Job Overview
Job description
- Salary:
- USD 110,000 - 130,000 per year
- Location:
- United States
- Work arrangement:
- On-site
Role Summary
- Location: Remote | Reports to: CISO
- About VetClaims.AI
- VetClaims.AI is a fast-growing startup providing educational tools and AI-driven guidance to
- help veterans understand and complete VA disability claims. We're building technology that
- makes a real difference in veterans' lives, and we take the security and privacy of their data
seriously.
- You'll work alongside our CISO as the hands-on leader of security execution, owning the
- implementation of our security strategy end to end. You'll design and deploy our security control
- framework, build our detection and incident response capabilities, and drive HIPAA compliance
- across the organization — from technical safeguards in our platform to administrative policies
and workforce training.
This is a builder's leadership role that combines strategy with engineering. You'll help shape the
roadmap with the CISO, then make it real — building tooling and automations yourself where
off-the-shelf solutions don't exist, and coordinating closely with engineering on everything else.
Responsibilities
- Security Strategy & Leadership
- Partner with the CISO to define and execute VetClaims' security strategy, roadmap, and
- priorities
- Design, implement, and operate security controls across cloud infrastructure,
- applications, and corporate systems — encryption at rest and in transit, access controls,
- audit logging, and data retention
- Establish secure SDLC practices with engineering: security code review standards,
- dependency scanning, secrets management, and PHI data-handling patterns
- Detection & Response
- Design, implement, and maintain centralized logging across our infrastructure (GCP,
- Cloudflare, application logs, and others)
- Evaluate, implement, and manage SIEM or log management tooling
- Create, tune, and maintain security alerts for critical events; build monitoring for
- suspicious activity, unauthorized access, and anomalies
- Review and analyze Cloudflare analytics and threat data, and track threats targeting our
- platform
- Lead investigation and response for security incidents, and create and own incident
response playbooks.
- Vulnerability Management
- Evaluate, implement, and maintain security scanning tools, including container and
- dependency scanning
- Prioritize vulnerabilities and coordinate remediation with engineering
- Build custom integrations for vulnerability tracking and remediation workflows
- Implement monitoring and alerting for role changes, privileged access, and access
- anomalies. Suggest improvements in access and identity management across all our
tech stack.
- HIPAA & Compliance Operations
- Support HIPAA compliance end to end: administrative, physical, and technical
- safeguards under the Security Rule, Privacy Rule alignment, breach notification
- procedures, and ongoing risk assessments
- Conduct and maintain the HIPAA-required security risk analysis and drive remediation of
- gaps
- Build and maintain Vanta integrations, developing custom solutions where standard
- integrations don't exist
- Collect and manage evidence for audits and compliance reviews
- Support Business Associate Agreements and third-party/vendor risk, including
- payments, CRM, and communications integrations
- Support security and privacy awareness training for all staff
- Automation & Tooling
- Design and build security automations to reduce manual work
- Develop custom tools and integrations where off-the-shelf solutions fall short
- Maintain and continuously improve the security tooling stack
Requirements
- 7+ years in information security, with 2+ years leading security programs or teams
- Bilingual English/Spanish proficiency (fluent in verbal and written communication in both languages)
- Hands-on experience securing cloud-native SaaS platforms, with log management or
- SIEM tooling experience
- Scripting skills (Python, Bash, or similar) and comfort working with APIs to build custom
- integrations and tools
- Track record implementing a security framework like (NIST CSF, NIST AI RMF, ISO
- 27001) and conducting formal risk assessments
- Strong communication skills — able to translate risk for executives, engineers, and non-
- technical staff
- Willingness to learn and build in a startup environment
Nice to Have
Direct experience building or running HIPAA compliance programs in a healthcare,
healthtech, PHI-handling environment or PCI-SSC
- Experience with GCP and Cloudflare
Experience with compliance automation platforms like Vanta, Drata, among others
- Bilingual Spanish/English
Certifications like,CSFPC, CompTIA Security+
Benefits
Opportunity to build the security function from the ground up
Direct impact on protecting veterans' sensitive data
- Collaborative, remote-first team
- Competitive salary and benefits
- Room to grow as the company scales
- Role:
- Cybersecurity Lead
- Job Type:
- Contractor
Company profile
VetClaims.ai
vetclaims.aiVetClaims.ai is a veteran-owned company that helps veterans secure the VA disability benefits they have earned, combining AI with expert support. It prepares file-ready VA claim packages in 30 days for a flat fee, with evidence-backed nexus letters and VA case law, and says it handles 99% of the work. VetClaims.ai reports 43K+ veterans guided and was founded by a Purple Heart veteran.
- Founders
- Lukas Simianer