Cybersecurity Lead
Summary
Cybersecurity Lead at a health-tech startup, owning hands-on security strategy implementation, detection and incident response, HIPAA compliance, and security automation across a cloud-native SaaS platform.
Location: Remote | Reports to: CISO
About VetClaims.AI
VetClaims.AI is a fast-growing startup providing educational tools and AI-driven guidance to
help veterans understand and complete VA disability claims. We're building technology that
makes a real difference in veterans' lives, and we take the security and privacy of their data
seriously.
About the Role
You'll work alongside our CISO as the hands-on leader of security execution, owning the
implementation of our security strategy end to end. You'll design and deploy our security control
framework, build our detection and incident response capabilities, and drive HIPAA compliance
across the organization — from technical safeguards in our platform to administrative policies
and workforce training.
This is a builder's leadership role that combines strategy with engineering. You'll help shape the
roadmap with the CISO, then make it real — building tooling and automations yourself where
off-the-shelf solutions don't exist, and coordinating closely with engineering on everything else.
What You'll Do
Security Strategy & Leadership
- Partner with the CISO to define and execute VetClaims' security strategy, roadmap, and
priorities
- Design, implement, and operate security controls across cloud infrastructure,
applications, and corporate systems — encryption at rest and in transit, access controls,
audit logging, and data retention
- Establish secure SDLC practices with engineering: security code review standards,
dependency scanning, secrets management, and PHI data-handling patterns
Detection & Response
- Design, implement, and maintain centralized logging across our infrastructure (GCP,
Cloudflare, application logs, and others)
- Evaluate, implement, and manage SIEM or log management tooling
- Create, tune, and maintain security alerts for critical events; build monitoring for
suspicious activity, unauthorized access, and anomalies
- Review and analyze Cloudflare analytics and threat data, and track threats targeting our
platform
- Lead investigation and response for security incidents, and create and own incident
response playbooks.
Vulnerability Management
- Evaluate, implement, and maintain security scanning tools, including container and
dependency scanning
- Prioritize vulnerabilities and coordinate remediation with engineering
- Build custom integrations for vulnerability tracking and remediation workflows
- Implement monitoring and alerting for role changes, privileged access, and access
anomalies. Suggest improvements in access and identity management across all our
tech stack.
HIPAA & Compliance Operations
- Support HIPAA compliance end to end: administrative, physical, and technical
safeguards under the Security Rule, Privacy Rule alignment, breach notification
procedures, and ongoing risk assessments
- Conduct and maintain the HIPAA-required security risk analysis and drive remediation of
gaps
- Build and maintain Vanta integrations, developing custom solutions where standard
integrations don't exist
- Collect and manage evidence for audits and compliance reviews
- Support Business Associate Agreements and third-party/vendor risk, including
payments, CRM, and communications integrations
- Support security and privacy awareness training for all staff
Automation & Tooling
- Design and build security automations to reduce manual work
- Develop custom tools and integrations where off-the-shelf solutions fall short
- Maintain and continuously improve the security tooling stack
What We're Looking For
Required
- 7+ years in information security, with 2+ years leading security programs or teams
- Bilingual English/Spanish proficiency (fluent in verbal and written communication in both languages)
- Hands-on experience securing cloud-native SaaS platforms, with log management or
SIEM tooling experience
- Scripting skills (Python, Bash, or similar) and comfort working with APIs to build custom
integrations and tools
- Track record implementing a security framework like (NIST CSF, NIST AI RMF, ISO
27001) and conducting formal risk assessments
- Strong communication skills — able to translate risk for executives, engineers, and non-
technical staff
- Willingness to learn and build in a startup environment
Nice to Have
- Direct experience building or running HIPAA compliance programs in a healthcare,
healthtech, PHI-handling environment or PCI-SSC
● Experience with GCP and Cloudflare
- Experience with compliance automation platforms like Vanta, Drata, among others
● Bilingual Spanish/English
- Certifications like,CSFPC, CompTIA Security+
What We Offer
- Opportunity to build the security function from the ground up
- Direct impact on protecting veterans' sensitive data