Your browser cookies must be enabled in order to apply for this job. Please contact support@jobscore.com if you need further instruction on how to do that.

Information Security Compliance Analyst

G&A - Legal & Compliance - 19 | Remote in Eagan, MN | Full Time | From $80,000 to $100,000 per year

Job Description

About Us:

ImageTrend, LLC. is dedicated to connecting life’s most important data in the healthcare and emergency response community. We deliver software solutions, data analytics and services for EMS, hospitals, community paramedicine (CP), critical care, fire, and preparedness to enable fully integrated patient-centric healthcare and public safety. Our commitment to innovation, its clients, and providing world-class implementation and support is unsurpassed. Based in Eagan, MN, ImageTrend combines business analysis, creative design and data driven architecture to offer scalable solutions and strategies for today and the future.

Employment at ImageTrend is not just about doing a job; it's about being a part of a community. We are top-notch talent, passionate about making a difference through the work we do together!

Description:

Under the direction of the Director, Information Security, the Information Security Compliance Analyst supports the execution, administration, and continuous improvement of ImageTrend's cybersecurity compliance, governance, and risk management programs. This role is responsible for coordinating and maintaining security compliance programs aligned with frameworks and regulations including NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, and other contractual, customer, and regulatory requirements.

The Information Security Compliance Analyst partners with Information Security, IT, Engineering, Product, Legal, Privacy, and other business stakeholders to support audits, assessments, control documentation, risk management activities, cloud compliance initiatives, remediation efforts, and ongoing audit readiness. This role also supports third-party risk management, customer security due diligence activities, continuous monitoring efforts, and process improvements that strengthen ImageTrend's overall security and compliance program.

What You'll Do:

  • Support the administration, documentation, monitoring, and continuous improvement of ImageTrend's information security compliance, governance, and risk management programs
  • Coordinate and support compliance initiatives aligned with NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, and other applicable customer, contractual, and regulatory requirements
  • Maintain compliance documentation, policies, standards, procedures, control matrices, ownership records, audit artifacts, evidence repositories, and related compliance records to ensure ongoing audit readiness
  • Participate in internal and external audits, assessments, and compliance reviews, including coordinating audit requests, collecting and validating evidence, facilitating stakeholder responses, and supporting audit preparation activities
  • Assess the design and effectiveness of security controls, participate in control testing and reviews, identify improvement opportunities, and track audit findings, corrective actions, and remediation efforts through closure
  • Monitor and track Plans of Action & Milestones (POA&Ms), corrective action plans, security exceptions, compensating controls, risk acceptance documentation, and other remediation activities
  • Assist with security risk assessments, control gap analyses, risk register management, mitigation tracking, and policy and standards development activities
  • Support vendor risk management, third-party security assessments, third-party risk monitoring activities, and external risk assessment platforms
  • Assist with validating, documenting, monitoring, and collecting evidence for compliance-related security controls implemented within AWS and Microsoft Azure environments, including the review of cloud security documentation, configurations, and control implementations against established security frameworks and requirements
  • Collaborate with Information Security, IT, Engineering, Product, Legal, Privacy, and other cross-functional teams to ensure security and compliance requirements are effectively implemented and maintained
  • Coordinate multiple compliance-related projects and initiatives, effectively manage competing priorities, monitor milestones and deliverables, provide status updates, and drive accountability for assigned action items
  • Research emerging cybersecurity, privacy, compliance, regulatory, and cloud security trends, and recommend process improvements that strengthen organizational readiness and operational efficiency
  • Support security awareness initiatives, customer security questionnaires, due diligence requests, continuous monitoring activities, and other security and compliance-related projects as needed
  • Travel to orientation, industry or company events, or other onsite meetings as required
  • Perform additional duties or tasks as assigned

Requirements:

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field, or the equivalent combination of education and relevant experience
  • Proven professional experience in information security, cybersecurity, compliance, audit, governance, risk management, information technology, or a related field, preferably within healthcare technology, SaaS, public sector, or cloud-native environments
  • Experience interpreting and applying information security frameworks, auditing principles, internal controls, compliance processes, and risk management practices, including experience or familiarity with NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, ISO 27001, or similar frameworks
  • Demonstrated ability to evaluate security controls and support cloud compliance requirements within AWS and Microsoft Azure environments
  • Practical experience supporting compliance assessments, control testing, audit preparation, risk assessments, gap analyses, continuous monitoring activities, or related governance, risk, and compliance initiatives
  • Experience utilizing Governance, Risk, and Compliance (GRC) platforms, compliance management tools, vendor risk management processes, or third-party security assessments is preferred
  • Strong organizational, project management, analytical, investigative, research, problem-solving, and documentation skills, with the ability to manage multiple priorities, maintain audit-ready records, and meet deadlines
  • Demonstrated ability to coordinate cross-functional initiatives, influence stakeholders, drive accountability, and successfully manage remediation efforts to completion while working independently and collaboratively in a fast-paced environment
  • Excellent verbal, written, interpersonal, and stakeholder communication skills, with strong attention to detail and a commitment to producing accurate, high-quality documentation
  • Demonstrated experience coordinating audits, compliance assessments, remediation efforts, or governance initiatives across multiple stakeholders
  • Industry certifications such as Security+, SSCP, CGRC (formerly CAP), CISA, CRISC, CCSK, AWS Security Specialty, Azure Security Engineer Associate, or similar credentials are preferred
  • Ability to maintain discretion when handling proprietary and confidential information
  • Enthusiasm for learning and expanding knowledge or skills
  • Strong work ethic, integrity, honesty, collaboration and team orientation
  • Ability to travel as required, up to 10%.

This role can be performed 100% virtually anywhere in the US while following our Remote Work Policy. Deadline to apply is at least 3 days after the posting date listed.

Position Salary Range: The annual base salary range for this full-time role is $80,000- $100,000 USD + bonus + benefits + perks + community gains. Within the range, individual pay is determined by job-related skills, education or training and other relevant qualifications.

ImageTrend is an equal opportunity employer and is committed to providing a workplace free from harassment and discrimination. We celebrate the unique differences of our employees because that is what drives curiosity, innovation, and the success of our business. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, gender identity or expression, age, marital status, veteran status, disability status, pregnancy, parental status, genetic information, political affiliation, or any other status protected by the laws or regulations in the locations where we operate. Accommodations are available for applicants with disabilities.

If you are unable to submit your application because of incompatible assistive technology or a disability, please contact us at 952-469-1589, and ImageTrend will reasonably accommodate qualified individuals with disabilities to the extent required by applicable law.

ImageTrend participates in the Electronic Employment Verification Program (E-Verify) to validate employee Form I-9 documentation. Please visit everify.gov to learn more.