Information Security Compliance Analyst
Skills
About the role
This is a fully remote information security compliance role supporting cybersecurity governance and risk programs. It suits a mid-level compliance or audit professional comfortable working across NIST, FedRAMP, HIPAA and SOC 2 frameworks. The analyst maintains compliance documentation, supports audits, and tracks remediation for ImageTrend, a healthcare and emergency response software company based in Eagan, MN.
What you’ll do
- Support administration, documentation and monitoring of information security compliance and risk programs
- Coordinate compliance initiatives aligned with NIST 800-53, FedRAMP, GovRAMP, HIPAA and SOC 2
- Maintain compliance documentation, control matrices and audit evidence repositories
- Participate in internal and external audits, collecting and validating evidence
- Assess design and effectiveness of security controls and track findings through closure
- Monitor Plans of Action & Milestones, corrective action plans and risk acceptance documentation
- Assist with risk assessments, control gap analyses and risk register management
- Support vendor risk management and third-party security assessments
- Validate and document cloud security controls in AWS and Microsoft Azure environments
- Coordinate multiple compliance projects and provide status updates
- Support security awareness initiatives and customer security questionnaires
What they’re looking for
- Bachelor's degree in information security, cybersecurity, IT, information systems, risk management, business or related field, or equivalent experience
- Professional experience in information security, compliance, audit, governance or risk management, preferably in healthcare tech, SaaS, public sector or cloud environments
- Experience applying frameworks such as NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2 or ISO 27001
- Ability to evaluate security controls and support cloud compliance in AWS and Azure
- Practical experience with compliance assessments, control testing, audit prep, risk assessments or gap analyses
- Strong organizational, analytical and documentation skills
- Ability to coordinate cross-functional initiatives and manage remediation to completion
- Excellent verbal, written and stakeholder communication skills
- Ability to travel up to 10%
Nice to have
- Experience with GRC platforms, compliance management tools or third-party risk assessment processes
- Certifications such as Security+, SSCP, CGRC, CISA, CRISC, CCSK, AWS Security Specialty or Azure Security Engineer Associate
What’s on offer
- Annual base salary range of $80,000-$100,000 USD plus bonus, benefits and perks
- Fully remote work anywhere in the US
Questions about this role
Is this role remote?
Yes, it can be performed 100% virtually anywhere in the US.
How much does it pay?
The base salary range is $80,000 to $100,000 USD per year, plus bonus and benefits.
What frameworks does this role work with?
NIST 800-53, FedRAMP, GovRAMP, HIPAA and SOC 2, among others.
Do I need a degree?
A bachelor's degree in a related field is required, or equivalent experience.
Related roles
Security Guard Job at BenchMark Security YYC Ltd in Calgary
Full-time on-site unarmed and event-security role in Calgary. It suits candidates with at least two years of security, law-enforcement, or related experience.
Senior Security Engineer, Security Research
A senior vulnerability research and exploit development role at Google in San Jose, focused on iOS, macOS and XNU security. Suited to an experienced security researcher with a strong coding and research background.
Vice President, Information Security
Danaher is hiring a US-remote information security vice president to lead OT, product, and application security across a global operating-company portfolio. The role fits an experienced security executive with manufacturing and regulated-product security expertise.
Business Analyst, Global Solutions & Risk Compliance (GSRC)
A mid-level business analyst role at Amazon in Bengaluru, supporting global compliance and supply chain reporting with SQL and data visualization. Suited to an analyst with a few years of SQL and reporting experience.
Security Guard Job at Jungle Lion Security in Toronto
Full-time on-site security role in Toronto covering residential, office, and live-event assignments. Applicants need a valid Ontario Security Guard License and flexible availability.
Security Operations Center Analyst - Part Time
Part-time Security Operations Center Analyst role monitoring physical-security systems and coordinating incident responses for Allied Universal in Little Canada. The role suits security professionals with operations-center experience, strong reporting skills, and the ability to stay composed under pressure.