Salary Range: $110,000.00 To $130,000.00 Annually Location: Remote | Reports to: CISO About VetClaims.AI VetClaims.AI is a fast-growing startup providing educational tools and AI-driven guidance to help veterans understand and complete VA disability claims. We're building technology that makes a real difference in veterans' lives, and we take the security and privacy of their data seriously. About the Role You'll work alongside our CISO as the hands-on leader of security execution, owning the implementation of our security strategy end to end. You'll design and deploy our security control framework, build our detection and incident response capabilities, and drive HIPAA compliance across the organization — from technical safeguards in our platform to administrative policies and workforce training. This is a builder's leadership role that combines strategy with engineering. You'll help shape the roadmap with the CISO, then make it real — building tooling and automations yourself where off-the-shelf solutions don't exist, and coordinating closely with engineering on everything else. What You'll Do Security Strategy & Leadership ● Partner with the CISO to define and execute VetClaims' security strategy, roadmap, and priorities ● Design, implement, and operate security controls across cloud infrastructure, applications, and corporate systems — encryption at rest and in transit, access controls, audit logging, and data retention ● Establish secure SDLC practices with engineering: security code review standards, dependency scanning, secrets management, and PHI data-handling patterns Detection & Response ● Design, implement, and maintain centralized logging across our infrastructure (GCP, Cloudflare, application logs, and others) ● Evaluate, implement, and manage SIEM or log management tooling ● Create, tune, and maintain security alerts for critical events; build monitoring for suspicious activity, unauthorized access, and anomalies ● Review and analyze Cloudflare analytics and threat data, and track threats targeting our platform ● Lead investigation and response for security incidents, and create and own incident response playbooks. Vulnerability Management ● Evaluate, implement, and maintain security scanning tools, including container and dependency scanning ● Prioritize vulnerabilities and coordinate remediation with engineering ● Build custom integrations for vulnerability tracking and remediation workflows ● Implement monitoring and alerting for role changes, privileged access, and access anomalies. Suggest improvements in access and identity management across all our tech stack. HIPAA & Compliance Operations ● Support HIPAA compliance end to end: administrative, physical, and technical safeguards under the Security Rule, Privacy Rule alignment, breach notification procedures, and ongoing risk assessments ● Conduct and maintain the HIPAA-required security risk analysis and drive remediation of gaps ● Build and maintain Vanta integrations, developing custom solutions where standard integrations don't exist ● Collect and manage evidence for audits and compliance reviews ● Support Business Associate Agreements and third-party/vendor risk, including payments, CRM, and communications integrations ● Support security and privacy awareness training for all staff Automation & Tooling ● Design and build security automations to reduce manual work ● Develop custom tools and integrations where off-the-shelf solutions fall short ● Maintain and continuously improve the security tooling stack What We're Looking For Required ● 7+ years in information security, with 2+ years leading security programs or teams ● Bilingual English/Spanish proficiency (fluent in verbal and written communication in both languages) ● Hands-on experience securing cloud-native SaaS platforms, with log management or SIEM tooling experience ● Scripting skills (Python, Bash, or similar) and comfort working with APIs to build custom integrations and tools ● Track record implementing a security framework like (NIST CSF, NIST AI RMF, ISO 27001) and conducting formal risk assessments ● Strong communication skills — able to translate risk for executives, engineers, and non- technical staff ● Willingness to learn and build in a startup environment Nice to Have ● Direct experience building or running HIPAA compliance programs in a healthcare, healthtech, PHI-handling environment or PCI-SSC ● Experience with GCP and Cloudflare ● Experience with compliance automation platforms like Vanta, Drata, among others ● Bilingual Spanish/English ● Certifications like,CSFPC, CompTIA Security+ What We Offer ● Opportunity to build the security function from the ground up ● Direct impact on protecting veterans' sensitive data ● Collaborative, remote-first team ● Competitive salary and benefits ● Room to grow as the company scales
Senior Cybersecurity Subject Matter Expert - Technical Lead
Softthink Solutions Inc
Cybersecurity SME - Lead (Cyber Tools)
Credence
Lead Consultant, Cybersecurity (Remote)
American Bureau of Shipping
Senior Director, Analyst – Cybersecurity Leadership
Gartner
Cybersecurity Team Lead
GM Financial Canada
Director, Cybersecurity Engineering Lead
Blackrock