# Vulnerability & Attack Surface Management Analyst II at OpenLoop

- Company: OpenLoop
- What the company does: OpenLoop is the white label telehealth platform trusted by 400+ virtual care brands. Clinicians, pharmacy, diagnostics, AI — all under your brand. Backed by Techstars.
- Company website: https://openloophealth.com
- Type: Startups (AI role)
- Level: Analyst
- Location: United States - Remote
- Work setup: Remote
- Posted: 2026-09-24
- Apply by: 2026-11-08
- Apply: https://jobs.ashbyhq.com/openloophealth/58983e15-f590-452c-b0e8-ac978dcb1391
- Page: https://www.1752.vc/careers/jobs/openloop-vulnerability-and-attack-surface-management-analyst-ii/

## About the role

OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Security Operations at OpenLoop protects patient data, clinical operations, and the systems our partners build on. We handle PHI, we’re subject to HIPAA, and care delivery depends on our systems working.

## What they're looking for

- REQUIRED
- 3 to 6 years in security, with significant hands-on experience in vulnerability management, attack surface management, or cloud security posture management
- Hands-on experience running and tuning a vulnerability scanning or CNAPP platform
- Experience prioritizing a large set of findings with a risk-based model, and the ability to explain how you made those calls. Working knowledge of CVSS, EPSS, and the CISA KEV catalog, and a view on how to use them together
- Cloud security fundamentals in at least one major provider (GCP or AWS preferred), including how workloads, identity, and network exposure fit together. Experience with container and image vulnerabilities and dependency (SCA) findings in code repositories
- Comfort starting with an incomplete inventory. Figuring out what exists and who owns it is a large part of this job

Tags: General and Administrative
