Cybersecurity Risk & Compliance Analyst
PATRIOTCLAIMS LLC United States · $95K–$135K/yr
Insurance · 51-200 employees
About the role
The analyst will manage operational security, including SaaS administration, vulnerability management, and incident response. They will also lead the company's risk management and compliance program, ensuring adherence to HIPAA and NIST frameworks.
What they look for
Requirements
Candidates must have 4–6+ years of experience in cybersecurity risk management or security operations with a strong background in GRC. Proficiency in identity management, compliance automation tools, and scripting for automation is required.
Benefits
Full description
Cybersecurity Risk & Compliance Analyst
Department: Technology — Security Reports to: CISO Location: Remote Employment type: Full-time
About the Role
VetClaims.AI operates a growing portfolio of SaaS applications and internal systems that power a HIPAA-regulated platform serving thousands of veterans every month. As we scale, we need someone who can run the operational security of that environment and contribute a structured, disciplined approach to how we track and manage risk. Risk and compliance work at VetClaims.AI is cross-functional. This role brings the operational depth and structured risk-tracking discipline that makes those shared decisions easier to make well, working alongside whichever teams a given risk or project actually touches.
This role sits at the intersection of hands-on SaaS/security administration and risk governance. You'll administer and harden the tools we run day to day, support incident investigations when something goes wrong, help engineering and business teams build integrations securely, and help run the mechanics of an ongoing risk program — tracking, remediating, and reporting on risk in partnership with the teams involved in each case.
We help veterans navigate one of the most consequential bureaucratic processes of their lives. Security and compliance here aren't checkbox exercises — they protect the health information of people who served. You'll have a direct line to the CISO, real ownership of a critical function, and the budget and mandate to do it properly.
What You'll Do
Security Operations
- Own the inventory of SaaS applications company-wide, including access management (SSO/SAML/OIDC, MFA, SCIM provisioning/deprovisioning) and configuration hardening against vendor and industry baselines
- Manage the joiner/mover/leaver access lifecycle on least-privilege principles
- Monitor security posture and remediate misconfigurations
- Run vulnerability management across our SaaS and cloud environment — identifying, prioritizing, and tracking vulnerabilities to remediation, using our existing monitoring tools (e.g., Cloudflare WAF/Log Explorer) and any additional scanning tools
- Support investigation of security incidents and suspicious activity — scoping, containing, and documenting findings, using scripting where useful to analyze logs or automate parts of the investigation
- Contribute to post-incident documentation and follow-up remediation tracking
- Support secure implementation of integrations between internal and third-party systems: API key management, OAuth scopes, service account governance, and webhook security
- Review integration requests from Engineering and business teams for security and compliance impact before approval
Risk Management & Governance (Program-Level)
- Help run a structured, ongoing risk management program for the company — identifying risks, assessing their severity/likelihood, tracking remediation to closure, and reporting status on a regular cadence
- Conduct control assessments against our adopted frameworks (HIPAA Security Rule and NIST CSF — our risk framework already on the roadmap) and identify gaps
- Bring Zero Trust and modern risk-management principles into how we evaluate new systems, vendors, and technical decisions
- Actively participate in the company's AI use case assessment process — evaluating proposed AI tools and use cases from a technical, security, and compliance perspective. Like vendor assessment, this is a cross-functional process with several stakeholders, not an area this role owns exclusively
- Contribute risk analysis to support risk-based decisions — translating technical risk into business terms
Compliance & Audit Readiness
- Operate and maintain compliance automation in Vanta: evidence collection, control monitoring, remediation tracking, audit readiness
- Execute recurring access reviews and produce audit-ready documentation
- Support HIPAA compliance activities: risk assessments, vendor security reviews, BAA tracking, policy enforcement across SaaS systems
- Conduct vendor/third-party risk assessments for new SaaS purchases; maintain the vendor risk register
- Support ongoing security monitoring and log review to help confirm controls (including NIST CSF controls) are actually operating as intended, not just documented as if they were
What You Bring
Required
- 4–6+ years in cybersecurity risk management, GRC, or security operations roles, with real ownership of both hands-on security administration and a structured risk/compliance program
- Experience running a formal risk management process — identifying, assessing, tracking, and reporting on risk to closure — under any recognized framework (NIST RMF, ISO 27001, NIST CSF, or equivalent); the specific framework matters less than the discipline of running the process end-to-end
- Experience with identity providers and SSO (Google Workspace, Okta, Entra ID, or similar): SAML, OIDC, SCIM, MFA policy design
- Experience with compliance automation platforms (Vanta, Drata, Secureframe, or similar)
- Comfort with APIs and integration concepts: OAuth flows, API tokens, scopes, webhooks
- Solid scripting/automation skills (Python, Bash, or similar) — used for secure integration work and to support incident investigations (e.g., log analysis, automating recurring checks), not just for provisioning tasks
- Strong documentation habits: risk registers, access review records, runbooks, vendor assessments, that stand up to audit
- Professional English (written and spoken); Spanish is a plus
Nice to have
- Fluent in written and oral Spanish in addition to English
- Demonstrated ability to communicate risk to non-technical stakeholders and support executive-level, risk-based decision making — valuable, but something that can also develop on the job
- Experience in a HIPAA-regulated or otherwise regulated/high-compliance environment
- Familiarity with Zero Trust Architecture principles
- Familiarity with our stack: Google Workspace, GCP, Cloudflare, Vanta, HubSpot, Stripe, BigQuery
- Certifications such as Security+, CySA+, or similar
What We Offer
- $95,000 – $135,000 annually depending on experience
- Medical
- Dental
- Fully remote
Similar roles
-
Security Engineer
Sierra Central Credit Union Yuba City, California, United States · $120K–$145K/yr
-
Cyber Security Engineer
Paragon Cyber Solutions Crane, Indiana, United States
-
Principal Cloud Security Engineer
Rocket Lab Corporation Long Beach, California, United States · $152K–$165K/yr
-
Information Systems Security Engineer (6836)
MetroStar Washington, District of Columbia, United States · $180K–$200K/yr
-
Senior Cybersecurity Engineer
Charger Logistics Inc Brampton, Ontario, Canada
-
1850 - Information Systems Security Engineer (ISSE) - Hybrid - Active Secret Clearance Required - Bonus Eligible
Rollout Systems Okaloosa County, Florida, United States · $120K–$175K/yr