Clera - Your AI talent agent
LoginStart
Start
M
ModMed

Senior GRC Analyst

full-time•United States

Summary

Location

United States

Type

full-time

Experience

5-10 years

Company links

WebsiteLinkedInLinkedIn

About this role

Join the Team Modernizing Medicine

At ModMed, we’re not just building software—we’re reimagining the healthcare experience. Founded in 2010 by a practicing physician and a successful tech entrepreneur, we took a radically different approach: we hired doctors and taught them how to code. This "for doctors, by doctors" philosophy has allowed us to create an AI-enabled, specialty-specific cloud platform that places patients at the center of care.

A Culture of Excellence

When you join ModMed, you’re joining an award-winning team recognized for innovation and employee satisfaction.   From our global headquarters in Boca Raton Florida, and extensive employee base in Hyderabad India, we are a team of 4,500+ passionate problem-solvers on a mission to increase medical practice success and improve patient outcomes:

  • Consistently ranked as a Top Place to Work

  • 2025 Globee Business Awards: Gold Globee for “Technology Team of the Year”

  • 2025 Black Book Awards: Ranked #1 EHR in 11 Specialties

  • Florida Venture Forum: Venture-Backed Company of the Year

We are growing fast, thinking big, and we are just getting started.

Ready to modernize medicine with us?

Job Description Summary:

The Senior GRC Analyst is responsible for leading and maturing key components of ModMed’s Governance, Risk, and Compliance program. This role partners closely with security, technology, legal, compliance, and business stakeholders to proactively identify, assess, and mitigate risk while ensuring ongoing compliance with regulatory and industry standards. The incumbent operates as a trusted advisor, driving continuous improvement of GRC processes, frameworks, and controls across the enterprise.

The Senior GRC Analyst is responsible for designing, enhancing, and scaling GRC processes, including enterprise risk assessments, third-party risk management, audit readiness, and security awareness programs. This role contributes directly to improving program maturity, efficiency, and sustainability across ModMed.

What you'll do:

  • Lead the development, implementation, and ongoing maintenance of enterprise cybersecurity policies, standards, and procedures.

  • Own and evolve components of the cybersecurity governance framework, ensuring alignment with business strategy, risk appetite, and regulatory obligations.

  • Serve as a subject matter expert on GRC frameworks and best practices, advising leadership on governance decisions and tradeoffs.

  • Partner cross-functionally to embed governance requirements into operational and technology processes.

  • Lead and independently execute enterprise and third-party risk assessments, including methodology refinement and scoping decisions

  • Evaluate complex risk scenarios, identify control gaps, and recommend prioritized, risk-based mitigation strategies.

  • Monitor risk remediation efforts, challenge effectiveness of controls, and escalate material risks as appropriate.

  • Contribute to the ongoing maturation of the enterprise risk management and third-party risk management programs.

  • Own and lead compliance activities for major regulatory and industry frameworks (PCI, HIPAA, SOC 2, CIS Controls, NIST CSF).

  • Act as a primary point of contact for internal and external auditors, independently managing audit readiness, execution, and remediation efforts.

  • Interpret evolving regulatory requirements and translate them into actionable controls and processes for the business.

  • Drive continuous improvement of compliance processes, reducing audit friction and improving control sustainability.

  • Design and continuously improve security awareness and training initiatives based on risk trends and audit findings.

  • Advise business partners and leadership on risk-conscious decision-making and secure-by-design practices.

  • Measure and report on program effectiveness and adoption.

  • Develop and present executive-level reporting on GRC metrics, risk posture, audit outcomes, and program maturity.

  • Ensure comprehensive, defensible documentation for audits, risk assessments, and governance decisions.

  • Provide insights and recommendations to senior security leadership based on data and trend analysis.

What you'll bring:

  • Bachelor’s degree in Information Security, Cybersecurity, InformationTechnology or equivalent education and experience.

  • Minimum of 7 years of experience in information security GRC, or related fields.

  • Experience with PCI, HIPAA, SOC2, CIS Controls, and risk management, enterprise security risk management, and security awareness.

  • Proficiency in PCI and security risk assessments methodologies and tools.

