Senior Consultant, Cyber Risk Advisory Healthcare

5 days ago


Remote, Oregon, United States Coalfire Full time

About Coalfire

Coalfire is on a mission to make the world a safer place by solving our clients' toughest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Denver, Colorado with offices across the U.S. and U.K., and we support clients around the world.

But that's not who we are – that's just what we do.

We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

And we're growing fast.

We're looking for a Senior Consultant to support our Cyber Risk Advisory Team, to be focused on Healthcare Risk / Strategy.

Position Summary

As a Senior Consultant on our Cyber Risk Advisory team, you'll lead distinct portions of large client engagements and entire smaller engagements, assessing the security and compliance of client firms against regulatory and industry requirements and standards, and against security best practice frameworks, Senior Consultants play a key role in designing cybersecurity program transformation activities, possessing a strong understanding of cybersecurity frameworks (program, risk, and controls) and assess client cybersecurity programs against those frameworks. You will conduct and/or lead interviews with client staff, analyze documents, and develop reports for clients, provide quality control and peer review to other members of the delivery staff, and will work closely with Project Managers, Directors, and other Delivery team members to effectively manage project timelines and deliverables.

What You'll Do

  • Leads cybersecurity program diagnostic and advisory efforts including data collection plan preparation, review of technical plans, documentation and evidence, preparation of various surveys and assessment tools, evaluation of procedures, and client interviews.
  • Prepare and review reports of findings and recommendations.
  • Manage priorities, tasks, and hours on projects in conjunction with the project manager and/or Director to deliver on time and within allocated budgets.
  • Ensures quality products and services are delivered on time.
  • Escalates client and project issues to management in a timely manner to inform and engage the necessary resources to address the issue.
  • Provide mentorship to team members in areas including, but not limited to risk and controls assessments, technical control implementation, maturity assessments, and a wide range of remediation activities management programs.
  • Interfaces with clients through entire engagement, interacting will all levels of client organizations. Establish and maintain positive collaborative relationships with clients and stakeholders.
  • Continuous professional development in maintaining industry specific certifications. Maintains strong depth of knowledge in the practice area.
  • Collaborates with project managers, quality management, sales, and other delivery team members to drive customer satisfaction and meet project deliverables.

What You'll Bring

  • At least four plus (4+) years working experience in cyber security, GRC, and cyber related risk management.
  • Bachelor's degree in Business Administration, Computer Science, Information Systems, Engineering or related field, or equivalent combination of education and experience.
  • Strong knowledge and awareness of the latest information risk, security and compliance innovations, trends, challenges, and solutions.
  • Strong knowledge of HIPAA regulatory requirement for healthcare covered entities and business associates
  • Awareness or experience with healthcare business operations, systems, and culture
  • Strong knowledge of cloud transformation and its impact on healthcare, medical device manufactures, and software developers.
  • Experience with AWS, Google, or Microsoft hosting environments for SaaS, PaaS, and IaaS platforms.
  • Deep knowledge of information governance, risk and security standards/frameworks and professional practices (NIST CSF, NIST RMS, NIST controls frameworks such as NIST SP or SP , ISO, CIS Critical Security Controls, ISSA, CSA CMM and FAIR, etc.).
  • Knowledge of the typical enterprise risk and security operational practices.
  • Knowledge of information security related solutions, tools, and utilities.
  • Strong initiative.
  • Strong analytical skills, demonstrated problem solving abilities, and the ability to develop solutions for unique client problems.
  • Strong oral and written communication skills.
  • Ability to travel up to 40%.

Bonus Points

  • CISM, CISSP, CISA, CCSP, or CCSK certification(s).
  • Big Four Advisory/Consulting Experience.
  • DevSec Ops Experience.
  • AWS, Azure, Google Cloud Platform certification(s).
  • OpenFair or related certification, CCBP

Why You'll Want to Join Us

At Coalfire, you'll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you'll work most effectively – whether you're at home or an office.

Regardless of location, you'll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You'll have opportunities to join employee resource groups,

participate in in-person and virtual events, and more. And you'll enjoy competitive perks and benefits to support you and your family, like flexible time off, certification and training reimbursement, and comprehensive insurance options.

#LI-JM3

#LI-Remote



  • Remote, Oregon, United States Origami Risk Full time

    The Sr Account Manager is responsible for identifying opportunities and closingadditional revenue from assigned clients, including upselling and cross-selling of relatedproducts. They are also accountable for client renewal, and retention efforts.Starting base pay for this role is between $89,000 and $109,000. The actual base pay isdependent upon many...


  • Remote, Oregon, United States Liberty Mutual Insurance Full time

    Pay PhilosophyThe typical starting salary range for this role is determined by a number of factors including skills, experience, education, certifications and location. The full salary range for this role reflects the competitive labor market value for all employees in these positions across the national market and provides an opportunity to progress as...


  • Remote, Oregon, United States ServiceNow Full time

    Company DescriptionAt ServiceNow, our technology makes the world work for everyone, and our people make it possible. We move fast because the world can't wait, and we innovate in ways no one else can for our customers and communities. By joining ServiceNow, you are part of an ambitious team of change makers who have a restless curiosity and a drive for...


  • Remote, Oregon, United States FiscalNote Full time

    About the PositionFiscalNote's Business Development team is seeking an experienced Senior Account Executive to drive growth in the supply chain and operational risk markets with our transformative alternative data offerings. Your expertise will be critical in packaging our data solutions and navigating the entire sales process—from initial outreach to...


