{"id":2030574,"url":"https://alion.io/job/openloop-health-staff-security-engineer","title":"Staff Security Engineer","company":{"id":678301,"name":"OpenLoop Health","domain":"openloophealth.com","url":"https://alion.io/company/openloophealth","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"A","score":85,"open_postings":5,"ghost_share":0,"stale_share":0.6,"repost_share":0,"time_to_fill_p50_days":33,"computed_at":"2026-10-09T06:01:00Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Dallas, United States","Nashville, United States","Des Moines, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":119000,"max_usd":240000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":297},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"CI/CD","optional":false},{"name":"CIS Benchmarks","optional":false},{"name":"DNS","optional":false},{"name":"Google Workspace","optional":false},{"name":"HIPAA","optional":false},{"name":"IAM","optional":false},{"name":"Least Privilege","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SOC 2","optional":false},{"name":"Threat Modeling","optional":false},{"name":"VPN","optional":false},{"name":"Windows","optional":false},{"name":"Okta","optional":true}],"status":"live","first_seen_at":"2026-10-07T13:14:01Z","employer_posted_date":"2026-10-07","last_verified_at":"2026-10-09T21:53:17Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"About OpenLoop\nOpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.\nAbout the Role\nOpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. We deliver white-labeled clinical and operational infrastructure that helps companies scale virtual care across all 50 states: telehealth delivery, clinician staffing, licensing, payer coverage, and revenue cycle management. Our clients run on our platform under their own brand, which means their patients’ trust depends on how well we protect it. We operate in a regulated environment (HIPAA, HITRUST, SOC 2) with protected health information in scope across much of the business - security here is not a checkbox, it is part of how we deliver care.\nWe’re hiring a Staff Security Engineer to own and mature the security of the systems our workforce depends on every day, with a focus on endpoints and email. You’ll be a hands-on generalist with deep engineering expertise in those two areas, and you’ll set the technical bar for them across OpenLoop and our subsidiaries.\nSecurity Architecture & Engineering (SAE) builds and owns the security platform; our Security Operations team consumes it for detection and response. In this role you engineer, deploy, and harden the controls, and you partner closely with SecOps so the telemetry and tooling you build actually serve their mission.\nAt the Staff level, your impact goes beyond your own tickets. You’ll build controls that hold up for years, write the standards and baselines other engineers follow, and raise the technical bar of the team around you.\nWhat You’ll Do\nEndpoint security\nOwn the engineering of security controls for our macOS and Windows fleet, including device management (MDM), disk encryption, patch compliance, and local admin controls.\n\nEngineer MDM and mobile application management (MAM) policies that protect company and PHI data on both managed devices and BYOD, including app protection, conditional access, and selective wipe.\n\nDeploy and manage an enterprise browser to secure SaaS and web access, including data controls (copy/paste, download, print), session policies, and extension management.\n\nBuild, apply, and continuously measure CIS Benchmark baselines across the fleet. Track drift, manage documented exceptions, and produce fleet-level evidence that holds up to HITRUST and SOC 2 auditors.\n\nDrive application control and least-privilege on endpoints without breaking the clinicians and operators who depend on them.\n\nEmail security\nOwn email security for our Google Workspace environment: SPF, DKIM, DMARC enforcement, phishing and BEC defenses, attachment and link protection, and data loss prevention for PHI.\n\nTune controls to reduce real risk and false positives, and partner with SecOps on phishing triage workflows.\n\nAcross the program\nWrite security standards, configuration baselines, and runbooks that others can follow without you in the room.\n\nImplement and validate controls identified through threat modeling and security reviews.\n\nContribute to audit readiness by mapping controls to HITRUST and SOC 2 requirements and owning evidence for your domains.\n\nAutomate repetitive work. If you’ve done it twice by hand, script it.\n\nMentor engineers on SAE and adjacent teams, and serve as an escalation point during incidents in your domains.\n\nPartner with IT, Engineering, Compliance, and SecOps, translating security risk into business and operational terms.\n\nOther duties as assigned.\n\nWho You Are\nYou treat patient safety and integrity as non-negotiable - speed never outruns integrity where care is involved. You own outcomes end to end, not just your part. You say the thing and explain the why, and you start from what we’re solving and why it matters now. At the Staff level that shows up as judgment other engineers borrow: you build the control that holds up, write the standard people actually follow, and leave the team more capable than you found it.\nRequired Qualifications\n8+ years in security engineering, with a track record of owning outcomes end to end.\n\nDeep, hands-on expertise in endpoint security and email security.\n\nExperience deploying and operating MDM/MAM platforms (Kandji, Jamf, Intune, or similar) and email security platforms.\n\nExperience deploying and managing an enterprise browser platform.\n\nHands-on experience implementing CIS Benchmarks and measuring compliance against them at fleet scale.\n\nExposure to network security: secure remote access (ZTNA/VPN), DNS filtering, segmentation, or firewall policy.\n\nWorking knowledge of cloud security fundamentals (AWS preferred): IAM, network controls, logging, and how workforce access reaches cloud environments.\n\nExposure to DevSecOps practices: infrastructure as code, CI/CD security, secrets management, or security tooling in pipelines.\n\nScripting ability in Python, Bash, PowerShell, or similar.\n\nExperience working in a regulated environment (HIPAA, HITRUST, SOC 2, PCI, or similar) and producing audit evidence.\n\nClear written communication. You can write a standard, defend a decision, and explain a risk to a non-security executive.\n\nPreferred Qualifications\nHealthcare or health tech experience, especially environments handling PHI.\n\nExperience with Okta or another enterprise identity provider.\n\nExperience supporting a multi-entity organization with subsidiaries or acquisitions.\n\nRelevant certifications (GIAC, CISSP, OSCP, or cloud security certs) - a plus, not a requirement.\n\nWhat We Offer\nCompetitive compensation\n\nMedical, Dental & Vision\n\nFlexible Spending / Health Savings Accounts\n\nGenerous PTO and hybrid-work flexibility\n\n401(k) with Company Match\n\nLife Insurance, Pet Insurance, and more\n\nOur Company\nWe have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.\nSound like a good fit? We’d love to meet you.","description_format":"text","description_chars":6318,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Life insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Health Care","Telemedicine & Virtual Care","Pharmacies"],"lifecycle":[{"event":"open","at":"2026-10-07T14:14:04Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"H-1B filings in 12 months: 2","filings_12m":2,"filings_prev_12m":0,"green_card_filings_12m":0,"median_offered_wage_usd":172500,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)"],"filings_for_role_12m":0}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":33,"reasons":["conf:0","velocity","win:early"],"computed_at":"2026-10-09T06:01:00Z"},"pay":null,"html_url":"https://alion.io/job/openloop-health-staff-security-engineer","json_url":"https://alion.io/job/openloop-health-staff-security-engineer.json","meta":{"generated_at":"2026-10-10T00:47:40Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1258,"day_limit":5000,"remaining_today":3742,"minute_limit":60,"resets_at":"2026-10-11T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":678301},"rest":"https://alion.io/mcp/rest/get_company?id=678301"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fopenloop-health-staff-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fopenloop-health-staff-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fopenloop-health-staff-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/openloop-health-staff-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fopenloop-health-staff-security-engineer"}]}