Join the Team Modernizing Medicine
At ModMed, we’re not just building software—we’re reimagining the healthcare experience. Founded in 2010 by a practicing physician and a successful tech entrepreneur, we took a radically different approach: we hired doctors and taught them how to code. This "for doctors, by doctors" philosophy has allowed us to create an AI-enabled, specialty-specific cloud platform that places patients at the center of care.
A Culture of Excellence
When you join ModMed, you’re joining an award-winning team recognized for innovation and employee satisfaction. From our global headquarters in Boca Raton Florida, and extensive employee base in Hyderabad India, we are a team of 4,500+ passionate problem-solvers on a mission to increase medical practice success and improve patient outcomes:
Consistently ranked as a Top Place to Work
2025 Globee Business Awards: Gold Globee for “Technology Team of the Year”
2025 Black Book Awards: Ranked #1 EHR in 11 Specialties
Florida Venture Forum: Venture-Backed Company of the Year
We are growing fast, thinking big, and we are just getting started.
Ready to modernize medicine with us?
Job Description Summary:
The Senior GRC Analyst is responsible for leading and maturing key components of ModMed’s Governance, Risk, and Compliance program. This role partners closely with security, technology, legal, compliance, and business stakeholders to proactively identify, assess, and mitigate risk while ensuring ongoing compliance with regulatory and industry standards. The incumbent operates as a trusted advisor, driving continuous improvement of GRC processes, frameworks, and controls across the enterprise.
The Senior GRC Analyst is responsible for designing, enhancing, and scaling GRC processes, including enterprise risk assessments, third-party risk management, audit readiness, and security awareness programs. This role contributes directly to improving program maturity, efficiency, and sustainability across ModMed.
What you'll do:
Lead the development, implementation, and ongoing maintenance of enterprise cybersecurity policies, standards, and procedures.
Own and evolve components of the cybersecurity governance framework, ensuring alignment with business strategy, risk appetite, and regulatory obligations.
Serve as a subject matter expert on GRC frameworks and best practices, advising leadership on governance decisions and tradeoffs.
Partner cross-functionally to embed governance requirements into operational and technology processes.
Lead and independently execute enterprise and third-party risk assessments, including methodology refinement and scoping decisions
Evaluate complex risk scenarios, identify control gaps, and recommend prioritized, risk-based mitigation strategies.
Monitor risk remediation efforts, challenge effectiveness of controls, and escalate material risks as appropriate.
Contribute to the ongoing maturation of the enterprise risk management and third-party risk management programs.
Own and lead compliance activities for major regulatory and industry frameworks (PCI, HIPAA, SOC 2, CIS Controls, NIST CSF).
Act as a primary point of contact for internal and external auditors, independently managing audit readiness, execution, and remediation efforts.
Interpret evolving regulatory requirements and translate them into actionable controls and processes for the business.
Drive continuous improvement of compliance processes, reducing audit friction and improving control sustainability.
Design and continuously improve security awareness and training initiatives based on risk trends and audit findings.
Advise business partners and leadership on risk-conscious decision-making and secure-by-design practices.
Measure and report on program effectiveness and adoption.
Develop and present executive-level reporting on GRC metrics, risk posture, audit outcomes, and program maturity.
Ensure comprehensive, defensible documentation for audits, risk assessments, and governance decisions.
Provide insights and recommendations to senior security leadership based on data and trend analysis.
What you'll bring:
Bachelor’s degree in Information Security, Cybersecurity, InformationTechnology or equivalent education and experience.
Minimum of 7 years of experience in information security GRC, or related fields.
Experience with PCI, HIPAA, SOC2, CIS Controls, and risk management, enterprise security risk management, and security awareness.
Proficiency in PCI and security risk assessments methodologies and tools.
Excellent problem-solving skills.
Strong communication and interpersonal skills.
It's a plus if you have:
Familiarity with healthcare industry regulations
Strong understanding of security frameworks and standards (NIST CSF, PCI, HIPAA, SOC2, CIS Controls)
Experience with GRC tools and technologies
PCIP, ISA
CISA Certification
CISM Certification
ModMed Benefits Highlight: At ModMed, we believe it’s important to offer a competitive benefits package designed to meet the diverse needs of our growing workforce. Eligible Modernizers can enroll in a wide range of benefits:
United States
PHISHING SCAM WARNING: ModMed is among several companies recently made aware of a phishing scam involving imposters posing as hiring managers recruiting via email, text and social media. The imposters are creating misleading email accounts, conducting remote "interviews," and making fake job offers in order to collect personal and financial information from unsuspecting individuals. Please be aware that no job offers will be made from ModMed without a formal interview process, and valid communications from our hiring team will come from our employees with a ModMed email address ([email protected]). Please check senders’ email addresses carefully. Additionally, ModMed will not ask you to purchase equipment or supplies as part of your onboarding process. If you are receiving communications as described above, please report them to the FTC website.
Take the next step in your career journey
Get matched with similar opportunities at top startups
This role is hosted on ModMed's careers site.
Join our talent pool first to get notified about similar roles that match your profile.