Startups · AI

Vulnerability & Attack Surface Management Analyst II

OpenLoop · United States - Remote · Remote

← All jobs
About OpenLoop

OpenLoop is the white label telehealth platform trusted by 400+ virtual care brands. Clinicians, pharmacy, diagnostics, AI — all under your brand. Backed by Techstars.

About the role

OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Security Operations at OpenLoop protects patient data, clinical operations, and the systems our partners build on. We handle PHI, we’re subject to HIPAA, and care delivery depends on our systems working.

What they're looking for

  • REQUIRED
  • 3 to 6 years in security, with significant hands-on experience in vulnerability management, attack surface management, or cloud security posture management
  • Hands-on experience running and tuning a vulnerability scanning or CNAPP platform
  • Experience prioritizing a large set of findings with a risk-based model, and the ability to explain how you made those calls. Working knowledge of CVSS, EPSS, and the CISA KEV catalog, and a view on how to use them together
  • Cloud security fundamentals in at least one major provider (GCP or AWS preferred), including how workloads, identity, and network exposure fit together. Experience with container and image vulnerabilities and dependency (SCA) findings in code repositories
  • Comfort starting with an incomplete inventory. Figuring out what exists and who owns it is a large part of this job
More about this role

OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.

OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Security Operations at OpenLoop protects patient data, clinical operations, and the systems our partners build on. We handle PHI, we’re subject to HIPAA, and care delivery depends on our systems working.

We’re hiring a Vulnerability & Attack Surface Management Analyst II. Nobody at OpenLoop works on vulnerability management or attack surface management full-time today, so you’ll be the first. You’ll report to the Director of Information Security, who sets strategy and priorities for both programs. You’ll carry out that plan, and we expect you to tell us when the findings suggest the priorities should change.

Some context on where things stand. Our cloud inventory has grown about five times over this year and more than doubled in the last two...

Read the full posting on OpenLoop's site ↗

General and Administrative

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.