P
Cybersecurity Risk & Compliance Analyst
Cloud Security
Cloud Security Monitoring
Cybersecurity Analysis
Hipaa Compliance
Identity and Access Management
Incident Response
Information Security
InfoSec
Nist Standards
Risk Governance
Risk Management
Security Automation
Security Compliance
Security Operations
Security Posture Management
Security Standards
Vulnerability Management
Job Description
PATRIOTCLAIMS LLC is seeking a Cybersecurity Risk & Compliance Analyst to strengthen operational security in a HIPAA-regulated SaaS environment. This remote role reports to the CISO and helps maintain compliance and audit readiness while supporting security operations, risk governance, and incident-related work across the organization.
In this position, you will own key areas of security administration, run structured risk management, and contribute to ongoing control and vendor risk activities, including evidence automation in Vanta. The role blends hands-on identity and access management, vulnerability and log-informed monitoring, and cross-functional assessment of integrations, AI use cases, and third-party SaaS.
Core Responsibilities
- Own the company-wide SaaS application inventory, including access management using SSO/SAML/OIDC, MFA, and SCIM provisioning/deprovisioning, along with configuration hardening aligned to vendor and industry baselines
- Manage joiner/mover/leaver access lifecycle processes using least-privilege principles
- Monitor security posture and remediate SaaS and cloud misconfigurations
- Run vulnerability management across the SaaS and cloud environment by identifying, prioritizing, and tracking vulnerabilities to remediation, leveraging existing monitoring tools such as Cloudflare WAF and Cloudflare Log Explorer, plus additional scanning tools as needed
- Support investigation of security incidents and suspicious activity, including scoping, containment, and documented findings, using scripting when helpful for log analysis or investigation automation
- Contribute to post-incident documentation and follow-up remediation tracking
- Support secure implementation of internal-to-third-party integrations, including API key management, OAuth scopes, service account governance, and webhook security
- Review integration requests from Engineering and business stakeholders to assess security and compliance impact before approval
- Operate an ongoing, structured risk management program by identifying risks, assessing severity and likelihood, tracking remediation to closure, and reporting status on a regular cadence
- Conduct control assessments against the adopted frameworks, including the HIPAA Security Rule and NIST CSF (risk framework already on the roadmap), and identify gaps
- Apply Zero Trust and modern risk-management principles when evaluating new systems, vendors, and technical decisions
- Participate in the company’s AI use case assessment process from technical, security, and compliance perspectives
- Translate technical risk into business terms to support risk-based decision-making
- Operate and maintain compliance automation in Vanta for evidence collection, control monitoring, remediation tracking, and audit readiness
- Execute recurring access reviews and produce audit-ready documentation
- Support HIPAA compliance activities such as risk assessments, vendor security reviews, BAA tracking, and policy enforcement across SaaS systems
- Conduct vendor and third-party risk assessments for new SaaS purchases and maintain the vendor risk register
- Support ongoing security monitoring and log review to confirm controls are functioning as intended, including controls mapped to NIST CSF
Requirements
- 4–6+ years in cybersecurity risk management, GRC, or security operations roles, with demonstrated ownership of both hands-on security administration and a structured risk/compliance program
- Experience running a formal risk management process end-to-end under a recognized framework such as NIST RMF, ISO 27001, NIST CSF, or an equivalent approach
- Experience with identity providers and SSO, including Google Workspace, Okta, Entra ID (or similar), with SAML, OIDC, SCIM, and MFA policy design
- Experience with compliance automation platforms such as Vanta, Drata, or Secureframe
- Comfort with APIs and integration concepts including OAuth flows, API tokens, scopes, and webhooks
- Strong scripting and automation skills (such as Python or Bash) used for secure integration work and supporting incident investigations (for example, log analysis and automating recurring checks)
- Strong documentation habits including risk registers, access review records, runbooks, and vendor assessments that stand up to audit
- Professional English (written and spoken); Spanish is a plus
Technologies
- HIPAA Security Rule, NIST CSF, NIST RMF, ISO 27001
- SSO, SAML, OIDC, MFA, SCIM, Zero Trust
- Vanta, Drata, Secureframe
- Cloudflare WAF, Cloudflare Log Explorer
- Python, Bash
- OAuth, webhooks, API tokens, service account governance
- Google Workspace, Okta, Entra ID, GCP
- HubSpot, Stripe, BigQuery
Benefits
- $95,000–$135,000 annually depending on experience
- Medical
- Dental
- Fully remote
Nice to Have
- Fluent written and oral Spanish in addition to English
- Ability to communicate risk to non-technical stakeholders and support executive-level, risk-based decision making
- Experience in a HIPAA-regulated or otherwise regulated/high-compliance environment
- Familiarity with Zero Trust Architecture principles
- Familiarity with the stack: Google Workspace, GCP, Cloudflare, Vanta, HubSpot, Stripe, BigQuery
- Certifications such as Security+, CySA+, or similar