OpenLoop logo
OpenLoop

Powering superior telehealth from end-to-end. #HealingAnywhere

Senior Staff Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 201-500Since 2020H1B No SponsorCompany SiteLinkedIn

Location

California + 2 moreAll locations: California | Iowa | Tennessee

Posted

2 days ago

Salary

0

Seniority

Senior

Bachelor Degree10 yrs expEnglishCloudPython

Job Description

Senior Staff Security Analyst

OpenLoop

• AI-assisted security operations. Use AI tools (Claude, copilots, and emerging agentic platforms) as a force multiplier across every part of the job - accelerating triage and investigation, drafting and refining detections, summarizing alerts and incidents, automating repetitive analyst work, and improving the metrics that matter (MTTD, MTTR, dwell time, analyst throughput). Set the bar for how the security team uses AI responsibly in a PHI environment. • Threat hunting. Develop and execute hypothesis-driven hunts across endpoints, cloud workloads, identity, and SaaS. Translate hunt findings into durable detections. Utilize AI and automation to turn Threat Hunting into a powerful, proactive tool. • Vulnerability management. Drive the vulnerability lifecycle - discovery, prioritization (risk-based, not just CVSS), remediation tracking, and reporting. Partner with engineering to close real risk fast. • Attack surface management. Maintain visibility into our external and internal attack surface across cloud, SaaS, third parties, and acquired entities. Find exposure before someone else does. • Incident response and digital forensics. Assist, however necessary, the Lead Incident Responder with investigations and security incidents from triage through containment, eradication, recovery, and post-incident review. Perform host, network, cloud, and memory forensics. Assist with IR playbooks and the evidence chain. • Fraud assessment. Drive deep analysis on the source of digital fraud. From payment card to cyber-initiated fraud, understand the how and why on the digital fraud frontier. • Cross-functional partnership. Work directly with Engineering, IT, Operations, and Compliance. Translate security findings into clear asks with concrete next steps. Attack problems, not people. • Healthcare-specific risk. Apply controls that fit a HIPAA-regulated, PHI-handling environment. Help us move at purposeful speed without breaking what matters.

Job Requirements

  • 10–12 years of progressive experience in security operations, with deep hands-on work across all of: digital forensics, incident response, vulnerability management, attack surface management, threat hunting, and security analytics.
  • Demonstrated ownership of major security incidents end-to-end - you've been the technical lead, not just on the bridge.
  • Working knowledge of cloud security, endpoint detection and response, SIEM platforms, identity providers, and modern attacker tradecraft (MITRE ATT&CK fluency expected).
  • Detection engineering experience — you've written, tuned, and retired detections, and you can defend your choices with data.
  • Scripting and automation proficiency (Python, PowerShell, or similar) — enough to build what you need rather than wait for it.
  • Demonstrated, hands-on use of AI tools (Claude, ChatGPT, GitHub Copilot, or equivalent) as part of day-to-day security work — not just experimentation. You can point to specific examples of how AI changed your throughput, your detection quality, or your time-to-resolution.
  • Clear point of view on AI safety and data handling — especially what's appropriate to send to which tools when PHI, credentials, or sensitive telemetry are involved.
  • Clear written and verbal communication. You can brief an engineer, a clinician, and an executive on the same incident and have all three walk away with what they need.
  • Strongly preferred: Experience in a healthcare, fintech, or other regulated environment with sensitive data handling requirements.
  • Strongly preferred: Working familiarity with HIPAA, HITRUST, or SOC 2 from the operator side — not just the audit side.
  • Strongly preferred: Industry certifications such as GCFA, GCIH, GNFA, GCTI, OSCP, or equivalent demonstrated expertise.
  • Strongly preferred: Experience supporting M&A security integration or multi-entity environments (we operate across several subsidiaries).
  • Strongly preferred: Experience building AI-assisted workflows or automations for security operations (custom prompts, agentic workflows, integrations with SIEM/EDR/ticketing).
  • Strongly preferred: Familiarity with prompt engineering, retrieval-augmented patterns, or building internal tooling on top of LLM APIs.

