About Coalfire
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.
But that’s not who we are – that’s just what we do.
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.
Position Summary
The Senior Consultant – Healthcare Advisory is an individual contributor responsible for delivering and leading healthcare‑focused governance, risk, compliance, and resilience advisory services under the guidance of Principal Consultants and Directors. This role supports healthcare organizations by conducting assessments, developing documentation, facilitating workshops, and delivering actionable recommendations aligned to healthcare regulatory and cybersecurity requirements.
Senior Consultants are expected to independently execute defined portions of healthcare advisory engagements, apply established methodologies, contribute to high‑quality client deliverables, monitor project health, and budget while continuing to deepen their healthcare domain expertise.
What You'll Do
Healthcare Advisory DeliveryExecute healthcare advisory engagements including Governance, Risk, and Compliance (GRC) assessments, gap analyses, and remediation support.Support and deliver services across Incident Response (IR), Disaster Recovery (DR), Business Impact Analysis (BIA), and Business Continuity Planning (BCP) engagements.Assist with Vendor Risk Management (VRM) and Cybersecurity Supply Chain Risk Management (C‑SCRM) activities for healthcare organizations.Develop and update healthcare specific documentation, including: Policies and procedures, Risk assessment reports, System and program documentation, Plans and playbooksCollect, analyze, and map client provided evidence to healthcare regulatory and framework requirements.Client & Project SupportLead client interviews, workshops, and working sessions with IT, compliance, security, and operational stakeholders.Manage assigned tasks and deliverables to meet project timelines, utilization targets, and quality expectations.Collaborate with Project Managers, Principals, and Directors to support successful engagement execution.Contribute to client presentations and status updates.Quality & Professional DevelopmentEnsure accuracy, consistency, and quality of assigned deliverables.Maintain and grow healthcare regulatory and cybersecurity knowledge.Pursue and maintain relevant certifications aligned to healthcare advisory services.Incorporate feedback from peer review and quality management processes.Contribute to thought leadership, white papers, and blogs to expand technical expertise and support practice level objective.'Travel up to 25–50%, depending on client needs
What You'll Bring
4–6 years of experience in cybersecurity, GRC, compliance, risk management, or related consulting roles.Bachelor’s degree in Information Security, Information Systems, Computer Science, Business, or equivalent experience.Experience supporting or delivering advisory or assessment engagements in healthcare or regulated environments.Working knowledge of healthcare regulations and frameworks, including: HIPAA / HITECH, HITRUST, CMS requirements (as applicable), NIST 800‑series frameworksExperience developing compliance documentation and assessment reports. Familiarity with cloud based and on-premises IT environments.Strong written and verbal communication skills.Ability to clearly document and explain compliance and risk concepts.Strong attention to detail and organizational skills.Ability to manage multiple tasks and deadlines.Consulting mindset with the ability to build trust and credibility with clients.Comfortable working independently while escalating issues appropriatelyThe ability to organize and lead engagement activities while training junior staff on project workflow and both the mechanical and technical aspects of developing project deliverables.Dependent on the framework(s) you will be supporting, you must have one or more of the following:
HITRUST Certified CSF Practitioner (CCSFP) – for healthcare focusFedRAMP related certifications (if applicable)CompTIA Security + certification or equivalent work experienceCompTIA Network + certification or equivalent work experience
Bonus Points
CISA, CISM, CISSPCIPP/USCloud certifications (AWS, Azure, GCP)
Why You’ll Want to Join Us
At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.
Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at
HumanResourcesMB@coalfire.com.