Modernizing Medicine

GRC Analyst

Only, Tennessee, United States

Not SpecifiedCompensation
Junior (1 to 2 years)Experience Level
Full TimeJob Type
UnknownVisa
Healthcare, Health Technology, CybersecurityIndustries

GRC Analyst (Governance, Risk, and Compliance)

Employment Type: [Not Specified] Location Type: [Not Specified] Salary: [Not Specified]

About Us

We Are Modernizing Medicine (WAMM)! We’re a team of bright, passionate, and positive problem-solvers on a mission to place doctors and patients at the center of care through an intelligent, specialty-specific cloud platform. Our vision is a world where the software we build increases medical practice success and improves patient outcomes. Founded in 2010 by Daniel Cane and Dr. Michael Sherling, we have grown to over 3400 combined direct and contingent team members serving eleven specialties, and we are just getting started! ModMed's global headquarters is based in Boca Raton, FL, with a growing office in Hyderabad, India, and a robust remote workforce across the US, Chile, and Germany.

Our Accolades:

  • South Florida Business Journal, Best Places to Work 2024
  • Inc. 5000 Fastest-Growing Private Companies in America 2024
  • 2024 Black Book Awards, ranked #1 EHR in 11 Specialties
  • 2024 Spring Digital Health Awards, “Web-based Digital Health” category for EMA Health Records (Gold)
  • 2024 Stevie American Business Award (Silver), New Product and Service: Health Technology Solution (Klara)

Join Us! We are united in our mission to make a positive impact on healthcare.

Position Overview

ModMed is hiring a driven GRC Analyst (Governance, Risk, and Compliance) Analyst to support the development and implementation of GRC strategies within ModMed. This role will ensure that ModMed adheres to regulatory requirements, industry standards, and best practices for cybersecurity. The ideal candidate will have a strong understanding of GRC frameworks, experience in risk assessment and management, and the ability to collaborate across various departments to enhance our security posture.

Responsibilities

Governance

  • Develop and maintain cybersecurity policies, procedures, and standards.
  • Ensure alignment of cybersecurity practices with business objectives and regulatory requirements.
  • Assist in the creation and management of the cybersecurity governance framework.

Risk Management

  • Conduct risk assessments on third parties to identify and evaluate potential cybersecurity risks.
  • Develop and implement risk mitigation strategies and controls.
  • Monitor and report on risk management activities and the effectiveness of controls.

Compliance

  • Ensure compliance with industry regulations and standards (PCI, HIPAA, SOC2).
  • Conduct regular audits and assessments to ensure adherence to compliance requirements.
  • Collaborate with internal and external auditors during compliance reviews and audits.

Security Awareness & Training

  • Develop and deliver cybersecurity awareness training materials.
  • Promote a culture of cybersecurity awareness across the organization.
  • Monitor and report on the effectiveness of security awareness initiatives.

Reporting & Documentation

  • Prepare regular reports on GRC activities and metrics for senior security management.
  • Maintain comprehensive documentation of all GRC activities, policies, and procedures.
  • Ensure proper documentation of risk assessments, audit findings, and compliance activities.

Skills & Requirements

  • Education: Bachelor’s degree in Information Security, Cybersecurity, or Information Technology or equivalent education and experience.
  • Experience: Minimum of 3-5 years of experience in information security GRC, or related fields.
  • Frameworks & Standards: Strong understanding of security frameworks and standards (NIST CSF, PCI, HIPAA, SOC2, CIS Controls).
  • Risk Management: Experience with PCI, HIPAA, SOC2, CIS Controls, and risk management, enterprise security risk management. Proficiency in PCI and security risk assessments methodologies and tools.
  • Tools: Experience with GRC tools and technologies.
  • Certifications: PCIP, ISA, CISA Certification (preferred).
  • Healthcare: Familiarity with healthcare industry regulations and standards is a plus.
  • Skills: Excellent problem-solving skills, strong communication and interpersonal skills.

#LI-DV1

ModMed Benefits Highlight

At ModMed, we believe it’s important to offer a competitive benefits package designed to meet the...

Skills

GRC frameworks
Risk assessment
Cybersecurity policies
Regulatory compliance
Security standards
Cross-department collaboration

Modernizing Medicine

Specialty-specific electronic health record systems

About Modernizing Medicine

Modernizing Medicine provides specialty-specific Electronic Health Records (EHR) systems designed to improve the workflow of healthcare providers. Their main products, EMA and gGastro EHR, help users manage patient information and administrative tasks more efficiently, allowing them to concentrate on patient care. These systems adapt to the specific practices of each user, enhancing their effectiveness. Unlike many competitors, Modernizing Medicine focuses on tailored solutions for various medical specialties, which sets them apart in the healthcare technology market. The company's goal is to streamline healthcare delivery and improve patient outcomes by providing tools that simplify administrative processes.

Boca Raton, FloridaHeadquarters
2010Year Founded
$360.6MTotal Funding
LATE_VCCompany Stage
Biotechnology, HealthcareIndustries
1,001-5,000Employees

Benefits

Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
Health Savings Account/Flexible Spending Account
Unlimited Paid Time Off
Paid Vacation
Paid Sick Leave
Paid Holidays
Parental Leave
401(k) Retirement Plan
401(k) Company Match
Professional Development Budget
Conference Attendance Budget
Hybrid Work Options
Remote Work Options
Wellness Program

Risks

Potential sale by Warburg Pincus could lead to strategic shifts misaligned with current goals.
Resistance to AI technologies may slow implementation and affect user satisfaction.
Dependency on Medtronic's technology poses risks if partnership faces challenges or strategic changes.

Differentiation

ModMed offers specialty-specific EHR systems, enhancing workflow efficiency for healthcare providers.
Their EHR systems, EMA and gGastro, adapt to user practices, increasing adaptability.
ModMed integrates AI technologies, like Medtronic's GI Genius, to improve procedural accuracy.

Upsides

ModMed consistently ranks #1 in G2's 2024 Grid Reports for EHR and RCM software.
Collaboration with Brevium enhances patient re-engagement, boosting retention in gastroenterology practices.
Appointment of Dan Costantino as CISO strengthens cybersecurity, crucial for healthcare data protection.

Land your dream remote job 3x faster with AI