Arraya Solutions, a leading National Technology Consulting Firm, is looking for a Senior Cyber Security Consultant to join our customers' team!
We are a culture that embraces change, values family and are actively involved with the community. Our team consists of people with positive attitudes who are interested in growing their knowledge around technology and leaders that are heavily involved in day-to-day activities.
***PLEASE NOTE THIS POSITION WILL BE REMOTE-20 HOURS PER WEEK***
Job Overview
As our Senior Cyber Security Consultant, you'll guide the design and implementation of secure solutions and services in the cloud, driving the configuration of cloud-based security capabilities that reduce risk to an acceptable level. You'll make sure stakeholder security requirements are addressed in every aspect of the enterprise architecture – from reference models to segment and cloud solution architectures.
This Senior Cyber Security Consultant combines deep knowledge of cybersecurity frameworks with hands-on experience in governance, risk, and compliance (GRC) operations, and excels at clear communication and high-quality documentation, and actively supports security awareness and responsible HIPAA and HITRUST initiatives.
Key Responsibilities
Security Strategy & Program Development
- Develop and implement an enterprise information security program aligned with healthcare industry standards and business objectives.
- Establish and maintain security policies, standards, and procedures across the organization.
- Build and maintain a risk management framework to identify, assess, and mitigate information security risks.
- Report security posture, metrics, and program progress directly to the CEO.
Compliance & Certifications
- Lead and manage HIPAA compliance efforts, including risk assessments, policy development, and workforce training.
- Own the HITRUST certification process — managing assessments, remediation, and ongoing maintenance.
- Oversee SOC 2 readiness and audit support, coordinating with external auditors and internal stakeholders.
- Maintain awareness of evolving regulatory requirements impacting healthcare technology companies.
Cloud Security (Google Cloud Platform)
- Design and enforce security controls within Google Cloud Platform (Google Cloud Platform), including IAM, data encryption, network security, and logging.
- Conduct regular cloud security assessments and ensure configurations align with CIS benchmarks and healthcare compliance requirements.
- Partner with engineering teams to embed security into the software development lifecycle (DevSecOps).
Incident Response & Threat Management
- Develop and maintain an incident response plan; lead response efforts for security events and breaches.
- Monitor the threat landscape for risks relevant to healthcare technology and proactively address vulnerabilities.
- Oversee security awareness training and phishing simulation programs for employees.
Vendor & Client Security
- Review and negotiate security terms in vendor contracts and business associate agreements.
- Serve as the primary security contact for clients and prospects — supporting security questionnaires, audits, and due diligence requests.
- Evaluate third-party vendors for security risk prior to onboarding.
Qualifications
Required
- 5+ years of information security experience, with at least 3 years in a healthcare or health IT environment.
- Demonstrated hands-on experience with HIPAA compliance, including risk assessments and policy development.
- Direct experience managing or participating in HITRUST assessments (e1, i1, or r2).
- Experience with SOC 2 Type I or Type II audits.
- Hands-on experience securing workloads in Google Cloud Platform (Google Cloud Platform).
- Strong understanding of security frameworks including NIST CSF, ISO 27001, and CIS Controls.
- Excellent written and verbal communication skills — able to translate technical risk into business terms for executive audiences.
Preferred
- Industry certifications such as CISSP, CISM, HCISPP, CompTIA Security+, or equivalent.
- Experience working with early-stage or growth-stage healthcare technology companies.
- Familiarity with EHR/EMR platforms, HL7/FHIR standards, or healthcare interoperability.
- Experience advising executive leadership or boards on information security strategy.