Position Details:
Job Title: IT Auditor
Location: Detroit, MI (Onsite – Hybrid)
Duration: 12+ Months (C2H)
This is a Hybrid position. Resource will be required to come into the office once a week.
IT Security Specialist
Work Schedule: Required to come onsite at least one day per week.
Engagement Description
The EIS Compliance/Governance Analyst will be responsible for assisting in the execution of security framework compliance and governance activities for a major healthcare payer. The role includes documenting adherence to governance requirements across policies, standards, procedures, controls, compliance, training and awareness programs, and preparing metrics, KPIs, and reporting materials.
Key Responsibilities
• Evaluate the design and operational effectiveness of Business/IT operations against the HITRUST CSF and identify areas for improvement.
• Interview SMEs, examine evidence documentation, analyze findings, and perform testing.
• Learn company functions and processes through process walkthroughs.
• Analyze root causes of issues and provide recommendations for process improvements and risk mitigation based on assessment findings.
• Collaborate with cross-functional teams to mitigate risks and ensure compliance with HITRUST CSF.
• Deliver effective and concise documentation that meets HITRUST quality standards.
• Prepare and provide dashboards, metrics, and reports on performance, issue analysis, and assessment status.
• Utilize GRC tools to manage assessment remediation plans and documentation.
• Serve as a HITRUST subject matter expert.
• Participate in and support audits, assessments, and third-party reviews.
• Support initiatives and projects.
• Build internal relationships to foster teamwork and collaboration.
Top 3 Required Skills/Experience
• 4–5 years of experience in IT Compliance, IT Assessments, and/or IT Audit, with knowledge of Governance, Risk, and Compliance (GRC).
• Knowledge of security and risk frameworks, standards, and best practices, including HITRUST CSF, NIST CSF, ISO/IEC 27001, and COBIT.
• Strong written and verbal communication skills, critical thinking ability, and a self-starter mindset.
Required Skills/Experience
• Ability to tailor communication style to different audiences.
• Experience coordinating and executing the audit lifecycle, including evidence collection, review, observation tracking, management response collection, and auditor communications.
• Strong problem-solving and decision-making abilities.
• Experience testing IT controls across systems, databases, applications, and operating systems.
• Ability to effectively frame and deliver messages based on audience experience and knowledge level.
• Strong critical thinking skills with the ability to develop and implement solutions to workplace challenges.
• Ability to solve problems, handle conflict, and make effective decisions under pressure while maintaining professionalism.
• Strong organizational skills.
• Ability to manage changing priorities and multitask effectively.
• Self-directed with minimal supervision and proactive in seeking guidance when needed.
Preferred Skills/Experience
• Knowledge of Information Technology GCC and Governance, Risk & Compliance principles.
• Experience performing audits and assessments.
• Knowledge of security and risk frameworks such as HITRUST CSF and NIST CSF.
• Strong communication and critical thinking skills with a self-starter approach.
Education & Certifications
• Bachelor's degree preferred but not required.
• Master's degree (MBA, MSIS, MIS, etc.) preferred but not required.
• Five (5) years of combined IT experience, including two (2) years in IT Security.
• Experience in Information Security, IT General Controls, IT Compliance, IT Assessments, and/or IT Audit.
• Professional certifications such as CISSP, CISA, CPA/CA, CISM, or equivalent are preferred but not required.
Founded in 1998 and headquartered in Farmington Hills, MI, Kyyba has a global presence delivering high-quality resources and top-notch recruiting services, enabling businesses to effectively respond to organizational changes and