O
OpenLoop
Posted 10 days agoVerified live 2d ago

Vulnerability & Attack Surface Management Analyst II

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
Vulnerability ManagementAttack Surface ManagementCNAPP PlatformsRisk-Based Vulnerability PrioritizationCVSSEPSSCISA KEVCloud SecurityContainer and Image Vulnerability ManagementSoftware Composition Analysis (SCA)PythonPowerShellAI-Assisted Security OperationsWeb Application Security TestingVulnerability RemediationStakeholder Management

About the company

OpenLoop is the nation’s top white-label digital health infrastructure provider, powering virtual care delivery for healthcare organizations, employers, retailers, and consumer brands.

Job description

Summary

OpenLoop provides telehealth support solutions designed to streamline virtual care delivery across specialties and states. The Vulnerability & Attack Surface Management Analyst II will operate and build vulnerability and attack surface management programs, prioritize findings by risk, drive remediation across engineering and IT teams, automate security workflows, and report exposure metrics in a HIPAA-regulated environment.

Responsibilities

  • Run the vulnerability lifecycle day to day. Discovery, validation, prioritization, remediation tracking, verification, and reporting across cloud workloads, containers, code repositories, and endpoints
  • Prioritize by real risk. Apply and refine the risk-based model we’re establishing — internet reachability, exploitability (CISA KEV, EPSS), asset criticality, and data sensitivity, not raw CVSS. Bring evidence for where the model needs to change, and surface what’s being deprioritized so those calls get made explicitly rather than by default
  • Know what we have, who owns it, and what’s exposed. Correlate cloud, endpoint, and SaaS inventory into one usable picture with a named owner on every asset that matters — today most don’t have one, and this is your first and most valuable deliverable. Then run external discovery on a defined cadence to find what of ours is reachable from the internet, including the things nobody told us about
  • Drive remediation. Work fixes through Engineering, IT, and Platform. Land tickets that are actionable, negotiate realistic timelines, escalate to the Director when you’re blocked, and follow through to verification. Attack problems, not people
  • Fix at the source, and automate the rest. Push hardened base images and dependency baselines so one upstream change closes thousands of findings instead of generating thousands of tickets — we’ve started this and proven it works, and you’ll drive the rollout. Wire scanner and CNAPP APIs into ticketing and reporting: if you’re assembling the same report by hand twice, build it instead. The leverage in this job is in the pattern, not the ticket
  • Run web application security. Run dynamic scanning of our web properties, work fixes through the application teams, and use edge and WAF controls as deliberate temporary mitigation while the real fix ships. Be clear with yourself and others about which one you’ve done
  • Implement the gate for a new publishing platform. Put inventory and scanning in front of internally built, externally published applications before they go live, and flag gaps in the pattern while it’s still being established rather than after
  • Run coordinated disclosure intake. Handle intake and triage for our vulnerability disclosure program and bug bounty. Validate what researchers send, deduplicate against what we already know, respond like a professional on a clock, and drive legitimate reports to a verified fix — escalating disclosure and severity decisions to the Director
  • Apply AI to the work. Use AI tools (Claude, copilots, and emerging agentic platforms) to triage at volume, correlate findings, draft remediation guidance, and generate reporting — with disciplined judgment about what belongs in which tool in a PHI environment. At this ratio of findings to people, leverage is not optional
  • Track and report the numbers. Report mean time to remediate, backlog burn-down, and coverage against our SLAs. Produce the reporting the Director takes to leadership, and assemble evidence for client, partner, and auditor requests — applying vulnerability and exposure management in a HIPAA-regulated, PHI-handling environment

