Please mention DailyRemote when applying
Match your resume skills with our AI powered skill match!
Upload your resume and we draft a letter for this exact role, tailored to what it asks for.
Manage vulnerability discovery, risk-based prioritization, remediation, verification, and reporting across cloud, container, code, and endpoint environments. Establish asset ownership and recurring external attack surface discovery, drive engineering fixes and automation, oversee web scanning and disclosure intake, and provide security metrics and audit evidence.
OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.
OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Security Operations at OpenLoop protects patient data, clinical operations, and the trust that lets our partners build on top of us — the stakes are PHI, HIPAA, and the integrity of care delivery at scale.
We’re hiring a Vulnerability & Attack Surface Management Analyst II to be the first dedicated pair of hands on two disciplines nobody here works full-time yet. You’ll report to the Director of Information Security, who owns program strategy and priorities across vulnerability management and attack surface management. Your job is to execute against them — and to tell us what the findings say about where those priorities should go next.
Here’s the honest version of the problem. Our cloud inventory has grown roughly fivefold this year and more than doubled in the last two months. The CNAPP platform we deployed eight months ago is doing its job — it is telling us about far more risk than we have capacity to work. Vulnerability management is being absorbed between other duties, attack surface management is barely being exercised at all, and we’re rolling out a platform that will let internal teams publish their own applications — growing our external surface faster than anything else we’ve done this year.
So the program is early, and you’ll help build it — with direction, not from a blank page. You’ll work a very large finding set down to what actually matters using the risk model we’re establishing, work fixes through engineering teams across the company, and run attack surface discovery on a cadence rather than when a client asks. If you like turning noise into a short, correct list of things that genuinely need to happen — and then making them happen — this is a good job.
On scope: this isn’t a scan-and-forward role — emailing a scanner report to engineering isn’t the job, driving the fix is. It isn’t incident response or forensics; you’ll partner with our IR staff, but this is exposure and remediation work. It isn’t pure GRC; you’ll support audits and client reviews, but the work is operational. And it isn’t a tooling evaluation role — we have the platforms, and this job is about getting outcomes out of them.
Run the vulnerability lifecycle day to day. Discovery, validation, prioritization, remediation tracking, verification, and reporting across cloud workloads, containers, code repositories, and endpoints.
Prioritize by real risk. Apply and refine the risk-based model we’re establishing — internet reachability, exploitability (CISA KEV, EPSS), asset criticality, and data sensitivity, not raw CVSS. Bring evidence for where the model needs to change, and surface what’s being deprioritized so those calls get made explicitly rather than by default.
Know what we have, who owns it, and what’s exposed. Correlate cloud, endpoint, and SaaS inventory into one usable picture with a named owner on every asset that matters — today most don’t have one, and this is your first and most valuable deliverable. Then run external discovery on a defined cadence to find what of ours is reachable from the internet, including the things nobody told us about.
Drive remediation. Work fixes through Engineering, IT, and Platform. Land tickets that are actionable, negotiate realistic timelines, escalate to the Director when you’re blocked, and follow through to verification. Attack problems, not people.
Fix at the source, and automate the rest. Push hardened base images and dependency baselines so one upstream change closes thousands of findings instead of generating thousands of tickets — we’ve started this and proven it works, and you’ll drive the rollout. Wire scanner and CNAPP APIs into ticketing and reporting: if you’re assembling the same report by hand twice, build it instead. The leverage in this job is in the pattern, not the ticket.
Run web application security. Run dynamic scanning of our web properties, work fixes through the application teams, and use edge and WAF controls as deliberate temporary mitigation while the real fix ships. Be clear with yourself and others about which one you’ve done.
Implement the gate for a new publishing platform. Put inventory and scanning in front of internally built, externally published applications before they go live, and flag gaps in the pattern while it’s still being established rather than after.
Run coordinated disclosure intake. Handle intake and triage for our vulnerability disclosure program and bug bounty. Validate what researchers send, deduplicate against what we already know, respond like a professional on a clock, and drive legitimate reports to a verified fix — escalating disclosure and severity decisions to the Director.
Apply AI to the work. Use AI tools (Claude, copilots, and emerging agentic platforms) to triage at volume, correlate findings, draft remediation guidance, and generate reporting — with disciplined judgment about what belongs in which tool in a PHI environment. At this ratio of findings to people, leverage is not optional.
