Vulnerability & Attack Surface Management Analyst II @OpenLoop Health
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 6d ago

[Hiring] Vulnerability & Attack Surface Management Analyst II @OpenLoop Health

6d ago - OpenLoop Health is hiring a remote Vulnerability & Attack Surface Management Analyst II. 💸 Salary: unspecified 📍Location: USA

Role Description

OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Security Operations at OpenLoop protects patient data, clinical operations, and the trust that lets our partners build on top of us — the stakes are PHI, HIPAA, and the integrity of care delivery at scale.

We’re hiring a Vulnerability & Attack Surface Management Analyst II to be the first dedicated pair of hands on two disciplines nobody here works full-time yet. You’ll report to the Director of Information Security, who owns program strategy and priorities across vulnerability management and attack surface management. Your job is to execute against them — and to tell us what the findings say about where those priorities should go next.

Here’s the honest version of the problem:

  • Our cloud inventory has grown roughly fivefold this year and more than doubled in the last two months.
  • The CNAPP platform we deployed eight months ago is doing its job — it is telling us about far more risk than we have capacity to work.
  • Vulnerability management is being absorbed between other duties, attack surface management is barely being exercised at all.
  • We’re rolling out a platform that will let internal teams publish their own applications — growing our external surface faster than anything else we’ve done this year.

So the program is early, and you’ll help build it — with direction, not from a blank page. You’ll work a very large finding set down to what actually matters using the risk model we’re establishing, work fixes through engineering teams across the company, and run attack surface discovery on a cadence rather than when a client asks. If you like turning noise into a short, correct list of things that genuinely need to happen — and then making them happen — this is a good job.

On scope: this isn’t a scan-and-forward role — emailing a scanner report to engineering isn’t the job, driving the fix is. It isn’t incident response or forensics; you’ll partner with our IR staff, but this is exposure and remediation work. It isn’t pure GRC; you’ll support audits and client reviews, but the work is operational. And it isn’t a tooling evaluation role — we have the platforms, and this job is about getting outcomes out of them.

What You’ll Do

  • Run the vulnerability lifecycle day to day.
  • Discovery, validation, prioritization, remediation tracking, verification, and reporting across cloud workloads, containers, code repositories, and endpoints.
  • Prioritize by real risk.
  • Know what we have, who owns it, and what’s exposed.
  • Drive remediation.
  • Fix at the source, and automate the rest.
  • Run web application security.
  • Implement the gate for a new publishing platform.
  • Run coordinated disclosure intake.
  • Apply AI to the work.
  • Track and report the numbers.

Qualifications

  • 3–6 years in security, with meaningful hands-on time in vulnerability management, attack surface management, or cloud security posture.
  • Hands-on operation of a vulnerability scanning or CNAPP platform — running and tuning it, not just reading its dashboards.
  • Experience working a large finding set down using a risk-based model, and the ability to explain how the prioritization calls were made.
  • Cloud security fundamentals in at least one major provider (GCP or AWS preferred).
  • Comfort starting from an incomplete inventory.
  • Experience working directly with engineering teams to get fixes shipped.
  • Scripting and automation proficiency (Python, PowerShell, or similar).
  • Demonstrated, hands-on use of AI tools (Claude, ChatGPT, GitHub Copilot, or equivalent) in day-to-day security work.
  • Clear written communication.

Preferred Qualifications

  • VM and CNAPP platforms.
  • Attack surface and asset inventory.
  • Application and edge security.
  • Platform and supply chain.
  • Regulated environments.
  • Certifications.

Benefits

  • Competitive compensation
  • Medical, Dental & Vision
  • Flexible Spending / Health Savings Accounts
  • Generous PTO and hybrid-work flexibility
  • 401(k) with Company Match
  • Life Insurance, Pet Insurance, and more

Company Description

We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.

Sound like a good fit? We’d love to meet you.

Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Vulnerability & Attack Surface Management Analyst II @OpenLoop Health
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 6d ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 128,995+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later