Summary
Coalfire is a cybersecurity company that helps clients solve complex cybersecurity challenges and navigate evolving security requirements. The Healthcare Advisory Consultant supports healthcare and life-sciences client engagements by evaluating security and compliance controls, developing documentation, analyzing evidence, facilitating client interactions, and preparing practical recommendations and reports.
Responsibilities
- Support security and compliance consulting for cloud-based, hybrid, and on-premises healthcare environments in accordance with applicable requirements and guidance, including ARC-AMPE, NIST SP 800-53, NIST SP 800-30, HITRUST, HIPAA, and emerging healthcare standards and frameworks
- Manage assigned priorities and tasks to meet delivery timelines, utilization expectations, and quality standards; raise schedule, scope, resource, or evidence issues early
- Support client SME interviews, workshops, readouts, and status meetings; co-facilitate assigned portions of sessions when appropriate
- Assist with the development of System Security Plans, configuration management plans, information system security policies, rules of behavior, privacy impact analyses, IT contingency and business continuity plans, incident response plans, , as applicable to the engagement
- Support advisory projects, including risk assessments, gap analyses, assessment readiness, system security plan development, policy and procedure development, and other consulting services
- Collect, organize, and interpret client information and evidence; map information to applicable requirements; and identify potential compliance and risk implications for engagement lead review
- Prepare, update, and quality-check client deliverables, including compliance documentation, reports, policies, procedures, plans, evidence matrices, and workpapers
- Support engagement planning by reviewing contractual requirements, agendas, data requests, action items, schedules, and assigned responsibilities
- Review technology, control evidence, and configurations related to cloud infrastructure, identity and access management, MFA, user access lifecycle, privileged access, access reviews, logging and monitoring, vulnerability management, incident response, endpoint security, and network security, as applicable to the engagement
- Support engagements involving business continuity and disaster recovery, incident response, and vendor risk management
- Translate technical requirements and security findings into clear, practical recommendations for review by engagement leads and use with technical and non-technical stakeholders
- Contribute to reusable tools, templates, workpapers, methodologies, and process improvements that increase delivery consistency and efficiency
- Participate in internal knowledge sharing, peer review, and constructive feedback activities appropriate to the role
- Maintain current knowledge of assigned frameworks, industry practices, and relevant technology and security topics
- Collaborate with project management, quality management, sales, and delivery teams to support customer satisfaction and successful project delivery
- Communicate professionally and promptly with clients, project leads, and Coalfire team members through email, video conferencing, and in-person meetings
- Explain technical requirements, evidence needs, control gaps, and recommendations clearly to technical and non-technical audiences
- Build credible, professional relationships with client stakeholders and internal team members
- Document decisions, action items, risks, dependencies, and follow-up requirements accurately
- Use sound judgment, diplomacy, and discretion when working with sensitive client and patient-related information
- Remote work environment, with frequent use of computers and video-conferencing tools
- Travel may be required based on engagement needs. Travel is generally limited, and up to 25% travel is uncommon
Skills
- 3+ years of relevant experience in professional IT services, cybersecurity, technology risk, technology compliance, security assessment, or related consulting
- At least 2 years of experience working with one or more security, privacy, risk, or compliance frameworks or regulations
- Bachelor's degree from a four-year college or university in information technology, computer science, business, risk management, cybersecurity, or a related field; or an equivalent combination of education and work experience
- Experience facilitating or supporting security and compliance audits, risk assessments, gap analyses, advisory engagements, or assessment-readiness activities
- Working knowledge of virtualization and cloud technologies and the ability to recognize common cloud security and architecture-related risks
- Working knowledge of client-server and traditional on-premises architecture
- Working knowledge of identity and access management concepts, including authentication, MFA, least privilege, joiner/mover/leaver processes, privileged access, access reviews, and access-request workflows
- Working knowledge of security operations concepts, including incident response, vulnerability management, security logging and monitoring, endpoint or network security, and remediation tracking
- Equivalent experience assessing technology controls, interviewing IT support teams, or evaluating access and operational evidence is acceptable
- Familiarity with Governance Risk and Compliance (GRC) tools and information-security-related solutions, tools, and utilities
- Demonstrated ability to evaluate evidence carefully, identify control or process concerns, and communicate risks and dependencies to an engagement lead
- Demonstrated ability to support interviews and ask follow-up questions that clarify processes, identify gaps, and support root-cause analysis
- Demonstrated ability to produce accurate, well-organized, client-ready written work
- Experience with one or more of the following is required
- HITRUST
- HIPAA/HITECH
- NIST SP 800-53
- NIST SP 800-30
- NIST CSF
- ARC-AMPE for Medicare and Medicaid-related healthcare advisory work, BSI C5, ISMAP, or other cloud and healthcare-related frameworks
- Applicable privacy, security, and technology regulations across regulated industries
