Cherry Bekaert is a nationally recognized CPA firm with over 75 years of experience providing assurance, tax, and advisory services to our clients. We are seeking a Senior Associate (HITRUST) to join our growing Risk Advisory Services (RAS) practice with location flexibility throughout our footprint or possibly remote for the right resource.
As a key member of the RAS team, you will help organizations strengthen their security and compliance posture by testing and validating HITRUST CSF controls. Your knowledge of industry frameworks, compliance risks, and the HITRUST assurance program will help you provide clients perspective on their risks, advise them on mitigation strategies, and support them in achieving certification. If you are seeking diversity in your engagement work and the opportunity to support clients across a wide array of industries, keep reading.
As a Senior Associate, you will :
- Perform control testing procedures in accordance with the HITRUST CSF and scoring rubric.
- Evaluate evidence for completeness and accuracy against HITRUST illustrated procedures and evaluation elements.
- Document test procedures and conclusions in a manner consistent with HITRUST requirements.
- Assist with readiness assessments, validated assessments, interim procedures, and remediation validation activities.
- Collaborate with team members and managers to ensure the quality of testing, while also working semi-independently on assigned tasks.
- Communicate testing results, findings, and recommendations to engagement leaders and client stakeholders.
- Support project planning, fieldwork, and engagement wrap-up, including the preparation of client deliverables.
Types of projects you can expect :
HITRUST CSF Validated Assessments (e1, i1, and r2)HITRUST readiness assessments and gap analysisEvidence evaluation and testing across implementation, policy, and procedure domainsRisk and compliance assessments aligned to regulatory and industry frameworks (e.g., HIPAA, SOC 2, ISO, PCI)Ongoing advisory support for clients pursuing or maintaining HITRUST certificationWhat you bring to the role :
HITRUST certification (CCSFP required; additional HITRUST credentials a plus)At least 1 year of experience testing HITRUST CSF controls, including assessments accepted by HITRUSTHands-on experience performing implementation-only (e1 / i1) and r2 assessments covering policy, procedure, and implementation testingClear understanding of the HITRUST scoring rubric, sampling requirements, and evaluation methodologyAbility to independently review evidence against HITRUST illustrated procedures and determine compliance with evaluation elementsStrong organizational skills and the ability to work in a deadline-driven environment with attention to detailEffective written and verbal communication skills, with the ability to clearly document procedures and findingsAbility to adapt to rapidly changing environments and work independently while collaborating with the teamAdditional, preferred qualifications :
Bachelor’s degree in Information Systems, Cybersecurity, Accounting, or a related fieldPrior experience working in a consulting, public accounting, or professional services environmentExperience with other compliance frameworks (SOC 2, HIPAA, ISO, PCI)Professional certifications such as CISA, CISSP, CPA, or CIAFamiliarity with data analytics or GRC tools (Excel, PowerBI, MyCSF portal, etc.)What we offer you :
Our shared values that foster inclusion and belonging including uncompromising integrity, collaboration, trust, and mutual respect.The opportunity to innovate and do work that motivates and engages you.A collaborative environment focused on enabling you to further your career growth and continuous professional development.Competitive compensation and a total rewards package that focuses on all aspects of your wellbeing.Flexibility to do impactful work and the time to enjoy your life outside of work.Opportunities to connect and learn from professionals from different backgrounds and with different cultures.About Cherry Bekaert
Cherry Bekaert, ranked among the largest assurance, tax and advisory firms in the U.S., serves clients across industries in all 50 U.S. states and internationally. “Cherry Bekaert” is the brand name under which Cherry Bekaert LLP and Cherry Bekaert Advisory LLC, independently owned entities, provide professional services in an alternative practice structure in accordance with applicable professional standards. Cherry Bekaert LLP is a licensed CPA firm that provides attest services, and Cherry Bekaert Advisory LLC and its subsidiary entities provide business advisory and non-attest services spanning the areas of transaction advisory, risk and accounting advisory, digital solutions, cybersecurity, tax, benefits consulting, and wealth management. For more details, visit cbh.com / disclosure.