Skills

  • 3–6 years in security, with meaningful hands-on time in vulnerability management, attack surface management, or cloud security posture
  • Hands-on operation of a vulnerability scanning or CNAPP platform — running and tuning it, not just reading its dashboards
  • Experience working a large finding set down using a risk-based model, and the ability to explain how the prioritization calls were made — with working fluency in CVSS, EPSS, and the CISA KEV catalog and a point of view on how they combine
  • Cloud security fundamentals in at least one major provider (GCP or AWS preferred) — how workloads, identity, and network exposure actually fit together — plus container and image vulnerability management and dependency/SCA findings in code repositories
  • Comfort starting from an incomplete inventory. Establishing what exists and who owns it isn't a prerequisite someone hands you; it's a large part of the job
  • Experience working directly with engineering teams to get fixes shipped
  • Scripting and automation proficiency (Python, PowerShell, or similar) — enough to query APIs and build reporting rather than assemble it by hand
  • Demonstrated, hands-on use of AI tools (Claude, ChatGPT, GitHub Copilot, or equivalent) in day-to-day security work — not just experimentation — with specific examples of how AI changed your throughput or output quality, and a clear point of view on what's appropriate to send to which tools when PHI, credentials, or sensitive telemetry are involved
  • Clear written communication. You can write a remediation ticket an engineer will act on and a risk summary an executive will understand, and you know they're different documents
  • VM and CNAPP platforms. Wiz above all — it's our platform, and it will cut your ramp time substantially. Also valuable: Orca, Prisma Cloud, Defender for Cloud, Lacework; CrowdStrike Falcon Exposure Management or Spotlight; and Tenable, Qualys, or Rapid7 for non-cloud estate
  • Attack surface and asset inventory. External ASM tooling and reconnaissance methodology (DNS, certificate transparency, subdomain and shadow-IT discovery), plus CAASM and inventory platforms such as Axonius or runZero and SaaS discovery tooling
  • Application and edge security. Web application scanning (DAST) and edge or WAF platforms (Invicti, Burp Suite, Cloudflare, Akamai), and coordinated disclosure or bug bounty operations (HackerOne, Bugcrowd) including researcher communication, report validation, and duplicate handling
  • Platform and supply chain. Hardened or minimal base image programs (Chainguard, distroless, or a disciplined in-house golden image practice); Kubernetes and container security at scale (we run GKE and EKS); PaaS/edge hosting such as Vercel, Netlify, or Cloudflare Pages; SBOM and software supply chain practice; and VM/ASM automation wiring scanner APIs into Jira, Slack, or reporting pipelines
  • Regulated environments. Healthcare, fintech, or other regulated experience with sensitive data handling requirements, and HIPAA, HITRUST, or SOC 2 from the operator side — particularly evidencing a vulnerability management program to auditors and clients
  • Certifications. GCLD, GCPN, GWEB, GSEC, AWS or GCP security specialties, OSCP, or equivalent demonstrated expertise

Qualifications

Must Haves

  • 3–6 years in security, with meaningful hands-on time in vulnerability management, attack surface management, or cloud security posture
  • Hands-on operation of a vulnerability scanning or CNAPP platform — running and tuning it, not just reading its dashboards
  • Experience working a large finding set down using a risk-based model, and the ability to explain how the prioritization calls were made — with working fluency in CVSS, EPSS, and the CISA KEV catalog and a point of view on how they combine
  • Cloud security fundamentals in at least one major provider (GCP or AWS preferred) — how workloads, identity, and network exposure actually fit together — plus container and image vulnerability management and dependency/SCA findings in code repositories
  • Comfort starting from an incomplete inventory. Establishing what exists and who owns it isn't a prerequisite someone hands you; it's a large part of the job
  • Experience working directly with engineering teams to get fixes shipped
  • Scripting and automation proficiency (Python, PowerShell, or similar) — enough to query APIs and build reporting rather than assemble it by hand
  • Demonstrated, hands-on use of AI tools (Claude, ChatGPT, GitHub Copilot, or equivalent) in day-to-day security work — not just experimentation — with specific examples of how AI changed your throughput or output quality, and a clear point of view on what's appropriate to send to which tools when PHI, credentials, or sensitive telemetry are involved
  • Clear written communication. You can write a remediation ticket an engineer will act on and a risk summary an executive will understand, and you know they're different documents

Nice to Haves

  • VM and CNAPP platforms. Wiz above all — it's our platform, and it will cut your ramp time substantially. Also valuable: Orca, Prisma Cloud, Defender for Cloud, Lacework; CrowdStrike Falcon Exposure Management or Spotlight; and Tenable, Qualys, or Rapid7 for non-cloud estate
  • Attack surface and asset inventory. External ASM tooling and reconnaissance methodology (DNS, certificate transparency, subdomain and shadow-IT discovery), plus CAASM and inventory platforms such as Axonius or runZero and SaaS discovery tooling
  • Application and edge security. Web application scanning (DAST) and edge or WAF platforms (Invicti, Burp Suite, Cloudflare, Akamai), and coordinated disclosure or bug bounty operations (HackerOne, Bugcrowd) including researcher communication, report validation, and duplicate handling
  • Platform and supply chain. Hardened or minimal base image programs (Chainguard, distroless, or a disciplined in-house golden image practice); Kubernetes and container security at scale (we run GKE and EKS); PaaS/edge hosting such as Vercel, Netlify, or Cloudflare Pages; SBOM and software supply chain practice; and VM/ASM automation wiring scanner APIs into Jira, Slack, or reporting pipelines
  • Regulated environments. Healthcare, fintech, or other regulated experience with sensitive data handling requirements, and HIPAA, HITRUST, or SOC 2 from the operator side — particularly evidencing a vulnerability management program to auditors and clients
  • Certifications. GCLD, GCPN, GWEB, GSEC, AWS or GCP security specialties, OSCP, or equivalent demonstrated expertise

Benefits

  • Medical, Dental & Vision
  • Flexible Spending / Health Savings Accounts
  • Generous PTO and hybrid-work flexibility
  • 401(k) with Company Match
  • Life Insurance
  • Pet Insurance

More jobs like this