ImageTrend Logo

ImageTrend

Information Security Compliance Analyst

Posted 22 Days Ago
In-Office or Remote
Hiring Remotely in Eagan, MN
80K-100K Annually
Entry level
In-Office or Remote
Hiring Remotely in Eagan, MN
80K-100K Annually
Entry level
Supports cybersecurity compliance, governance, and risk management programs across frameworks including NIST 800-53, FedRAMP, GovRAMP, HIPAA, and SOC 2. Responsibilities include maintaining audit documentation, coordinating assessments, testing controls, tracking remediation, managing risk registers and vendor assessments, validating AWS and Azure controls, supporting customer due diligence, and coordinating cross-functional compliance initiatives. The role is fully remote in the United States and requires up to 10% travel.
The summary above was generated by AI

About Us:

ImageTrend, LLC. is dedicated to connecting life’s most important data in the healthcare and emergency response community. We deliver software solutions, data analytics and services for EMS, hospitals, community paramedicine (CP), critical care, fire, and preparedness to enable fully integrated patient-centric healthcare and public safety. Our commitment to innovation, its clients, and providing world-class implementation and support is unsurpassed. Based in Eagan, MN, ImageTrend combines business analysis, creative design and data driven architecture to offer scalable solutions and strategies for today and the future.

Employment at ImageTrend is not just about doing a job; it's about being a part of a community. We are top-notch talent, passionate about making a difference through the work we do together!

Description:

Under the direction of the Director, Information Security, the Information Security Compliance Analyst supports the execution, administration, and continuous improvement of ImageTrend's cybersecurity compliance, governance, and risk management programs. This role is responsible for coordinating and maintaining security compliance programs aligned with frameworks and regulations including NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, and other contractual, customer, and regulatory requirements.

The Information Security Compliance Analyst partners with Information Security, IT, Engineering, Product, Legal, Privacy, and other business stakeholders to support audits, assessments, control documentation, risk management activities, cloud compliance initiatives, remediation efforts, and ongoing audit readiness. This role also supports third-party risk management, customer security due diligence activities, continuous monitoring efforts, and process improvements that strengthen ImageTrend's overall security and compliance program.

What You'll Do:

  • Support the administration, documentation, monitoring, and continuous improvement of ImageTrend's information security compliance, governance, and risk management programs
  • Coordinate and support compliance initiatives aligned with NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, and other applicable customer, contractual, and regulatory requirements
  • Maintain compliance documentation, policies, standards, procedures, control matrices, ownership records, audit artifacts, evidence repositories, and related compliance records to ensure ongoing audit readiness
  • Participate in internal and external audits, assessments, and compliance reviews, including coordinating audit requests, collecting and validating evidence, facilitating stakeholder responses, and supporting audit preparation activities
  • Assess the design and effectiveness of security controls, participate in control testing and reviews, identify improvement opportunities, and track audit findings, corrective actions, and remediation efforts through closure
  • Monitor and track Plans of Action & Milestones (POA&Ms), corrective action plans, security exceptions, compensating controls, risk acceptance documentation, and other remediation activities
  • Assist with security risk assessments, control gap analyses, risk register management, mitigation tracking, and policy and standards development activities
  • Support vendor risk management, third-party security assessments, third-party risk monitoring activities, and external risk assessment platforms
  • Assist with validating, documenting, monitoring, and collecting evidence for compliance-related security controls implemented within AWS and Microsoft Azure environments, including the review of cloud security documentation, configurations, and control implementations against established security frameworks and requirements
  • Collaborate with Information Security, IT, Engineering, Product, Legal, Privacy, and other cross-functional teams to ensure security and compliance requirements are effectively implemented and maintained
  • Coordinate multiple compliance-related projects and initiatives, effectively manage competing priorities, monitor milestones and deliverables, provide status updates, and drive accountability for assigned action items
  • Research emerging cybersecurity, privacy, compliance, regulatory, and cloud security trends, and recommend process improvements that strengthen organizational readiness and operational efficiency
  • Support security awareness initiatives, customer security questionnaires, due diligence requests, continuous monitoring activities, and other security and compliance-related projects as needed
  • Travel to orientation, industry or company events, or other onsite meetings as required
  • Perform additional duties or tasks as assigned

Requirements:

