Please mention DailyRemote when applying
Match your resume skills with our AI powered skill match!
The Cybersecurity Lead will partner with the CISO to design and implement a comprehensive security control framework and drive HIPAA compliance across the organization. This role involves building security automations, managing incident response, and establishing secure SDLC practices within a cloud-native environment.
Location: Remote | Reports to: CISO
About VetClaims.AI
VetClaims.AI is a fast-growing startup providing educational tools and AI-driven guidance to
help veterans understand and complete VA disability claims. We're building technology that
makes a real difference in veterans' lives, and we take the security and privacy of their data
seriously.
About the Role
You'll work alongside our CISO as the hands-on leader of security execution, owning the
implementation of our security strategy end to end. You'll design and deploy our security control
framework, build our detection and incident response capabilities, and drive HIPAA compliance
across the organization — from technical safeguards in our platform to administrative policies
and workforce training.
This is a builder's leadership role that combines strategy with engineering. You'll help shape the
roadmap with the CISO, then make it real — building tooling and automations yourself where
off-the-shelf solutions don't exist, and coordinating closely with engineering on everything else.
What You'll Do
Security Strategy & Leadership
● Partner with the CISO to define and execute VetClaims' security strategy, roadmap, and
priorities
● Design, implement, and operate security controls across cloud infrastructure,
applications, and corporate systems — encryption at rest and in transit, access controls,
audit logging, and data retention
● Establish secure SDLC practices with engineering: security code review standards,
dependency scanning, secrets management, and PHI data-handling patterns
Detection & Response
● Design, implement, and maintain centralized logging across our infrastructure (GCP,
Cloudflare, application logs, and others)
● Evaluate, implement, and manage SIEM or log management tooling
● Create, tune, and maintain security alerts for critical events; build monitoring for
suspicious activity, unauthorized access, and anomalies
● Review and analyze Cloudflare analytics and threat data, and track threats targeting our
platform
● Lead investigation and response for security incidents, and create and own incident
response playbooks.
Vulnerability Management
● Evaluate, implement, and maintain security scanning tools, including container and
dependency scanning
● Prioritize vulnerabilities and coordinate remediation with engineering
● Build custom integrations for vulnerability tracking and remediation workflows
● Implement monitoring and alerting for role changes, privileged access, and access
anomalies. Suggest improvements in access and identity management across all our
tech stack.
HIPAA & Compliance Operations
● Support HIPAA compliance end to end: administrative, physical, and technical
safeguards under the Security Rule, Privacy Rule alignment, breach notification
procedures, and ongoing risk assessments
● Conduct and maintain the HIPAA-required security risk analysis and drive remediation of
gaps
● Build and maintain Vanta integrations, developing custom solutions where standard
integrations don't exist
● Collect and manage evidence for audits and compliance reviews
● Support Business Associate Agreements and third-party/vendor risk, including
payments, CRM, and communications integrations
● Support security and privacy awareness training for all staff
Automation & Tooling
● Design and build security automations to reduce manual work
● Develop custom tools and integrations where off-the-shelf solutions fall short
● Maintain and continuously improve the security tooling stack
What We're Looking For
Required
● 7+ years in information security, with 2+ years leading security programs or teams
● Bilingual English/Spanish proficiency (fluent in verbal and written communication in both languages)
● Hands-on experience securing cloud-native SaaS platforms, with log management or
SIEM tooling experience
● Scripting skills (Python, Bash, or similar) and comfort working with APIs to build custom
integrations and tools
● Track record implementing a security framework like (NIST CSF, NIST AI RMF, ISO
27001) and conducting formal risk assessments
● Strong communication skills — able to translate risk for executives, engineers, and non-
technical staff
● Willingness to learn and build in a startup environment
Nice to Have
● Direct experience building or running HIPAA compliance programs in a healthcare,
healthtech, PHI-handling environment or PCI-SSC
● Experience with GCP and Cloudflare
● Experience with compliance automation platforms like Vanta, Drata, among others
● Bilingual Spanish/English
● Certifications like,CSFPC, CompTIA Security+
What We Offer
● Opportunity to build the security function from the ground up
● Direct impact on protecting veterans' sensitive data
● Collaborative, remote-first team
● Competitive salary and benefits
● Room to grow as the company scales
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Others
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”