Benefits

  • Medical, Dental, and Vision plans
  • Flexible Spending/Health Savings Accounts
  • Flexible PTO
  • 401(k) + Company Match
  • Life Insurance, Pet insurance, and more

Related Job Pages

More Security Analyst Jobs

ECS Tech Inc logo

Senior SOC Analyst/Lead

ECS Tech Inc

All candidates must meet the following criteria: Must be a US Citizen, no dual Citizenships. Must be able to secure a Public trust clearance. Must be able to work across multiple programs across the Federal and DOD space. The core values that ECS looks for in an engagement manager include: Teamwork, Respect, Accountability, Integrity, and Leadership.

Full TimeRemoteH1B No Sponsor

Role Description ECS is seeking a Senior SOC Analyst (SOC Lead) with demonstrated experience supporting the development of processes, procedures, and automations to rapidly ingest, aggregate, correlate, normalize, analyze event messages to absurdly identify and respond to Indicators of Compromise (IoCs). The ideal candidate is a critical thinker and perpetual learner who is excited to solve some of our clients’ toughest challenges. To be successful the candidate must have experience working in a mature 24x7x365 Security Operation Center. Shift schedule: Mon-Friday, 8AM-4PM ET (subject to change) Responsibilities - Provides subject matter expertise for monitoring and managing threats, disseminating information, and handling, responding to, and investigating all incident escalations from the Security Operations Center. - Ensures all security incidents are tracked and documented appropriately. - Continuously monitors SIEM and on-premises infrastructure/cloud applications for security events to threats & intrusions, including: - SIEM alert queue - Phishing email inbox - Intel feeds via email and other sources (i.e., US-CERT, MS-ISAC) - Incident ticketing queue (Resilient tickets) - Ensures the SOC manager stays informed of any issues or incidents. - Coordinates with SOC staff to conduct incident/policy violation investigations, report infractions, eradicate/mitigate/remediate Indications of Compromise (IoC), and perform continuous monitoring functions. - Leads root cause analysis and post-mortem dialogue after significant events to capture lessons learned and define process or technology improvements. - Owns the successful completion of all daily operational processes and procedures. - Develops and maintains standard operating procedures (SOPs), technical playbooks and operational run books to support SOC operations and incident response activities. - Conduct follow-up meetings of escalated or noteworthy cases and modifies SOPs and playbooks based on policies, standards and best practices learned from previous cases. - Works in conjunction with SOC and infrastructure management teams to administer and manage the SOC security technologies. - Evaluates Common Vulnerabilities and Exposures (CVE) as a potential internal/external attack vector, develop recommendations to eliminate vulnerability/weakness if present. - Work closely with Cyber Threat Intel to provide information on detection patterns for new upcoming threats. - Oversees threat hunting initiatives and reviews hunt reports that are provided by SOC analysts. - Provides training and mentorship to SOC analysts to improve the incident handling capabilities. - Provides guidance for all internal stakeholders for reporting and visualizations that supports SOC goals and objectives to identify and correct gaps. - Reconfigures analytic objects (e.g., fields, extractions, tags, event types, lookups, workflow actions, aliases). - Develops reports for operational activities to meet SOC and cybersecurity leadership requirements and directives. - Provides extensive knowledge of cybersecurity, incident response, digital forensic analysis and educate personnel on effective SOC searches, reporting, and visualization development. - This role involves shift work schedule to support our 24/7 operation, including weekends and holidays. Candidates must be flexible in their availability. While we make every effort to accommodate individual preferences, it's essential to understand that specific shift requests are not guaranteed and are assigned based on operational needs. Qualifications - 5+ years of experience in cybersecurity operations & incident response, with at least 3+ years in a SOC environment and 2+ years in a leadership role. - Ability to interpret complex cybersecurity topics and effectively communicate or present information to various groups of stakeholders (Executives, SOC, etc.). - In-depth knowledge of SIEM technologies (i.e. QRadar, Splunk), EDR (i.e. CrowdStrike), IDS/IPS, malware analysis, and vulnerability management tools (i.e. Tenable). - Experience leading and mentoring junior analysts. - Experience with two or more analysis tools used in a CIRT or similar investigative environment. - Ability to analyze and triage IoCs. - Proven understanding of computer and network fundamentals. - Ability to perform in-depth research tasks and produce written summaries to include insights and predictions based on an analytical process. - Knowledge of current cyber threats, trends, attack lifecycle, and various Tactics, Techniques, and Procedures (TTPs). - Industry-recognized certifications, such as CISSP, CISM, GIAC, or CEH, are preferred. - Excellent leadership, written and oral communication skills, and problem-solving skills. - Ability to handle high-stress situations with a calm and methodical approach. Requirements - Salary Range: $135,000 - $150,000 Benefits - General Description of Benefits

