All roles

IT Security & Compliance Specialist

Remote · USA Full-time New today

Information Technology Compliance Manager Chisholm Chisholm & Kilpatrick (CCK) is a nationally recognized law firm committed to providing exceptional client service in the areas of Veterans Law, ERISA law, and Bequest Management. CCK is seeking an Information Security & Compliance Specialist to lead our information security and compliance program. The ISS will be responsible for developing, implementing, and overseeing policies and controls that ensure compliance with HIPAA data security requirements and SOC 2 Type II audit certification. This position requires both strategic thinking and hands-on execution, with strong cross-functional collaboration across IT, legal, operations, and client-facing teams.

Key Responsibilities

  • Policy & Program Management: Develop and maintain the firm’s Information Security Management Program (ISMP); Establish and enforce data governance and cybersecurity policies in accordance with HIPAA, SOC 2, and relevant state laws; Own documentation of controls, risk assessments, audit responses, and security-related protocols.
  • Compliance & Risk Management: Lead regular risk assessments and threat modeling initiatives; Manage the SOC 2 Type II audit process, partnering with third-party auditors and internal stakeholders; Oversee HIPAA compliance, including breach notification protocols, security risk analysis, and access control.
  • Security Operations: Monitor cloud platforms, email, file sharing, and endpoints for data security compliance; Implement and maintain tools such as SIEM, MFA, and endpoint protection solutions; Evaluate third-party vendors for security posture and compliance alignment; Deliver firm-wide HIPAA security training and ongoing security awareness initiatives; Foster a culture of compliance through education and stakeholder engagement; Respond to incidents as needed, including triage, containment, and remediation support; Maintain up-to-date knowledge of industry trends, emerging threats, and best practices. Job Requirements
  • Bachelor’s degree in information security, Computer Science, or a related field (Master’s preferred).
  • Minimum 5 years of experience in an information security role, preferably within a highly regulated environment.
  • Deep understanding of state data security laws and regulations, HIPAA data security requirements and experience preparing for or managing SOC 2 Type II audits.
  • Familiarity with NIST, ISO 27001, or COBIT frameworks.
  • Experience with security tools (SIEM, endpoint protection, DLP, MFA, etc.).
  • Experience with the incident response life cycle.
  • Excellent communication skills and ability to work with legal, technical staff and non-technical staff. Preferred Certifications
  • Certified Information Security Manager (CISM)
  • Certified HIPAA Security Professional (CHSP) or equivalent
  • SOC 2 implementation or auditing experience
  • Competitive salary based on experience
  • CCK offers options for medical, dental, and vision insurance (including employer-paid medical insurance for the employee!) and other wellness benefits
  • Gym membership reimbursement
  • 15 days of PTO which increase to 20 days of PTO after 1 year plus 12 paid company holidays in 2025
  • 35 Work from Home Days per year that can be used for any reason
  • 401k matching Seniority level
  • Mid-Senior level Employment type
  • Full-time Job function
  • Information Technology
  • Industries: Legal Services Referrals increase your chances of interviewing at KLR Executive Search Group LLC by 2x Inferred from the description for this job Medical insurance Vision insurance 401(k) Apply BELOW Apply tot his job

Apply tot his job Apply To this Job

Related roles

Security & Compliance Specialist

Remote · USA Full-time

Cybersecurity Compliance Consultant

Remote · USA Full-time

Cybersecurity Compliance Officer – Remote

Remote · USA Full-time

Compliance Specialist / Cloud ISSO

Remote · USA Full-time

Technology Compliance Specialist

Remote · USA Full-time

Senior Cyber Security Compliance Officer

Remote · USA Full-time

Cyber Security Consulting Lead | Sun Prairie, WI, USA | Remote

Remote · USA Full-time

Cyber Security Consultant /Remote/ US/

Remote · USA Full-time

Remote Cybersecurity Director

Remote · USA Full-time

Cybersecurity Director

Remote · USA Full-time

Experienced Data Entry Professional – Remote Work Opportunity with Comprehensive Training and Career Growth Prospects at blithequark

Remote · USA Full-time

Netflix Content Tagger Remote

Remote · USA Full-time

Quality Assurance Engineer

Remote · USA Full-time

Looking for AI Architect || Plano, TX (Permanent remote work accepted from anywhere in US)

Remote · USA Full-time

Immediately Require Online English Teacher (100% Remote) in Phoenix, AZ

Remote · USA Full-time

Senior Cyber Security Ops Analyst | Remote | Contract

Remote · USA Full-time

Project Manager

Remote · USA Full-time

Experienced Customer Service and Call Center Representative for Emergency Alarm Monitoring Services - Full-Time Position with Opportunities for Remote Work and Professional Growth

Remote · USA Full-time

Junior Engineer, RT 5G Stack

Remote · USA Full-time

Graduate Engineer - Diagnostics

Remote · USA Full-time