Infinite Group logo

Sr. Healthcare Cybersecurity Consultant

Hiring from
United States
Work type
Remote
Posted
Sep 30, 2026
Is this job info correct?
Description

IGI Cybersecurity is seeking experienced independent consultants with strong healthcare cybersecurity and HIPAA expertise. The consultant will support client-facing assessments, risk analysis, remediation planning, and ongoing security program advisory engagements for healthcare organizations, business associates, and healthcare technology providers.


This role requires a practical consulting mindset, strong written and verbal communication skills, and the ability to independently guide clients from assessment findings to prioritized security improvements. IGI plans to engage multiple consultants on a project basis. As the practice grows, a contractor may be considered for a future full-time position based on business need, performance, and mutual interest.


Primary Responsibilities

  • Conduct HIPAA gap assessments covering the Security Rule, Breach Notification Rule, Business Associate requirements, Privacy Governance requirements, and applicable proposed Security Rule modernization requirements.
  • Perform HIPAA risk assessments that identify the ePHI environment, evaluate threats and vulnerabilities, assess existing safeguards, and produce prioritized risk registers and treatment recommendations.
  • Deliver combined HIPAA Security Assessments that connect compliance gaps with organizational risks and establish an integrated remediation roadmap.
  • Provide HIPAA-focused security program advisory services, including recurring client meetings, roadmap oversight, risk register maintenance, remediation guidance, and policy and procedure template support.
  • Lead stakeholder interviews, review client documentation and evidence, and clearly communicate findings to technical, operational, and executive audiences.
  • Prepare professional reports, recommendations, and executive presentations that are practical, concise, and defensible.


Requirements

Required Qualifications

  • Significant healthcare cybersecurity experience, including direct work with HIPAA-regulated organizations or business associates.
  • Demonstrated experience conducting HIPAA compliance assessments, HIPAA security risk analyses, or comparable healthcare security consulting engagements.
  • Broad cybersecurity assessment, governance, risk, and compliance experience beyond HIPAA.
  • Ability to lead client interviews and working sessions, exercise sound professional judgment, and manage assigned consulting work independently.
  • Excellent business writing, presentation, facilitation, and executive communication skills.
  • Ability to translate regulatory and technical issues into clear business risks, recommendations, and implementation priorities.

Preferred Experience

  • Experience assessing organizations against HITRUST, CIS Controls, or NIST SP 800-171/CMMC is strongly preferred. Prior experience in vCISO, GRC, or other security program leadership roles is highly desirable.
  • Preferred Certifications
  • Relevant certifications such as HITRUST CCSFP, CISSP, HCISPP, CISM, CRISC, or CISA are preferred. Comparable healthcare security, risk management, audit, or compliance credentials and substantial equivalent experience will also be considered.

Engagement Model

  • 1099 independent contractor relationship
  • Project-based assignments as opportunities arise
  • Flexible workload based on availability and fit
  • Remote work with client meetings conducted virtually unless otherwise scoped


Similar jobs

Apply for this job