Summary
Mosaic Clinical Technologies is pioneering an AI-native imaging platform to help clinical teams improve diagnostic quality, operational efficiency, and patient care. The Security Analyst, GRC will support daily governance, risk, and compliance operations, coordinate third-party risk activities, administer GRC tools, and collaborate across teams to improve security, compliance, and operational continuity.
Responsibilities
- Support day-to-day Governance, Risk, and Compliance (GRC) operations, including program coordination, stakeholder communications, reporting, metrics, training, and documentation
- Coordinate third-party risk and vendor assessment activities, including intake management, evidence collection, remediation tracking, approvals, reporting, and process improvements
- Administer and enhance GRC tools, workflows, dashboards, automations, and reporting solutions, including testing, troubleshooting, data quality, and user adoption support
- Support governance, risk, compliance, access management, vulnerability management, audit readiness, evidence collection, issue tracking, and operational continuity initiatives
- Collaborate with Security, Privacy, Compliance, Legal, Technology, Product, and business teams to drive process improvements, support platform implementations, and escalate material risks or control gaps to leadership
- Travel up to 5%
Skills
- Working understanding of GRC frameworks and regulations, such as HIPAA, SOC 2, NIST, ISO 27001, PCI DSS, GDPR, or applicable privacy requirements
- Understanding of data analytics, KPI development, dashboard and reporting concepts, evidence management, and operational metrics
- 2+ years of experience in GRC, information security, risk, compliance, audit, vendor risk, security operations, or a related role preferred
- Bachelor's degree in computer science, information security, information systems, risk management, compliance, or a related field preferred
- Experience administering, configuring, testing, troubleshooting, or supporting GRC, workflow, ticketing, reporting, or security platforms such as ServiceNow, LogicGate, or comparable tools is preferred
Qualifications
Must Haves
- Working understanding of GRC frameworks and regulations, such as HIPAA, SOC 2, NIST, ISO 27001, PCI DSS, GDPR, or applicable privacy requirements
- Understanding of data analytics, KPI development, dashboard and reporting concepts, evidence management, and operational metrics
Nice to Haves
- 2+ years of experience in GRC, information security, risk, compliance, audit, vendor risk, security operations, or a related role preferred
- Bachelor's degree in computer science, information security, information systems, risk management, compliance, or a related field preferred
- Experience administering, configuring, testing, troubleshooting, or supporting GRC, workflow, ticketing, reporting, or security platforms such as ServiceNow, LogicGate, or comparable tools is preferred
Benefits
- Competitive Benefits package – Eligibility starts the month after hire, with tiered options to choose from.
- Compensation Reviews
- Career Growth Opportunities
- Flexible Remote Schedules
- Generous PTO Plans and Paid Holidays
- Annual discretionary bonus
- Health & wellness coverage options
- 401k benefits
- Family planning
- Telehealth