Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Sep 24, 2026. OpenLoop Health scores B on the Alion truth index.
About OpenLoop
OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.
About the Role
OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Security Operations at OpenLoop protects patient data, clinical operations, and the systems our partners build on. We handle PHI, we’re subject to HIPAA, and care delivery depends on our systems working.
We’re hiring a Vulnerability & Attack Surface Management Analyst II. Nobody at OpenLoop works on vulnerability management or attack surface management full-time today, so you’ll be the first. You’ll report to the Director of Information Security, who sets strategy and priorities for both programs. You’ll carry out that plan, and we expect you to tell us when the findings suggest the priorities should change.
Some context on where things stand. Our cloud inventory has grown about five times over this year and more than doubled in the last two months. We deployed Wiz eight months ago, and it’s finding far more risk than we currently have people to work. Vulnerability management gets squeezed in around other work, and attack surface management has barely started. We’re also rolling out a platform that lets internal teams publish their own applications, which will grow our external footprint faster than anything else this year.
The program is early. You’ll help build it, with a direction already set. You’ll take a very large set of findings and narrow it to what matters using the risk model we’re putting in place, get fixes shipped through engineering teams across the company, and run attack surface discovery on a regular schedule instead of only when a client asks.
What this role is not: forwarding scanner reports to engineering. You own the fix through verification. It’s also not incident response or forensics (you’ll work with our IR team, but your focus is exposure and remediation), not a GRC role (you’ll help with audits and client reviews, but the day-to-day work is operational), and not a tool evaluation role. The platforms are in place, and the job is getting results from them.
What You’ll Do
Run the vulnerability lifecycle day to day: discovery, validation, prioritization, remediation tracking, verification, and reporting across cloud workloads, containers, code repositories, and endpoints.
Prioritize by actual risk, not raw CVSS. Apply and improve our risk model, which weighs internet exposure, exploitability (CISA KEV, EPSS), asset criticality, and data sensitivity. When the model needs to change, bring the evidence. When something is being deprioritized, make that visible so the decision is made on purpose.
Build a reliable asset inventory. Combine cloud, endpoint, and SaaS inventory into one view, with a named owner for every asset that matters. Most assets don’t have an owner today, so this is your first and most important deliverable. After that, run external discovery on a set schedule to find what we have exposed to the internet, including things nobody told us about.
Drive remediation. Get fixes done through Engineering, IT, and Platform teams. Write tickets people can act on, agree on realistic timelines, escalate to the Director when you’re blocked, and confirm the fix is in place.
Fix problems at the source and automate repetitive work. Roll out hardened base images and dependency baselines so a single upstream change closes thousands of findings. We’ve piloted this and it works, and you’ll lead the broader rollout. Connect scanner and CNAPP APIs to ticketing and reporting. If you find yourself building the same report by hand twice, automate it.
Own web application security. Run dynamic scans of our web properties, work fixes through application teams, and use edge and WAF controls as temporary mitigation while the real fix ships. Keep track of which issues are mitigated and which are actually fixed.
Set up security checks for the new publishing platform. Make sure internally built, externally published applications are inventoried and scanned before they go live, and raise gaps early while the process is still being designed.
Manage vulnerability disclosure and bug bounty intake. Validate researcher reports, check them against known issues, respond promptly and professionally, and see valid reports through to a verified fix. Escalate disclosure and severity decisions to the Director.
Use AI tools in your daily work. Use Claude, coding assistants, and newer agent-based tools to triage at volume, correlate findings, draft remediation guidance, and produce reports. Use good judgment about what data goes into which tool, since we handle PHI. With this many findings and a small team, these tools are a core part of how the work gets done.
Track and report metrics. Report mean time to remediate, backlog burn-down, and SLA coverage. Prepare the reporting the Director presents to leadership, and pull together evidence for client, partner, and auditor requests in our HIPAA-regulated environment.
Who You Are
You own your work from start to finish. A finding is done when the fix is verified, not when the ticket is filed. You’re comfortable working a backlog that will never reach zero. You’re direct: you state your view, explain your reasoning, and welcome disagreement, including from engineers who push back on a severity rating. You’re willing to argue that something shouldn’t be worked, and you’re fine being overruled. When thousands of findings share one root cause, you go after the root cause. You treat patient safety and data integrity as requirements. You already use AI tools in your work, you have opinions about where they help and where they don’t, and you’re careful about what goes into them.
REQUIRED
3 to 6 years in security, with significant hands-on experience in vulnerability management, attack surface management, or cloud security posture management.
Hands-on experience running and tuning a vulnerability scanning or CNAPP platform.
Experience prioritizing a large set of findings with a risk-based model, and the ability to explain how you made those calls. Working knowledge of CVSS, EPSS, and the CISA KEV catalog, and a view on how to use them together.
Cloud security fundamentals in at least one major provider (GCP or AWS preferred), including how workloads, identity, and network exposure fit together. Experience with container and image vulnerabilities and dependency (SCA) findings in code repositories.
Comfort starting with an incomplete inventory. Figuring out what exists and who owns it is a large part of this job.
Experience working directly with engineering teams to get fixes shipped.
Scripting skills (Python, PowerShell, or similar) sufficient to query APIs and automate reporting.
Regular, hands-on use of AI tools (Claude, ChatGPT, GitHub Copilot, or similar) in security work. Be ready to share specific examples of how they improved your speed or quality, and explain how you decide what’s safe to share with them when PHI, credentials, or sensitive data are involved.
Strong writing. You can write a ticket an engineer will act on and a risk summary an executive will understand, and you know those are different documents.
PREFERRED
VM and CNAPP platforms: Wiz especially, since it’s our primary platform and experience with it will shorten your ramp-up. Also useful: Orca, Prisma Cloud, Defender for Cloud, or Lacework; CrowdStrike Falcon Exposure Management or Spotlight; Tenable, Qualys, or Rapid7 for non-cloud assets.
Attack surface and asset inventory: external ASM tools and recon methods (DNS, certificate transparency, subdomain and shadow IT discovery), CAASM and inventory platforms such as Axonius or runZero, and SaaS discovery tools.
Application and edge security: DAST and edge/WAF platforms (Invicti, Burp Suite, Cloudflare, Akamai), and vulnerability disclosure or bug bounty programs (HackerOne, Bugcrowd), including researcher communication, report validation, and duplicate handling.
Platform and supply chain: hardened or minimal base images (Chainguard, distroless, or an in-house golden image program), Kubernetes and container security at scale (we run GKE and EKS), PaaS/edge hosting such as Vercel, Netlify, or Cloudflare Pages, SBOMs and software supply chain security, and automation connecting scanner APIs to Jira, Slack, or reporting pipelines.
Regulated environments: experience in healthcare, fintech, or another regulated industry, and hands-on HIPAA, HITRUST, or SOC 2 work, especially providing vulnerability management evidence to auditors and clients.
Certifications: GCLD, GCPN, GWEB, GSEC, AWS or GCP security specialty, OSCP, or equivalent experience.
What We Offer
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings Accounts
Generous PTO and hybrid-work flexibility
401(k) with Company Match
Life Insurance, Pet Insurance, and more
Our Company
We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.
Sound like a good fit? We’d love to meet you.

