The analyst will manage operational security, including SaaS administration, vulnerability management, and incident response. They will also lead the company's risk management and compliance program, ensuring adherence to HIPAA and NIST frameworks.
VetClaims.AI operates a growing portfolio of SaaS applications and internal systems that power a HIPAA-regulated platform serving thousands of veterans every month. As we scale, we need someone who can run the operational security of that environment and contribute a structured, disciplined approach to how we track and manage risk. Risk and compliance work at VetClaims.AI is cross-functional. This role brings the operational depth and structured risk-tracking discipline that makes those shared decisions easier to make well, working alongside whichever teams a given risk or project actually touches.
This role sits at the intersection of hands-on SaaS/security administration and risk governance. You'll administer and harden the tools we run day to day, support incident investigations when something goes wrong, help engineering and business teams build integrations securely, and help run the mechanics of an ongoing risk program — tracking, remediating, and reporting on risk in partnership with the teams involved in each case.
We help veterans navigate one of the most consequential bureaucratic processes of their lives. Security and compliance here aren't checkbox exercises — they protect the health information of people who served. You'll have a direct line to the CISO, real ownership of a critical function, and the budget and mandate to do it properly.
What You'll Do
Security Operations
Own the inventory of SaaS applications company-wide, including access management (SSO/SAML/OIDC, MFA, SCIM provisioning/deprovisioning) and configuration hardening against vendor and industry baselines
Manage the joiner/mover/leaver access lifecycle on least-privilege principles
Monitor security posture and remediate misconfigurations
Run vulnerability management across our SaaS and cloud environment — identifying, prioritizing, and tracking vulnerabilities to remediation, using our existing monitoring tools (e.g., Cloudflare WAF/Log Explorer) and any additional scanning tools
Support investigation of security incidents and suspicious activity — scoping, containing, and documenting findings, using scripting where useful to analyze logs or automate parts of the investigation
Contribute to post-incident documentation and follow-up remediation tracking
Support secure implementation of integrations between internal and third-party systems: API key management, OAuth scopes, service account governance, and webhook security
Review integration requests from Engineering and business teams for security and compliance impact before approval
Risk Management & Governance (Program-Level)
Help run a structured, ongoing risk management program for the company — identifying risks, assessing their severity/likelihood, tracking remediation to closure, and reporting status on a regular cadence
Conduct control assessments against our adopted frameworks (HIPAA Security Rule and NIST CSF — our risk framework already on the roadmap) and identify gaps
Bring Zero Trust and modern risk-management principles into how we evaluate new systems, vendors, and technical decisions
Actively participate in the company's AI use case assessment process — evaluating proposed AI tools and use cases from a technical, security, and compliance perspective. Like vendor assessment, this is a cross-functional process with several stakeholders, not an area this role owns exclusively
Contribute risk analysis to support risk-based decisions — translating technical risk into business terms
Compliance & Audit Readiness
Operate and maintain compliance automation in Vanta: evidence collection, control monitoring, remediation tracking, audit readiness
Execute recurring access reviews and produce audit-ready documentation
Support HIPAA compliance activities: risk assessments, vendor security reviews, BAA tracking, policy enforcement across SaaS systems
Conduct vendor/third-party risk assessments for new SaaS purchases; maintain the vendor risk register
Support ongoing security monitoring and log review to help confirm controls (including NIST CSF controls) are actually operating as intended, not just documented as if they were
What You Bring
Required
4–6+ years in cybersecurity risk management, GRC, or security operations roles, with real ownership of both hands-on security administration and a structured risk/compliance program
Experience running a formal risk management process — identifying, assessing, tracking, and reporting on risk to closure — under any recognized framework (NIST RMF, ISO 27001, NIST CSF, or equivalent); the specific framework matters less than the discipline of running the process end-to-end
Experience with identity providers and SSO (Google Workspace, Okta, Entra ID, or similar): SAML, OIDC, SCIM, MFA policy design
Experience with compliance automation platforms (Vanta, Drata, Secureframe, or similar)
Comfort with APIs and integration concepts: OAuth flows, API tokens, scopes, webhooks
Solid scripting/automation skills (Python, Bash, or similar) — used for secure integration work and to support incident investigations (e.g., log analysis, automating recurring checks), not just for provisioning tasks
Strong documentation habits: risk registers, access review records, runbooks, vendor assessments, that stand up to audit
Professional English (written and spoken); Spanish is a plus
Nice to have
Fluent in written and oral Spanish in addition to English
Demonstrated ability to communicate risk to non-technical stakeholders and support executive-level, risk-based decision making — valuable, but something that can also develop on the job
Experience in a HIPAA-regulated or otherwise regulated/high-compliance environment
Familiarity with Zero Trust Architecture principles
Familiarity with our stack: Google Workspace, GCP, Cloudflare, Vanta, HubSpot, Stripe, BigQuery
Certifications such as Security+, CySA+, or similar
What We Offer
$95,000 – $135,000 annually depending on experience
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”