cloud, and hybrid environments (AWS, Azure, GCP).Proficiency with GRC platforms (e.g., Vanta, Drata) and HITRUST tools (e.g., MyCSF) and common productivity tools.Consulting & Management SkillsStrong project management skills: able to manage multiple deadlines, prioritize work, and drive engagements to completion on time and within scope.Excellent written and verbal communication skills in English, with the ability to explain complex technical and regulatory topics to both technical and non-technical audiences.Demonstrated ability to lead and develop teams, including setting expectations, providing feedback, and supporting career growth.Strong analytical and problem-solving skills; able to identify risk, articulate impact, and recommend pragmatic solutions.High level of professionalism, integrity, and client-service orientation.EDUCATIONRequiredBachelor’s degree in Information Systems, Information Technology, Computer