  • Remote, Oregon, United States FiscalNote Full time

    About the PositionFiscalNote's Business Development team is seeking an experienced Senior Account Executive to drive growth in the supply chain and operational risk markets with our transformative alternative data offerings. Your expertise will be critical in packaging our data solutions and navigating the entire sales process—from initial outreach to...

  • Senior Consultant

    7 days ago


    Remote, Oregon, United States CrossCountry Consulting Full time

    From the beginning, our goal was to establish an advisory firm that stands apart from the rest – one that is grounded in our Core Values and dedicated to creating a positive experience not just for our clients, but for our people too. We firmly believe in the strength of collaboration, enthusiasm, generosity, and perseverance as the driving forces behind...


  • Remote, Oregon, United States Fusion Risk Management Full time

    The RoleFusion's Senior Implementation Consultant plays a key role within our Professional Services team. This role works with clients to analyze, design, and configure supported solutions in the Fusion Framework, built on the cloud platform.This role, which interfaces with clients, project managers, product managers, and developers as you:Respond to and...


  • Remote, Oregon, United States BlueVoyant Full time

    Risk and Compliance Account ManagerLocation: Remote in the United StatesUS Citizenship requiredConquest Cyber, a BlueVoyant Company, understands that our enemies are not simply amateur hackers, but highly motivated, well-funded nation states and criminal organizations. By targeting our nation's defense and critical infrastructure sectors, cyber-attacks...


  • Remote, Oregon, United States SailPoint Full time

    SailPoint is the leading Identity Security product and the only multi-tenant SaaS solution on the market. By harnessing the power of AI and machine learning, SailPoint automates and streamlines the complexity of delivering the right access to the right identities and technology resources at the right time. Delivered at the scale our enterprise customers...


  • Remote, Oregon, United States MetLife Full time

    Description and Requirements Position: Global Head of Insurance Advisory, Insurance Asset management Job Location: Whippany, NJ Setting: Hybrid or in-office Reports to: Senior Managing Director, Head of Insurance Asset Management Travel: 10% The Team You Will Join: MetLife Investment Management Based in Whippany, New Jersey, MetLife Investment...


  • Remote, Oregon, United States Origami Risk Full time

    As the Senior Cloud Solution Architect at Origami Risk, you will play a pivotal role in shaping our cloud strategy and ensuring that our SaaS products and services are built on a robust, scalable, and secure cloud infrastructure. You will lead the development and evolution of Origami's cloud architecture, providing highly scalable solutions to help drive and...

  • DevOps Engineer

    1 month ago


    Remote, Oregon, United States UltraViolet Cyber Full time

    Make a difference here.UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make...


  • Remote, Oregon, United States ServiceNow Full time

    Company DescriptionAt ServiceNow, our technology makes the world work for everyone, and our people make it possible. We move fast because the world can't wait, and we innovate in ways no one else can for our customers and communities. By joining ServiceNow, you are part of an ambitious team of change makers who have a restless curiosity and a drive for...


  • Remote, Oregon, United States Block Full time

    Company DescriptionBlock is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams - People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more - provide support and guidance at the corporate level. They work across business groups...


  • Remote, Oregon, United States Wipfli Full time

    At Wipfli, people countThe way you think makes you different. At Wipfli, we embrace that.Our inclusive culture provides a space for everyone to have a voice. Our growing number of DEI resource groups celebrate diversity and champion awareness throughout Wipfli.We're also focused on helping you achieve success with balance. From hybrid schedules and flexible...


  • Remote, Oregon, United States Immersive Labs Full time

    A product you can believe in. Immersive Labs is the leader in people-centric cyber resilienceWe have an exciting vision for cybersecurity that puts people at the center of cyber. Our cyber resilience SaaS platform is an agile, hands-on solution that helps teams continuously assess, build, and prove cyber capabilities through real-life simulations rather than...


  • Remote, Oregon, United States GE Aerospace Full time

    Job Description SummaryWe are seeking an experienced Senior Staff Cyber Security Engineer to lead our efforts in securing AWS and Azure GovCloud environments. The ideal candidate will possess deep expertise in cloud security, particularly within government frameworks, and will be adept at utilizing Cloud Security Posture Management (CSPM) tools such as Wiz....


  • Remote, Oregon, United States GE Aerospace Full time

    Job Description SummaryWe are seeking an experienced Senior Staff Cyber Security Engineer to lead our efforts in securing AWS and Azure GovCloud environments. The ideal candidate will possess deep expertise in cloud security, particularly within government frameworks, and will be adept at utilizing Cloud Security Posture Management (CSPM) tools such as Wiz....


  • Remote, Oregon, United States Green Dot Corporation Full time

    We're looking for talented professionals, anywhere in the United States, to join us in bringing smart money management and payment solutions to everyone's fingertips.At Green Dot, we are evolving to a new and permanent "Work from Anywhere" model designed to maximize the benefits of remote work, promote and enable a strong culture of performance and...


  • Remote, Oregon, United States Origami Risk Full time

    As a Service Delivery Manager you will support and drive success of individual team members and leading a collaborative approach to achieve group goals. The Service Delivery Manager will help build out a team of Professional Services & Implementations experts to help expand our business within the property & casualty insurance space or risk management, GRC,...