Information Security Compliance Analyst
Job Summary
About Us:
ImageTrend LLC. is dedicated to connecting lifes most important data in the healthcare and emergency response community. We deliver software solutions data analytics and services for EMS hospitals community paramedicine (CP) critical care fire and preparedness to enable fully integrated patient-centric healthcare and public safety. Our commitment to innovation its clients and providing world-class implementation and support is unsurpassed. Based in Eagan MN ImageTrend combines business analysis creative design and data driven architecture to offer scalable solutions and strategies for today and the future.
Employment at ImageTrend is not just about doing a job; its about being a part of a community. We are top-notch talent passionate about making a difference through the work we do together!
Description:
Under the direction of the Director Information Security the Information Security Compliance Analyst supports the execution administration and continuous improvement of ImageTrends cybersecurity compliance governance and risk management programs. This role is responsible for coordinating and maintaining security compliance programs aligned with frameworks and regulations including NIST 800-53 FedRAMP GovRAMP HIPAA SOC 2 and other contractual customer and regulatory requirements.
The Information Security Compliance Analyst partners with Information Security IT Engineering Product Legal Privacy and other business stakeholders to support audits assessments control documentation risk management activities cloud compliance initiatives remediation efforts and ongoing audit readiness. This role also supports third-party risk management customer security due diligence activities continuous monitoring efforts and process improvements that strengthen ImageTrends overall security and compliance program.
What Youll Do:
- Support the administration documentation monitoring and continuous improvement of ImageTrends information security compliance governance and risk management programs
- Coordinate and support compliance initiatives aligned with NIST 800-53 FedRAMP GovRAMP HIPAA SOC 2 and other applicable customer contractual and regulatory requirements
- Maintain compliance documentation policies standards procedures control matrices ownership records audit artifacts evidence repositories and related compliance records to ensure ongoing audit readiness
- Participate in internal and external audits assessments and compliance reviews including coordinating audit requests collecting and validating evidence facilitating stakeholder responses and supporting audit preparation activities
- Assess the design and effectiveness of security controls participate in control testing and reviews identify improvement opportunities and track audit findings corrective actions and remediation efforts through closure
- Monitor and track Plans of Action & Milestones (POA&Ms) corrective action plans security exceptions compensating controls risk acceptance documentation and other remediation activities
- Assist with security risk assessments control gap analyses risk register management mitigation tracking and policy and standards development activities
- Support vendor risk management third-party security assessments third-party risk monitoring activities and external risk assessment platforms
- Assist with validating documenting monitoring and collecting evidence for compliance-related security controls implemented within AWS and Microsoft Azure environments including the review of cloud security documentation configurations and control implementations against established security frameworks and requirements
- Collaborate with Information Security IT Engineering Product Legal Privacy and other cross-functional teams to ensure security and compliance requirements are effectively implemented and maintained
- Coordinate multiple compliance-related projects and initiatives effectively manage competing priorities monitor milestones and deliverables provide status updates and drive accountability for assigned action items
- Research emerging cybersecurity privacy compliance regulatory and cloud security trends and recommend process improvements that strengthen organizational readiness and operational efficiency
- Support security awareness initiatives customer security questionnaires due diligence requests continuous monitoring activities and other security and compliance-related projects as needed
- Travel to orientation industry or company events or other onsite meetings as required
- Perform additional duties or tasks as assigned
Requirements:
- Bachelors degree in Information Security Cybersecurity Information Technology Information Systems Risk Management Business or a related field or the equivalent combination of education and relevant experience
- Proven professional experience in information security cybersecurity compliance audit governance risk management information technology or a related field preferably within healthcare technology SaaS public sector or cloud-native environments
- Experience interpreting and applying information security frameworks auditing principles internal controls compliance processes and risk management practices including experience or familiarity with NIST 800-53 FedRAMP GovRAMP HIPAA SOC 2 ISO 27001 or similar frameworks
- Demonstrated ability to evaluate security controls and support cloud compliance requirements within AWS and Microsoft Azure environments
- Practical experience supporting compliance assessments control testing audit preparation risk assessments gap analyses continuous monitoring activities or related governance risk and compliance initiatives
- Experience utilizing Governance Risk and Compliance (GRC) platforms compliance management tools vendor risk management processes or third-party security assessments is preferred
- Strong organizational project management analytical investigative research problem-solving and documentation skills with the ability to manage multiple priorities maintain audit-ready records and meet deadlines
- Demonstrated ability to coordinate cross-functional initiatives influence stakeholders drive accountability and successfully manage remediation efforts to completion while working independently and collaboratively in a fast-paced environment
- Excellent verbal written interpersonal and stakeholder communication skills with strong attention to detail and a commitment to producing accurate high-quality documentation
- Demonstrated experience coordinating audits compliance assessments remediation efforts or governance initiatives across multiple stakeholders
- Industry certifications such as Security SSCP CGRC (formerly CAP) CISA CRISC CCSK AWS Security Specialty Azure Security Engineer Associate or similar credentials are preferred
- Ability to maintain discretion when handling proprietary and confidential information
- Enthusiasm for learning and expanding knowledge or skills
- Strong work ethic integrity honesty collaboration and team orientation
- Ability to travel as required up to 10%.
This role can be performed 100% virtually anywhere in the US while following our Remote Work Policy. Deadline to apply is at least 3 days after the posting date listed.
Position Salary Range: The annual base salary range for this full-time role is $80000- $100000 USD bonus benefits perks community gains. Within the range individual pay is determined by job-related skills education or training and other relevant qualifications.
ImageTrend is an equal opportunity employer and is committed to providing a workplace free from harassment and discrimination. We celebrate the unique differences of our employees because that is what drives curiosity innovation and the success of our business. We do not discriminate on the basis of race religion color national origin gender sexual orientation gender identity or expression age marital status veteran status disability status pregnancy parental status genetic information political affiliation or any other status protected by the laws or regulations in the locations where we operate. Accommodations are available for applicants with disabilities.
If you are unable to submit your application because of incompatible assistive technology or a disability please contact us at and ImageTrend will reasonably accommodate qualified individuals with disabilities to the extent required by applicable law.
ImageTrend participates in the Electronic Employment Verification Program (E-Verify) to validate employee Form I-9 documentation. Please visit to learn more.
Required Experience:
IC
About Company
ImageTrend turns emergency response data into actionable intelligence, empowering fire, EMS, and hospitals to improve operations, strategies, and outcomes.