Cybersecurity Lead

Summary

Cybersecurity Lead at a health-tech startup, owning hands-on security strategy implementation, detection and incident response, HIPAA compliance, and security automation across a cloud-native SaaS platform.

Location: Remote | Reports to: CISO

About VetClaims.AI

VetClaims.AI is a fast-growing startup providing educational tools and AI-driven guidance to

help veterans understand and complete VA disability claims. We're building technology that

makes a real difference in veterans' lives, and we take the security and privacy of their data

seriously.

About the Role

You'll work alongside our CISO as the hands-on leader of security execution, owning the

implementation of our security strategy end to end. You'll design and deploy our security control

framework, build our detection and incident response capabilities, and drive HIPAA compliance

across the organization — from technical safeguards in our platform to administrative policies

and workforce training.

This is a builder's leadership role that combines strategy with engineering. You'll help shape the

roadmap with the CISO, then make it real — building tooling and automations yourself where

off-the-shelf solutions don't exist, and coordinating closely with engineering on everything else.

What You'll Do

Security Strategy & Leadership

  • Partner with the CISO to define and execute VetClaims' security strategy, roadmap, and

priorities

  • Design, implement, and operate security controls across cloud infrastructure,

applications, and corporate systems — encryption at rest and in transit, access controls,

audit logging, and data retention

  • Establish secure SDLC practices with engineering: security code review standards,

dependency scanning, secrets management, and PHI data-handling patterns

Detection & Response

  • Design, implement, and maintain centralized logging across our infrastructure (GCP,

Cloudflare, application logs, and others)

  • Evaluate, implement, and manage SIEM or log management tooling
  • Create, tune, and maintain security alerts for critical events; build monitoring for

suspicious activity, unauthorized access, and anomalies

  • Review and analyze Cloudflare analytics and threat data, and track threats targeting our

platform

  • Lead investigation and response for security incidents, and create and own incident

response playbooks.

Vulnerability Management

  • Evaluate, implement, and maintain security scanning tools, including container and

dependency scanning

  • Prioritize vulnerabilities and coordinate remediation with engineering
  • Build custom integrations for vulnerability tracking and remediation workflows
  • Implement monitoring and alerting for role changes, privileged access, and access

anomalies. Suggest improvements in access and identity management across all our

tech stack.

HIPAA & Compliance Operations

  • Support HIPAA compliance end to end: administrative, physical, and technical

safeguards under the Security Rule, Privacy Rule alignment, breach notification

procedures, and ongoing risk assessments

  • Conduct and maintain the HIPAA-required security risk analysis and drive remediation of

gaps

  • Build and maintain Vanta integrations, developing custom solutions where standard

integrations don't exist

  • Collect and manage evidence for audits and compliance reviews
  • Support Business Associate Agreements and third-party/vendor risk, including

payments, CRM, and communications integrations

  • Support security and privacy awareness training for all staff

Automation & Tooling

  • Design and build security automations to reduce manual work
  • Develop custom tools and integrations where off-the-shelf solutions fall short
  • Maintain and continuously improve the security tooling stack

What We're Looking For

Required

  • 7+ years in information security, with 2+ years leading security programs or teams
  • Bilingual English/Spanish proficiency (fluent in verbal and written communication in both languages)
  • Hands-on experience securing cloud-native SaaS platforms, with log management or

SIEM tooling experience

  • Scripting skills (Python, Bash, or similar) and comfort working with APIs to build custom

integrations and tools

  • Track record implementing a security framework like (NIST CSF, NIST AI RMF, ISO

27001) and conducting formal risk assessments

  • Strong communication skills — able to translate risk for executives, engineers, and non-

technical staff

  • Willingness to learn and build in a startup environment

Nice to Have

  • Direct experience building or running HIPAA compliance programs in a healthcare,

healthtech, PHI-handling environment or PCI-SSC

● Experience with GCP and Cloudflare

  • Experience with compliance automation platforms like Vanta, Drata, among others

● Bilingual Spanish/English

  • Certifications like,CSFPC, CompTIA Security+

What We Offer

  • Opportunity to build the security function from the ground up
  • Direct impact on protecting veterans' sensitive data

● Collaborative, remote-first team

● Competitive salary and benefits

● Room to grow as the company scales

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available