Cybersecurity Risk & Compliance Analyst

Cybersecurity Jobs

United States

Remote

USD 95,000 - 135,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Fully remote

Job summary

PATRIOTCLAIMS LLC is seeking a Cybersecurity Risk & Compliance Analyst to strengthen operational security in a HIPAA‑regulated SaaS environment. This remote role reports to the CISO and supports risk governance, incident work, and audit readiness across the organization.

You will own security administration, run risk management, and contribute to vendor risk activities, including evidence automation in Vanta, while blending IAM, vulnerability monitoring, and cross‑functional assessments of

Qualifications

  • 4–6+ years in cybersecurity risk management, GRC, or security operations roles.
  • Experience running formal risk management end-to-end under a recognized framework (NIST RMF/ISO 27001/NIST CSF).
  • Experience with identity providers and SSO (Google Workspace, Okta, Entra ID) with SAML/OIDC/SCIM/MFA policy design.
  • Experience with compliance automation platforms such as Vanta, Drata, or Secureframe.

Responsibilities

  • Own key areas of security administration and structured risk management.
  • Contribute to incident response documentation and remediation tracking.
  • Maintain evidence automation in Vanta for audit readiness.
  • Review integration requests for security and compliance impact before approval.
  • Operate and maintain a structured risk management program and report status.

Skills

Risk management
GRC
Security operations
Documentation
Python scripting
Bash scripting
SSO policy design

Education

Bachelor's degree in Cybersecurity

Tools

Vanta
Drata
Secureframe
Cloudflare WAF
Cloudflare Log Explorer
OAuth flows
webhooks
API tokens
GCP
Google Workspace
Okta
Entra ID

Job description

PATRIOTCLAIMS LLC is seeking a Cybersecurity Risk & Compliance Analyst to strengthen operational security in a HIPAA-regulated SaaS environment. This remote role reports to the CISO and helps maintain compliance and audit readiness while supporting security operations, risk governance, and incident-related work across the organization.

In this position, you will own key areas of security administration, run structured risk management, and contribute to ongoing control and vendor risk activities, including evidence automation in Vanta. The role blends hands-on identity and access management, vulnerability and log-informed monitoring, and cross-functional assessment of integrations, AI use cases, and third-party SaaS.

