Openloophealth
Vulnerability & Attack Surface Management Analyst II
United States - Remote
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Mid level
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 24 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About OpenLoop
OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.
About the Role
OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Security Operations at OpenLoop protects patient data, clinical operations, and the systems our partners build on. We handle PHI, we’re subject to HIPAA, and care delivery depends on our systems working.
We’re hiring a Vulnerability & Attack Surface Management Analyst II. Nobody at OpenLoop works on vulnerability management or attack surface management full-time today, so you’ll be the first. You’ll report to the Director of Information Security, who sets strategy and priorities for both programs. You’ll carry out that plan, and we expect you to tell us when the findings suggest the priorities should change.
Some context on where things stand. Our cloud inventory has grown about five times over this year and more than doubled in the last two months. We deployed Wiz eight months ago, and it’s finding far more risk than we currently have people to work. Vulnerability management gets squeezed in around other work, and attack surface management has barely started. We’re also rolling out a platform that lets internal teams publish their own applications, which will grow our external footprint faster than anything else this year.
The program is early. You’ll help build it, with a direction already set. You’ll take a very large set of findings and narrow it to what matters using the risk model we’re putting in place, get fixes shipped through engineering teams across the company, and run attack surface discovery on a regular schedule instead of only when a client asks.
What this role is not: forwarding scanner reports to engineering. You own the fix through verification. It’s also not incident response or forensics (you’ll work with our IR team, but your focus is exposure and remediation), not a GRC role (you’ll help with audits and client reviews, but the day-to-day work is operational), and not a tool evaluation role. The platforms are in place, and the job is getting results from them.
What You’ll Do
Run the vulnerability lifecycle day to day: discovery, validation, prioritization, remediation tracking, verification, and reporting across cloud workloads, containers, code repositories, and endpoints.
Prioritize by actual risk, not raw CVSS. Apply and improve our risk model, which weighs internet exposure, exploitability (CISA KEV, EPSS), asset criticality, and data sensitivity. When the model needs to change, bring the evidence. When something is being deprioritized, make that visible so the decision is made on purpose.
Build a reliable asset inventory. Combine cloud, endpoint, and SaaS inventory into one view, with a named owner for every asset that matters. Most assets don’t have an owner today, so this is your first and most important deliverable. After that, run external discovery on a set schedule to find what we have exposed to the internet, including things nobody told us about.
Drive remediation. Get fixes done through Engineering, IT, and Platform teams. Write tickets people can act on, agree on realistic timelines, escalate to the Director when you’re blocked, and confirm the fix is in place.
Fix problems at the source and automate repetitive work. Roll out hardened base images and dependency baselines so a single upstream change closes thousands of findings. We’ve piloted this and it works, and you’ll lead the broader rollout. Connect scanner and CNAPP APIs to ticketing and reporting. If you find yourself building the same report by hand twice, automate it.
Own web application security. Run dynamic scans of our web properties, work fixes through application teams, and use edge and WAF controls as temporary mitigation while the real fix ships. Keep track of which issues are mitigated and which are actually fixed.
Set up security checks for the new publishing platform. Make sure internally built, externally published applications are inventoried and scanned before they go live, and raise gaps early while the process is still being designed.
Manage vulnerability disclosure and bug bounty intake. Validate researcher reports, check them against known issues, respond promptly and professionally, and see valid reports through to a verified fix. Escalate disclosure and severity decisions to the Director.
Use AI tools in your daily work. Use Claude, coding assistants, and newer agent-based tools to triage at volume, correlate findings, draft remediation guidance, and produce reports. Use good judgment about what data goes into which tool, since we handle PHI. With this many findings and a small team, these tools are a core part of how the work gets done.
Track and report metrics. Report mean time to remediate, backlog burn-down, and SLA coverage. Prepare the reporting the Director presents to leadership, and pull together evidence for client, partner, and auditor requests in our HIPAA-regulated environment.
Who You Are
You own your work from start to finish. A finding is done when the fix is verified, not when the ticket is filed. You’re comfortable working a backlog that will never reach zero. You’re direct: you state your view, explain your reasoning, and welcome disagreement, including from engineers who push back on a severity rating. You’re willing to argue that something shouldn’t be worked, and you’re fine being overruled. When thousands of findings share one root cause, you go after the root cause. You treat patient safety and data integrity as requirements. You already use AI tools in your work, you have opinions about where they help and where they don’t, and you’re careful about what goes into them.
REQUIRED
3 to 6 years in security, with significant hands-on experience in vulnerability management, attack surface management, or cloud security posture management.
Hands-on experience running and tuning a vulnerability scanning or CNAPP platform.
Experience prioritizing a large set of findings with a risk-based model, and the ability to explain how you made those calls. Working knowledge of CVSS, EPSS, and the CISA KEV catalog, and a view on how to use them together.
Cloud security fundamentals in at least one major provider (GCP or AWS preferred), including how workloads, identity, and network exposure fit together. Experience with container and image vulnerabilities and dependency (SCA) findings in code repositories.
Comfort starting with an incomplete inventory. Figuring out what exists and who owns it is a large part of this job.
Experience working directly with engineering teams to get fixes shipped.
Scripting skills (Python, PowerShell, or similar) sufficient to query APIs and automate reporting.
Regular, hands-on use of AI tools (Claude, ChatGPT, GitHub Copilot, or similar) in security work. Be ready to share specific examples of how they improved your speed or quality, and explain how you decide what’s safe to share with them when PHI, credentials, or sensitive data are involved.
Strong writing. You can write a ticket an engineer will act on and a risk summary an executive will understand, and you know those are different documents.
PREFERRED
VM and CNAPP platforms: Wiz especially, since it’s our primary platform and experience with it will shorten your ramp-up. Also useful: Orca, Prisma Cloud, Defender for Cloud, or Lacework; CrowdStrike Falcon Exposure Management or Spotlight; Tenable, Qualys, or Rapid7 for non-cloud assets.
Attack surface and asset inventory: external ASM tools and recon methods (DNS, certificate transparency, subdomain and shadow IT discovery), CAASM and inventory platforms such
Similar jobs
- Product Management AnalystUline · 5 LocationsFirst seen today
- Health Information Management Analyst - 100% OnsiteSturdymemorial · Attleboro, MAFirst seen today
- Health Information Management Analyst (Temporary) - 100% OnsiteSturdymemorial · Attleboro, MAFirst seen today
- Governance Risk Compliance Wealth Management AnalystRegions · Hoover, AL - Riverchase North Building (Birmingham, AL)First seen today
- Software Configuration Management Analyst (Level 2 or 3)Ngc · United States-California-PalmdaleFirst seen today
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job