  • Excellent problem-solving skills.

  • Strong communication and interpersonal skills.

It's a plus if you have:

  • Familiarity with healthcare industry regulations

  • Strong understanding of security frameworks and standards (NIST CSF, PCI, HIPAA, SOC2, CIS Controls)

  • Experience with GRC tools and technologies

  • PCIP, ISA

  • CISA Certification

  • CISM Certification

ModMed Benefits Highlight:  At ModMed, we believe it’s important to offer a competitive benefits package designed to meet the diverse needs of our growing workforce. Eligible Modernizers can enroll in a wide range of benefits:

United States

  • Comprehensive medical, dental, and vision benefits, including a company Health Savings Account contribution,
  • 401(k):  ModMed provides a matching contribution each payday of 50% of your contribution deferred on up to 6% of your compensation. After one year of employment with ModMed, 100% of any matching contribution you receive is yours to keep.
  • Generous Paid Time Off and Paid Parental Leave programs,
  • Company paid Life and Disability benefits, Flexible Spending Account, and Employee Assistance Programs,
  • Company-sponsored Business Resource & Special Interest Groups that provide engaged and supportive communities within ModMed,
  • Professional development opportunities, including tuition reimbursement programs and unlimited access to LinkedIn Learning,
  • Global presence and in-person collaboration opportunities; dog-friendly HQ (US), Hybrid office-based roles and remote availability for some roles,
  • Weekly catered breakfast and lunch, treadmill workstations, Zen, and wellness rooms within our BRIC headquarters.

PHISHING SCAM WARNING: ModMed is among several companies recently made aware of a phishing scam involving imposters posing as hiring managers recruiting via email, text and social media. The imposters are creating misleading email accounts, conducting remote "interviews," and making fake job offers in order to collect personal and financial information from unsuspecting individuals. Please be aware that no job offers will be made from ModMed without a formal interview process, and valid communications from our hiring team will come from our employees with a ModMed email address ([email protected]). Please check senders’ email addresses carefully.  Additionally, ModMed will not ask you to purchase equipment or supplies as part of your onboarding process. If you are receiving communications as described above, please report them to the FTC website.

What you'll do

  • The Senior GRC Analyst leads and matures key components of the Governance, Risk, and Compliance program, partnering with various stakeholders to proactively identify, assess, and mitigate risk while ensuring regulatory compliance. This role is responsible for designing, enhancing, and scaling GRC processes, including enterprise risk assessments, third-party risk management, audit readiness, and security awareness programs.

About ModMed

At ModMed, we empower medical practices to grow and scale by delivering better patient experiences with cloud, data and AI technologies. Leveraging extensive clinical datasets, we design intelligent software solutions to simplify, automate and streamline clinical workflows and drive practice efficiency. Our specialty-specific EHR, practice management, revenue cycle management and analytics solutions, as well as products for patient engagement, payment processing and marketing, are trusted by over 40,000 providers to drive clinical and operational success. Come visit us at www.modmed.com.

Ready to join ModMed?

Take the next step in your career journey

Frequently Asked Questions

What does a Senior GRC Analyst do at ModMed?

Toggle
As a Senior GRC Analyst at ModMed, you will: the Senior GRC Analyst leads and matures key components of the Governance, Risk, and Compliance program, partnering with various stakeholders to proactively identify, assess, and mitigate risk while ensuring regulatory compliance. This role is responsible for designing, enhancing, and scaling GRC processes, including enterprise risk assessments, third-party risk management, audit readiness, and security awareness programs..

Is the Senior GRC Analyst position at ModMed remote?

Toggle
The Senior GRC Analyst position at ModMed is based in United States, United States. Contact the company through Clera for specific work arrangement details.

How do I apply for the Senior GRC Analyst position at ModMed?

Toggle
You can apply for the Senior GRC Analyst position at ModMeddirectly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process.
Clera - Your AI talent agent
© 2026 Clera Labs, Inc.TermsPrivacyHelp

Join Clera's Talent Pool

Get matched with similar opportunities at top startups

This role is hosted on ModMed's careers site.
Join our talent pool first to get notified about similar roles that match your profile.