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field, or the equivalent combination of education and relevant experience
  • Proven professional experience in information security, cybersecurity, compliance, audit, governance, risk management, information technology, or a related field, preferably within healthcare technology, SaaS, public sector, or cloud-native environments
  • Experience interpreting and applying information security frameworks, auditing principles, internal controls, compliance processes, and risk management practices, including experience or familiarity with NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, ISO 27001, or similar frameworks
  • Demonstrated ability to evaluate security controls and support cloud compliance requirements within AWS and Microsoft Azure environments
  • Practical experience supporting compliance assessments, control testing, audit preparation, risk assessments, gap analyses, continuous monitoring activities, or related governance, risk, and compliance initiatives
  • Experience utilizing Governance, Risk, and Compliance (GRC) platforms, compliance management tools, vendor risk management processes, or third-party security assessments is preferred
  • Strong organizational, project management, analytical, investigative, research, problem-solving, and documentation skills, with the ability to manage multiple priorities, maintain audit-ready records, and meet deadlines
  • Demonstrated ability to coordinate cross-functional initiatives, influence stakeholders, drive accountability, and successfully manage remediation efforts to completion while working independently and collaboratively in a fast-paced environment
  • Excellent verbal, written, interpersonal, and stakeholder communication skills, with strong attention to detail and a commitment to producing accurate, high-quality documentation
  • Demonstrated experience coordinating audits, compliance assessments, remediation efforts, or governance initiatives across multiple stakeholders
  • Industry certifications such as Security+, SSCP, CGRC (formerly CAP), CISA, CRISC, CCSK, AWS Security Specialty, Azure Security Engineer Associate, or similar credentials are preferred
  • Ability to maintain discretion when handling proprietary and confidential information
  • Enthusiasm for learning and expanding knowledge or skills
  • Strong work ethic, integrity, honesty, collaboration and team orientation
  • Ability to travel as required, up to 10%.

This role can be performed 100% virtually anywhere in the US while following our Remote Work Policy. Deadline to apply is at least 3 days after the posting date listed.

Position Salary Range: The annual base salary range for this full-time role is $80,000- $100,000 USD + bonus + benefits + perks + community gains. Within the range, individual pay is determined by job-related skills, education or training and other relevant qualifications.

ImageTrend is an equal opportunity employer and is committed to providing a workplace free from harassment and discrimination. We celebrate the unique differences of our employees because that is what drives curiosity, innovation, and the success of our business. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, gender identity or expression, age, marital status, veteran status, disability status, pregnancy, parental status, genetic information, political affiliation, or any other status protected by the laws or regulations in the locations where we operate. Accommodations are available for applicants with disabilities.

If you are unable to submit your application because of incompatible assistive technology or a disability, please contact us at 952-469-1589, and ImageTrend will reasonably accommodate qualified individuals with disabilities to the extent required by applicable law.

ImageTrend participates in the Electronic Employment Verification Program (E-Verify) to validate employee Form I-9 documentation. Please visit everify.gov to learn more.

Similar Jobs

20 Minutes Ago
Remote or Hybrid
US
64K-89K Annually
Mid level
64K-89K Annually
Mid level
Information Technology
Develops and implements knowledge management strategies, processes, systems, and tools. Captures and organizes organizational knowledge, analyzes metrics, identifies process efficiencies, and supports automation. Collaborates with business leaders, subject matter experts, and IT teams to improve knowledge sharing and retention. Creates technical documentation, delivers training and workshops, manages initiatives, researches emerging technologies, and promotes adoption of knowledge management practices across managed services teams.
Top Skills: Power BIServicenow
An Hour Ago
In-Office or Remote
USA
139K-232K Annually
Senior level
139K-232K Annually
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Leads health technology assessment, value, and evidence strategy for Pfizer’s genitourinary oncology portfolio. Manages HEOR, real-world evidence, economic models, global value dossiers, registries, and evidence dissemination to support reimbursement and patient access. Partners with global, regional, country, and cross-functional oncology teams, oversees vendors and project teams, and communicates findings through publications and conferences.
An Hour Ago
Remote
2 Locations
177K-294K Annually
Senior level
177K-294K Annually
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Leads Pfizer’s state policy and government relations portfolio across Iowa, Minnesota, and potentially other states. Develops policy positions, analyzes legislative and regulatory developments, drafts advocacy materials, manages lobbying strategies, engages policymakers and trade associations, supervises grassroots and political action programs, coordinates internal and external stakeholders, and manages related budgets and priorities.

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account