USA Timezones
$135K - $150K / year
Full TimeRemoteTeam 1,001-5,000H1B No Sponsor

• Realizar a primeira linha de monitoramento dos sistemas, identificando alertas e eventos suspeitos; • Analisar alertas de segurança de acordo com procedimentos predefinidos, buscando por padrões e correlações; • Elaborar relatórios simples sobre as atividades de monitoramento e incidentes; • Elaborar relatórios de auditoria e revisão das consoles de segurança e de vulnerabilidades técnicas; • Prestar suporte técnico aos usuários, clientes e outras equipes, nos itens de responsabilidade do SOC e acionar equipes de apoio quando necessário; • Responder incidentes de baixa e média complexidade; • Elaborar e manter documentações dos processos internos de SOC e das consoles de segurança; • Atuar em melhorias e atualizações nas ferramentas de segurança do ambiente.

Brazil
Teltec Solutions logo

SOC Analyst II

Teltec Solutions

Transforming your business in the face of the challenges of the digital economy with experience, competence, and innovat

Full TimeRemoteTeam 201-500Since 1991H1B No Sponsor

• Operate and manage the Darktrace Network Detection and Response (NDR) solution dedicated to a Teltec client. • Perform continuous monitoring of alerts and detections generated by the platform, conducting initial analysis and enrichment of identified events. • Investigate suspicious activities and potential threats identified in network traffic using the analytical capabilities of the NDR solution. • Manage and optimize policies, detection rules, exceptions, and tool configurations to ensure maximum operational effectiveness. • Support security incident response processes by providing technical evidence, context, and recommendations for containment and remediation. • Continuously tune the platform to reduce false positives and improve detection quality. • Develop and maintain technical documentation, operational procedures, and playbooks related to the tool’s operation. • Prepare technical and executive reports including indicators, trends, identified threats, and recommendations for improving the monitored environment. • Serve as the technical focal point for the client on NDR-related matters, leading operational and technical alignment meetings. • Support continuous improvement initiatives by proposing new detections, use cases, and monitoring strategies to increase visibility and security maturity. • Collaborate with SOC, MDR, Network, and Infrastructure teams to investigate, validate, and handle security events identified by the platform.

Brazil

Role Description Ingeniero de sistemas o áreas afines, quien brindará soporte a cliente específicos, apoyando a la revisión y modificación de reglas de monitoreo, atendiendo y presentando reportería a nuestros clientes. - Investigar eventos e incidentes reportados por el equipo SOC para recopilar evidencia, profundizar y analizar de manera integral y consistente las alertas de seguridad para ser reportadas al cliente. - Identificar los falsos positivos comunes y hacer sugerencias para el afinamiento de las plataformas de detección con el objetivo de reducir la fatiga por alertas. - Realizar afinamiento de reglas de detección y construcción de casos de uso para la detección de amenazas y comportamientos maliciosos en las plataformas de detección del SOC. Qualifications - 1 año como SOC Specialist en nivel Junior o experiencia equivalente al puesto. - Ingeniero de sistemas o áreas afines. Requirements - CSAL - Certification SOC Analyst Level 1 - IC - Introduction to Cybersecurity - ICF - IT and Cybersecurity Foundations - Security+, deseables u otros que puedan tener. - Ingles intermedio.

Guatemala