Cybersecurity Risk & Compliance Analyst
Job Description
VetClaims.ai is hiring a Cybersecurity Risk & Compliance Analyst to help operate security for its HIPAA-regulated SaaS and internal systems. This fully remote role in the Technology Security team includes a direct reporting line to the CISO, with ownership across security operations, structured risk management, compliance automation, and audit readiness.
You will maintain the foundations that keep access, integrations, and security posture aligned to business and regulatory needs, while supporting incident readiness and ongoing control effectiveness across the environment.
Responsibilities
- Own the company-wide inventory of SaaS applications, including access management via SSO (SAML, OIDC), MFA, and SCIM provisioning and deprovisioning, plus configuration hardening against vendor and industry baselines
- Manage joiner/mover/leaver access on least-privilege principles
- Monitor security posture, remediate misconfigurations, and keep controls aligned to adopted expectations
- Run vulnerability management across SaaS and cloud environments by identifying, prioritizing, and tracking vulnerabilities to remediation using existing monitoring tools such as Cloudflare WAF and Log Explorer, and any additional scanning tools
- Support investigations of security incidents and suspicious activity by scoping, containing, and documenting findings, using scripting as needed to analyze logs or automate parts of the investigation
- Contribute to post-incident documentation and follow-up remediation tracking
- Support secure integration implementations between internal and third-party systems, including API key management, OAuth scopes, service account governance, and webhook security
- Review integration requests from Engineering and business teams for security and compliance impact before approval
- Operate a structured, ongoing risk management program: identify risks, assess severity and likelihood, track remediation to closure, and report status on a regular cadence
- Conduct control assessments aligned to HIPAA Security Rule and NIST CSF (with the risk framework already on the roadmap) to identify gaps
- Apply Zero Trust and modern risk-management principles to evaluate new systems, vendors, and technical decisions
- Participate in the AI use case assessment process from technical, security, and compliance perspectives
- Translate technical risk into business terms to support risk-based decision making
- Operate and maintain compliance automation in Vanta, including evidence collection, control monitoring, remediation tracking, and audit readiness
- Execute recurring access reviews and produce audit-ready documentation
- Support HIPAA compliance activities such as risk assessments, vendor security reviews, BAA tracking, and policy enforcement across SaaS systems
- Conduct vendor and third-party risk assessments for new SaaS purchases, and maintain the vendor risk register
- Support ongoing security monitoring and log review to confirm controls (including NIST CSF controls) operate as intended
Requirements
- 4–6+ years in cybersecurity risk management, GRC, or security operations with real ownership of both hands-on security administration and a structured risk/compliance program
- Experience running a formal risk management process end-to-end for example under NIST RMF, ISO 27001, NIST CSF, or an equivalent framework
- Experience with identity providers and SSO: SAML, OIDC, SCIM, and MFA policy design
- Experience with compliance automation platforms such as Vanta, Drata, Secureframe, or similar
- Comfort with APIs and integration concepts including OAuth flows, API tokens, scopes, and webhooks
- Strong scripting and automation skills (for example Python or Bash) used for secure integration work and incident investigation support such as log analysis and automating recurring checks
- Strong documentation habits including risk registers, access review records, runbooks, and vendor assessments suitable for audit
- Professional English (written and spoken); Spanish is a plus
Benefits
- $95,000 – $135,000 annually depending on experience
- Medical
- Dental
- Fully remote
Nice to Have
- Fluent written and oral Spanish in addition to English
- Demonstrated ability to communicate risk to non-technical stakeholders and support executive-level, risk-based decision making
- Experience in a HIPAA-regulated or otherwise regulated/high-compliance environment
- Familiarity with Zero Trust Architecture principles
- Familiarity with the stack: Google Workspace, GCP, Cloudflare, Vanta, HubSpot, Stripe, BigQuery
- Certifications such as Security+, CySA+, or similar
Technology (Security) • Full-time • Remote (United States)
Reports to: CISO
Similar Jobs
P