Security Compliance Advisor
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 28, 2026
Job Summary
Under the general direction of the Manager, Risk Assessment, the Security Compliance Advisor is responsible for providing security/compliance assessment and consulting services to Fortified’s clients. This position requires a working knowledge of information security frameworks, standards, laws, regulations, and protocols. The role includes responsibilities in project management, information security assessment, and client consulting on all matters related to the maturity of a client’s information security program and how the program ensures the protection of patient information.
Essential Job Functions
The following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required.
-
Support assigned client projects with clear communication to set and manage client expectations and deliver assessment outputs in a timely manner.
-
Provide high-quality, professional, and consultative support when engaging with clients to ensure the best possible client experience and outcome.
-
Evaluate evidence artifacts submitted by clients to validate alignment and compliance with selected industry security frameworks and regulatory requirements.
-
Interview and work with clients onsite at their location using Fortified’s defined risk assessment methodology.
-
Perform physical site assessments of client facilities to evaluate how PHI/ePHI is handled and secured by client personnel.
-
Develop or provide guidance on client information security, information security-adjacent, and/or compliance policies and processes.
-
Present findings and recommendations to both technical and executive client stakeholders.
-
Develop Corrective Action Plans (CAPs) for clients to use when remediating identified risks following the completion of a risk assessment.
-
Facilitate regularly scheduled CAP meetings with clients to support remediation prioritization and follow-through; provide insight into how immature areas of the client’s information security program could be improved and supported by Fortified, when relevant.
-
Contribute to enhancing current services or developing new client offerings with leadership input and guidance.
-
Knowledge & Skills
Education & Experience
-
Bachelor's degree in Cybersecurity, Information Systems, or similar field is required.
-
Minimum of 5 years of experience in information security consulting, risk assessments and evaluation, and program governance is required.
-
An understanding of and experience applying the HIPAA Security Rule and the NIST Cybersecurity Framework (versions 1.1 and 2.0) against organizational controls is required.
-
Experience with creating and/or managing a risk management program on behalf of an organization is required; experience should include corrective action plan development to support risk mitigation and/or remediation.
-
Experience with cybersecurity disruption plan (i.e., Business Continuity Plan, Disaster Recovery Plan, Incident Response Plan) creation and maintenance required.
-
Experience with supporting information security programs within a healthcare environment is preferred.
-
An understanding of and experience applying frameworks and best practices including ISO27001/27002, COBIT, PCI-DSS, STIGs, and/or CIS is preferred.
-
Experience with creating and/or maintaining a workforce information security training program preferred.
-
Experience with measuring organizational risk tolerance and using this understanding to develop strategies to satisfy a client’s defined exposure threshold is preferred.
Special Skills & Knowledge
-
Strong written and verbal communication skills are required.
-
Experience in creating client-facing deliverables and reports in a consulting environment is required.
-
Proven ability to multitask, prioritize, and manage time effectively in a remote setting is required.
-
Highly motivated self-starter with a drive to deliver excellence in all tasks is required.
-
Working, high-level knowledge of system outputs and/or configurations from various technologies including vulnerability scanners, endpoint protection solutions, asset management platforms, and Active Directory/Entra is required.
-
Working knowledge of International, Federal, and State regulatory and compliance requirements including the HIPAA Privacy Rule, GDPR, and SOX is preferred.
-
Working knowledge of current industry threats and vulnerabilities alongside the techniques employed by organizations to manage these emerging threats is preferred.
Licenses, Certifications, etc.
-
Security certifications such as the CISSP, CISM, CCSP, and CISA are preferred.
-
Healthcare certifications such as the CHP and CHPS are preferred.
-
Requirements
Working Conditions & Travel Requirements
-
Travel as required, up to 25%.
-
A valid driver's license is required.
-
A quiet, professional workspace with a reliable high-speed internet connection is required.
Fortified Health Security is an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, Fortified Health Security will provide reasonable accommodations to qualified individuals with disabilities. If a reasonable accommodation is needed to perform this position, you need to inform Fortified Health Security People and Culture Team of such request. Signatures below indicate the receipt and review of this job description by the associate assigned to the position and the People and Culture Team.