Information Security Compliance Analyst

ImageTrendEagan, MN
Remote

About The Position

Under the direction of the Director, Information Security, the Information Security Compliance Analyst supports the execution, administration, and continuous improvement of ImageTrend's cybersecurity compliance, governance, and risk management programs. This role is responsible for coordinating and maintaining security compliance programs aligned with frameworks and regulations including NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, and other contractual, customer, and regulatory requirements. The Information Security Compliance Analyst partners with Information Security, IT, Engineering, Product, Legal, Privacy, and other business stakeholders to support audits, assessments, control documentation, risk management activities, cloud compliance initiatives, remediation efforts, and ongoing audit readiness. This role also supports third-party risk management, customer security due diligence activities, continuous monitoring efforts, and process improvements that strengthen ImageTrend's overall security and compliance program.

Requirements

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field, or the equivalent combination of education and relevant experience
  • Proven professional experience in information security, cybersecurity, compliance, audit, governance, risk management, information technology, or a related field, preferably within healthcare technology, SaaS, public sector, or cloud-native environments
  • Experience interpreting and applying information security frameworks, auditing principles, internal controls, compliance processes, and risk management practices, including experience or familiarity with NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, ISO 27001, or similar frameworks
  • Demonstrated ability to evaluate security controls and support cloud compliance requirements within AWS and Microsoft Azure environments
  • Practical experience supporting compliance assessments, control testing, audit preparation, risk assessments, gap analyses, continuous monitoring activities, or related governance, risk, and compliance initiatives
  • Experience utilizing Governance, Risk, and Compliance (GRC) platforms, compliance management tools, vendor risk management processes, or third-party security assessments is preferred
  • Strong organizational, project management, analytical, investigative, research, problem-solving, and documentation skills, with the ability to manage multiple priorities, maintain audit-ready records, and meet deadlines
  • Demonstrated ability to coordinate cross-functional initiatives, influence stakeholders, drive accountability, and successfully manage remediation efforts to completion while working independently and collaboratively in a fast-paced environment
  • Excellent verbal, written, interpersonal, and stakeholder communication skills, with strong attention to detail and a commitment to producing accurate, high-quality documentation
  • Demonstrated experience coordinating audits, compliance assessments, remediation efforts, or governance initiatives across multiple stakeholders
  • Industry certifications such as Security+, SSCP, CGRC (formerly CAP), CISA, CRISC, CCSK, AWS Security Specialty, Azure Security Engineer Associate, or similar credentials are preferred
  • Ability to maintain discretion when handling proprietary and confidential information
  • Enthusiasm for learning and expanding knowledge or skills
  • Strong work ethic, integrity, honesty, collaboration and team orientation
  • Ability to travel as required, up to 10%. This role can be performed 100% virtually anywhere in the US while following our Remote Work Policy.

Nice To Haves

  • Experience utilizing Governance, Risk, and Compliance (GRC) platforms, compliance management tools, vendor risk management processes, or third-party security assessments is preferred
  • Industry certifications such as Security+, SSCP, CGRC (formerly CAP), CISA, CRISC, CCSK, AWS Security Specialty, Azure Security Engineer Associate, or similar credentials are preferred

Responsibilities

  • Support the administration, documentation, monitoring, and continuous improvement of ImageTrend's information security compliance, governance, and risk management programs
  • Coordinate and support compliance initiatives aligned with NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, and other applicable customer, contractual, and regulatory requirements
  • Maintain compliance documentation, policies, standards, procedures, control matrices, ownership records, audit artifacts, evidence repositories, and related compliance records to ensure ongoing audit readiness
  • Participate in internal and external audits, assessments, and compliance reviews, including coordinating audit requests, collecting and validating evidence, facilitating stakeholder responses, and supporting audit preparation activities
  • Assess the design and effectiveness of security controls, participate in control testing and reviews, identify improvement opportunities, and track audit findings, corrective actions, and remediation efforts through closure
  • Monitor and track Plans of Action & Milestones (POA&Ms), corrective action plans, security exceptions, compensating controls, risk acceptance documentation, and other remediation activities
  • Assist with security risk assessments, control gap analyses, risk register management, mitigation tracking, and policy and standards development activities
  • Support vendor risk management, third-party security assessments, third-party risk monitoring activities, and external risk assessment platforms
  • Assist with validating, documenting, monitoring, and collecting evidence for compliance-related security controls implemented within AWS and Microsoft Azure environments, including the review of cloud security documentation, configurations, and control implementations against established security frameworks and requirements
  • Collaborate with Information Security, IT, Engineering, Product, Legal, Privacy, and other cross-functional teams to ensure security and compliance requirements are effectively implemented and maintained
  • Coordinate multiple compliance-related projects and initiatives, effectively manage competing priorities, monitor milestones and deliverables, provide status updates, and drive accountability for assigned action items
  • Research emerging cybersecurity, privacy, compliance, regulatory, and cloud security trends, and recommend process improvements that strengthen organizational readiness and operational efficiency
  • Support security awareness initiatives, customer security questionnaires, due diligence requests, continuous monitoring activities, and other security and compliance-related projects as needed
  • Travel to orientation, industry or company events, or other onsite meetings as required
  • Perform additional duties or tasks as assigned

Benefits

  • bonus
  • benefits
  • perks
  • community gains
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service