Core Responsibilities
  • Own the company-wide SaaS application inventory, including access management using SSO/SAML/OIDC, MFA, and SCIM provisioning/deprovisioning, along with configuration hardening aligned to vendor and industry baselines
  • Manage joiner/mover/leaver access lifecycle processes using least-privilege principles
  • Monitor security posture and remediate SaaS and cloud misconfigurations
  • Run vulnerability management across the SaaS and cloud environment by identifying, prioritizing, and tracking vulnerabilities to remediation, leveraging existing monitoring tools such as Cloudflare WAF and Cloudflare Log Explorer, plus additional scanning tools as needed
  • Support investigation of security incidents and suspicious activity, including scoping, containment, and documented findings, using scripting when helpful for log analysis or investigation automation
  • Contribute to post-incident documentation and follow-up remediation tracking
  • Support secure implementation of internal-to-third-party integrations, including API key management, OAuth scopes, service account governance, and webhook security
  • Review integration requests from Engineering and business stakeholders to assess security and compliance impact before approval
  • Operate an ongoing, structured risk management program by identifying risks, assessing severity and likelihood, tracking remediation to closure, and reporting status on a regular cadence
  • Conduct control assessments against the adopted frameworks, including the HIPAA Security Rule and NIST CSF (risk framework already on the roadmap), and identify gaps
  • Apply Zero Trust and modern risk-management principles when evaluating new systems, vendors, and technical decisions
  • Participate in the company’s AI use case assessment process from technical, security, and compliance perspectives
  • Translate technical risk into business terms to support risk-based decision-making
  • Operate and maintain compliance automation in Vanta for evidence collection, control monitoring, remediation tracking, and audit readiness
  • Execute recurring access reviews and produce audit-ready documentation
  • Support HIPAA compliance activities such as risk assessments, vendor security reviews, BAA tracking, and policy enforcement across SaaS systems
  • Conduct vendor and third-party risk assessments for new SaaS purchases and maintain the vendor risk register
  • Support ongoing security monitoring and log review to confirm controls are functioning as intended, including controls mapped to NIST CSF
Requirements
  • 4–6+ years in cybersecurity risk management, GRC, or security operations roles, with demonstrated ownership of both hands-on security administration and a structured risk/compliance program
  • Experience running a formal risk management process end-to-end under a recognized framework such as NIST RMF, ISO 27001, NIST CSF, or an equivalent approach
  • Experience with identity providers and SSO, including Google Workspace, Okta, Entra ID (or similar), with SAML, OIDC, SCIM, and MFA policy design
  • Experience with compliance automation platforms such as Vanta, Drata, or Secureframe
  • Comfort with APIs and integration concepts including OAuth flows, API tokens, scopes, and webhooks
  • Strong scripting and automation skills (such as Python or Bash) used for secure integration work and supporting incident investigations (for example, log analysis and automating recurring checks)
  • Strong documentation habits including risk registers, access review records, runbooks, and vendor assessments that stand up to audit
  • Professional English (written and spoken); Spanish is a plus
Technologies
  • HIPAA Security Rule, NIST CSF, NIST RMF, ISO 27001
  • SSO, SAML, OIDC, MFA, SCIM, Zero Trust
  • Vanta, Drata, Secureframe
  • Cloudflare WAF, Cloudflare Log Explorer
  • Python, Bash
  • OAuth, webhooks, API tokens, service account governance
  • Google Workspace, Okta, Entra ID, GCP
  • HubSpot, Stripe, BigQuery
Benefits
  • $95,000–$135,000 annually depending on experience
  • Medical
  • Dental
  • Fully remote
Nice to Have
  • Fluent written and oral Spanish in addition to English
  • Ability to communicate risk to non-technical stakeholders and support executive-level, risk-based decision making
  • Experience in a HIPAA-regulated or otherwise regulated/high-compliance environment
  • Familiarity with Zero Trust Architecture principles
  • Familiarity with the stack: Google Workspace, GCP, Cloudflare, Vanta, HubSpot, Stripe, BigQuery
  • Certifications such as Security+, CySA+, or similar
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

InfoSec & IT Lead
InfoSec & IT Lead

RevOptimal LLC • New Orleans (LA), Northern (KY)

Hybrid
USD 120,000 - 170,000
IT & Security Engineer (Part Time)
IT & Security Engineer (Part Time)

Ultimate Staffing Services • Salt Lake City (UT)

Hybrid
USD 50,000 - 59,000
Security Engineer
Security Engineer

Cortavo, Inc. • Atlanta (GA)

On-site
USD 100,000 - 130,000
Competitive salary
Health benefits
Company cell phone plan
+2
Senior Security Engineer
Senior Security Engineer

AgelessRx • Town of Montana (WI)

On-site
USD 140,000 - 170,000
Senior Manager, Security & IT Ops
Senior Manager, Security & IT Ops

Hazelcast • Northern (KY)

Hybrid
USD 120,000 - 160,000
Unlimited PTO
Medical/Dental/Vision Insurance
HSA/FSA
+3
IT Security & Compliance Lead (Healthcare)
IT Security & Compliance Lead (Healthcare)

Premium Health Center • New York (NY)

On-site
USD 140,000 - 210,000
Paid time off
Medical, dental, and vision plans
Retirement plans
+1
Senior Security Engineer
Senior Security Engineer

Translucent • New York (NY)

On-site
USD 180,000 - 250,000
Equity
In-office 4 days/week
Competitive compensation
Senior Security Engineer
Senior Security Engineer

Translucent AI • New York (NY)

On-site
USD 180,000 - 250,000
Equity
In-office 4 days/week
Senior Security Engineer
Senior Security Engineer

agelessrx • United States

On-site
USD 150,000 - 190,000
Senior Manager of Governance, Risk, and Compliance
Senior Manager of Governance, Risk, and Compliance

Maven Clinic • United States

On-site
USD 140,000 - 180,000
Parental leave
401K matching
Professional development stipend
+2