Track and report the numbers. Report mean time to remediate, backlog burn-down, and coverage against our SLAs. Produce the reporting the Director takes to leadership, and assemble evidence for client, partner, and auditor requests — applying vulnerability and exposure management in a HIPAA-regulated, PHI-handling environment.
You take ownership end to end — a finding isn’t done when the ticket is filed, it’s done when the fix is verified. You’re comfortable with scale and incompleteness: this backlog will not be zero, and that motivates you rather than paralyzes you. You’re direct — you say the thing, explain the why, and invite pushback, including from engineers who disagree with your severity call. You’re comfortable making the case for what shouldn’t be worked, and comfortable being overruled. Given ten thousand findings and one root cause, you look for the one upstream fix rather than working ten thousand tickets. You treat patient safety and data integrity as non-negotiable, not as obstacles. And you treat AI as a tool you actively wield rather than something you wait for IT to roll out — skeptical where it’s warranted, opinionated where it’s earned, and disciplined about where it does and doesn’t belong.
3–6 years in security, with meaningful hands-on time in vulnerability management, attack surface management, or cloud security posture.
Hands-on operation of a vulnerability scanning or CNAPP platform — running and tuning it, not just reading its dashboards.
Experience working a large finding set down using a risk-based model, and the ability to explain how the prioritization calls were made — with working fluency in CVSS, EPSS, and the CISA KEV catalog and a point of view on how they combine.
Cloud security fundamentals in at least one major provider (GCP or AWS preferred) — how workloads, identity, and network exposure actually fit together — plus container and image vulnerability management and dependency/SCA findings in code repositories.
Comfort starting from an incomplete inventory. Establishing what exists and who owns it isn’t a prerequisite someone hands you; it’s a large part of the job.
Experience working directly with engineering teams to get fixes shipped.
Scripting and automation proficiency (Python, PowerShell, or similar) — enough to query APIs and build reporting rather than assemble it by hand.
Demonstrated, hands-on use of AI tools (Claude, ChatGPT, GitHub Copilot, or equivalent) in day-to-day security work — not just experimentation — with specific examples of how AI changed your throughput or output quality, and a clear point of view on what’s appropriate to send to which tools when PHI, credentials, or sensitive telemetry are involved.
Clear written communication. You can write a remediation ticket an engineer will act on and a risk summary an executive will understand, and you know they’re different documents.
VM and CNAPP platforms. Wiz above all — it’s our platform, and it will cut your ramp time substantially. Also valuable: Orca, Prisma Cloud, Defender for Cloud, Lacework; CrowdStrike Falcon Exposure Management or Spotlight; and Tenable, Qualys, or Rapid7 for non-cloud estate.
Attack surface and asset inventory. External ASM tooling and reconnaissance methodology (DNS, certificate transparency, subdomain and shadow-IT discovery), plus CAASM and inventory platforms such as Axonius or runZero and SaaS discovery tooling.
Application and edge security. Web application scanning (DAST) and edge or WAF platforms (Invicti, Burp Suite, Cloudflare, Akamai), and coordinated disclosure or bug bounty operations (HackerOne, Bugcrowd) including researcher communication, report validation, and duplicate handling.
Platform and supply chain. Hardened or minimal base image programs (Chainguard, distroless, or a disciplined in-house golden image practice); Kubernetes and container security at scale (we run GKE and EKS); PaaS/edge hosting such as Vercel, Netlify, or Cloudflare Pages; SBOM and software supply chain practice; and VM/ASM automation wiring scanner APIs into Jira, Slack, or reporting pipelines.
Regulated environments. Healthcare, fintech, or other regulated experience with sensitive data handling requirements, and HIPAA, HITRUST, or SOC 2 from the operator side — particularly evidencing a vulnerability management program to auditors and clients.
Certifications. GCLD, GCPN, GWEB, GSEC, AWS or GCP security specialties, OSCP, or equivalent demonstrated expertise.
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings Accounts
Generous PTO and hybrid-work flexibility
401(k) with Company Match
Life Insurance, Pet Insurance, and more
We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.
Sound like a good fit? We’d love to meet you.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 218,582+ Jobs in Others
Answer easy questions
218,582+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”