Security Compliance Analyst

Rochester Regional Health
$63,000 - $83,000Remote

About The Position

The Security Compliance Analyst at ACM Global Laboratories is responsible for the delivery of information security training and guiding various departments and personnel in the activities necessary to assure that the organization remains compliant with ISO-27001 certification standards and applicable international regulations.

Requirements

  • Minimum of 1 year experience in information security or a related field.

Nice To Haves

  • Strong critical thinking skills.
  • Basic computer skills.
  • Strong written and verbal communication skills.
  • Strong ability to drive task and organizing/maintaining records.
  • Ability to think creatively and strategically.
  • Passion for learning new and emerging technology.
  • Technology education or certifications, experience with enterprise IT environments, experience working with security regulatory requirements, and knowledge of security frameworks such as NIST CFS, NIST 800-53, ISO, PCI-DSS a plus.

Responsibilities

  • Oversee rollout of cybersecurity awareness campaigns and required annual training and policy attestations.
  • Monitor the participation of the cybersecurity awareness campaigns, ensure compliance, and support content preparation aligned with company and regulatory requirements.
  • Conduct in-person staff training and promote security awareness to educate employees on security protocols to reduce human error.
  • Monitor user training completions and work with user's manager to assure completion in a timely manner.
  • Maintain data classification and data retention documentation.
  • Manage and communicate processes for data labeling.
  • Act on findings related to data mishandling as determined by DLP systems, with direct user interaction.
  • Work closely with business units and individuals to help them navigate the complexities of applying ISMS requirements.
  • Liaison with end users and department leads to implement risk remediations and security controls.
  • Assure the appropriate use of data in relation to data security.
  • Assure data masking is in use where practicable.
  • Assure that device, application, and data inventories remain updated.
  • Collects, documents, and files evidence that various security processes are functioning as intended.
  • Other duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service