- Strong written and verbal communication skills
- Strong consulting skills, including the ability to ask thoughtful questions, communicate practical recommendations, and build professional relationships
- Strong personal initiative and ability to manage time, priorities, and deadlines
- High attention to detail and commitment to quality
- Ability to support or co-facilitate meetings and communicate effectively with small or large groups
- Ability to work collaboratively in a team-based delivery model and accept direction and feedback
- Proactive problem solving, adaptability, flexibility, and active learning
- Ability to handle sensitive information professionally and maintain appropriate confidentiality
- For engagements with a framework-specific credential requirement, the Consultant must hold the applicable credential or obtain it within the timeframe established by the practice
- Candidates without a relevant certification must demonstrate the ability to achieve a manager-prescribed certification within two years
- 4+ years preferred
- Preferably in healthcare or a highly regulated environment
- Experience working with healthcare, life-sciences, or other highly regulated environments is preferred
- Experience implementing technical controls or evaluating technology risk is highly valued
- Familiarity with enterprise technology support processes, system administration, technical support, or help desk operations is preferred
- Experience with multiple healthcare, security, privacy, or risk frameworks is preferred:
- Relevant certifications are preferred
- HITRUST CCSFP
- Security+, CISA, CRISC, CISM, CISSP, CCISO, CAP, CIPM, or CIPP/US
- CCSK, CCSP, or AWS, Azure, or Google Cloud security certifications
Qualifications
Must Haves
- 3+ years of relevant experience in professional IT services, cybersecurity, technology risk, technology compliance, security assessment, or related consulting
- At least 2 years of experience working with one or more security, privacy, risk, or compliance frameworks or regulations
- Bachelor's degree from a four-year college or university in information technology, computer science, business, risk management, cybersecurity, or a related field; or an equivalent combination of education and work experience
- Experience facilitating or supporting security and compliance audits, risk assessments, gap analyses, advisory engagements, or assessment-readiness activities
- Working knowledge of virtualization and cloud technologies and the ability to recognize common cloud security and architecture-related risks
- Working knowledge of client-server and traditional on-premises architecture
- Working knowledge of identity and access management concepts, including authentication, MFA, least privilege, joiner/mover/leaver processes, privileged access, access reviews, and access-request workflows
- Working knowledge of security operations concepts, including incident response, vulnerability management, security logging and monitoring, endpoint or network security, and remediation tracking
- Equivalent experience assessing technology controls, interviewing IT support teams, or evaluating access and operational evidence is acceptable
- Familiarity with Governance Risk and Compliance (GRC) tools and information-security-related solutions, tools, and utilities
- Demonstrated ability to evaluate evidence carefully, identify control or process concerns, and communicate risks and dependencies to an engagement lead
- Demonstrated ability to support interviews and ask follow-up questions that clarify processes, identify gaps, and support root-cause analysis
- Demonstrated ability to produce accurate, well-organized, client-ready written work
- experience with one or more of the following is required
- HITRUST
- HIPAA/HITECH
- NIST SP 800-53
- NIST SP 800-30
- NIST CSF
- ARC-AMPE for Medicare and Medicaid-related healthcare advisory work, BSI C5, ISMAP, or other cloud and healthcare-related frameworks
- Applicable privacy, security, and technology regulations across regulated industries
- Strong written and verbal communication skills
- Strong consulting skills, including the ability to ask thoughtful questions, communicate practical recommendations, and build professional relationships
- Strong personal initiative and ability to manage time, priorities, and deadlines
- High attention to detail and commitment to quality
- Ability to support or co-facilitate meetings and communicate effectively with small or large groups
- Ability to work collaboratively in a team-based delivery model and accept direction and feedback
- Proactive problem solving, adaptability, flexibility, and active learning
- Ability to handle sensitive information professionally and maintain appropriate confidentiality
- For engagements with a framework-specific credential requirement, the Consultant must hold the applicable credential or obtain it within the timeframe established by the practice
- Candidates without a relevant certification must demonstrate the ability to achieve a manager-prescribed certification within two years
Nice to Haves
- 4+ years preferred
- preferably in healthcare or a highly regulated environment
- experience working with healthcare, life-sciences, or other highly regulated environments is preferred
- experience implementing technical controls or evaluating technology risk is highly valued
- Familiarity with enterprise technology support processes, system administration, technical support, or help desk operations is preferred
- experience with multiple healthcare, security, privacy, or risk frameworks is preferred:
- Relevant certifications are preferred
- HITRUST CCSFP
- Security+, CISA, CRISC, CISM, CISSP, CCISO, CAP, CIPM, or CIPP/US
- CCSK, CCSP, or AWS, Azure, or Google Cloud security certifications
Benefits
- Flexible work model, in many cases, empowering employees to choose when and where they’ll work most effectively, whether at home or an office.
- Opportunities to join employee resource groups.
- Participation in in-person and virtual events.
- Paid parental leave.
- Flexible time off.
- Certification and training reimbursement.
- Digital mental health and wellbeing support membership.
- Comprehensive insurance options.