Job Closed
This listing is no longer active.
OpenLoop Health is a healthcare technology startup whose services are used by companies that provide telehealth delivery across all 50 states. In past hiring, the award-winning hea
Staff Security Engineer
Location
United States
Posted
119 days ago
Salary
0
No structured requirement data.
Job Description
Staff Security Engineer
OpenLoop Health
About OpenLoop OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states. About The Role OpenLoop is looking for a Staff Security Engineer (DevOps Integrations) to join our team remotely. In this role, you will be responsible for being our DevSecOps subject matter expert across the IT, software engineering and product teams. The ideal candidate is someone who has the ability to provide strategic oversight, possesses a wide range of cybersecurity and software engineering technical acumen, and has the ability to think like an attacker to guide us through potential security issues. What You’ll Do: - Build relationships with developers and stakeholders to incorporate security principles into engineering design and deployments. - Supervise validation in security controls and testing across projects, using SAST, DAST, IAST and RASP tools, documenting any security findings, outlining remediation options and overseeing mitigation. - Oversee implementation of defensive practices and countermeasures across infrastructure and applications. - Draft and uphold CI/CD security strategy and practices in tandem with other technical team leads. - Lead continuous product and application security reviews, focused on secure development practices, threat modeling, vulnerability management, architecture and application security design. - Ensure security principles and validations are consistently implemented throughout the CI/CD pipeline by embedding robust, security-focused practices into all automation processes. - Attend and participate in product meetings addressing security requirements for new and existing products. - Build services and tools to enable developers and engineers to use security components successfully - Simplify automation that applies security inter-workings with CI/CD pipelines. - Support the ability to “shift left” and incorporate security early on and throughout the development lifecycle. - Communicate vulnerability results to both technical and non-technical stakeholders, focused on risk tolerance and threat to the business, in order to gain support through influential messaging. - Leverage vulnerability database sources to understand the weakness, probability and remediation options supplied by vendors - Join forces and provision security principles in architecture, infrastructure and code. - Regularly research and learn new tactics, techniques and procedures (TTPs). - Partner with teams to define key performance indicators (KPIs) and metrics across business units. - Ensure regulatory compliance (e.g., PCI, HIPAA, HITRUST, NIST CSF) through effective security controls and processes. - Other duties as assigned. Who You Are: - Bachelor's degree in computer science (preferred), information assurance, MIS or related field, or equivalent. - 7+ years of security and systems administration-related experience, to include 3+ years of related cloud and security engineering experience - Experience with operations and security across Amazon Web Services (AWS) and/or Google Cloud Platform (GCP). - Experience with agile workflows, including Scrum and Kanban. - Understanding of containers (e.g., Docker) and container orchestration (e.g., Docker Swarm, Kubernetes). - Proficient in securing Windows and *nix operating systems, endpoint applications, networking protocols and devices. - Ability to obtain and maintain technical team and business support to influence a collaborative effort to reduce attack surface while performing rapid, continuous implementation. - Understanding of OWASP, CVSS, the MITRE ATT&CK framework and (SLDC). - Knowledge of Payment Card Industry (PCI), Health Information Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), National Institute of Standards (NIST) or International Standards Organization (ISO) requirements. - Self-starter mentality requiring minimal supervision. - Analytical and problem-solving abilities with a proactive, risk-based approach. - Highly organized and efficient. - Demonstrated strategic and tactical thinking, along with decision-making skills and business acumen. - Experience in healthcare or digital health is a plus. - Strong internal service minded, to provide support to all teams and leadership - Adaptability to handle dynamic and challenging environments. - Energetic, resourceful, and appropriate work intensity to get the work done. - Strong people acumen and relationship skills. Our Company We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work. Sound like a good fit? We’d love to meet you.
Related Guides
Related Categories
Related Job Pages
More DevOps Engineer Jobs
Senior Sire Reliability Engineer
CertifIDCertifID provides identity protection services to help prevent wire fraud. Focused on securing digital financial transactions, the company strives to reduce the financial and emoti
• Own and improve the reliability, availability, and performance of production systems while defining and operationalizing SLIs/SLOs and error budgets. • Design and implement autonomous and semi-autonomous AI agents for monitoring distributed systems and applications. Build agents capable of consuming multi-source observability data (metrics, logs, traces, etc.). • Participate in and help lead an on-call rotation, serving as an escalation point for major incidents and facilitating blameless postmortems. • Build automated workflows to eliminate manual work and design/maintain Infrastructure-as-Code with Terraform. • Improve metrics, logs, traces, and alerting using tools like Datadog or Prometheus to reduce noise and increase signal. • Partner with application teams to implement reliability best practices and mentor junior engineers to foster a culture of knowledge sharing.
Senior Security Engineer – DevSecOps
PrizePicksPrizePicks is a sports betting company offering a fantasy platform where users can select players and teams to place bets on. With the mission of becoming the most loved fan engage
• Manage and maintain edge and bot protection (e.g., WAF, CDN, DDoS mitigation). • Perform security-focused infrastructure reviews for new product releases and architectural changes. • Implement and maintain monitoring and alerting tools to detect cloud and container-related vulnerabilities and misconfigurations. • Collaborate with DevOps and Engineering teams to embed security into CI/CD pipelines and deployment processes without slowing down delivery. • Partner with Application Security and Engineering to implement security controls on opportunities identified during Threat Modeling. • Lead initiatives around infrastructure-as-code (IaC) security and runtime protection to automate security controls and hardening. • Assist with threat modeling, risk assessments, and provide security guidance during the development lifecycle. • Collaborate with incident response teams, offering expert advice on cloud-related security issues to help resolve incidents quickly. • Develop tooling or automation to support proactive remediation and continuous security validation. • Track and report DevSecOps KPIs, such as mean time to remediate, security control coverage, and vulnerability trends.
• Design, operate, and continuously improve automated CI/CD pipelines using GitLab CI to support zero-downtime deployments across multiple environments. • Support development teams with standardized deployment tooling, automation, and operational best practices. • Administer and support containerized workloads using Kubernetes (EKS) and Docker-based container platforms. • Configure and manage Linux-based servers and systems. • Implement Infrastructure as Code (IaC) using Terraform and/or AWS CDK for repeatable, auditable deployments. • Support provisioning and configuration of AWS services including EC2, EKS, ECS, S3, RDS, VPC, Lambda, and related services. • Coordinate infrastructure changes without performing AWS account provisioning or organizational administration. • Integrate security scanning into CI/CD pipelines using tools such as Trivy, AWS Inspector, and AWS Security Hub. • Perform vulnerability triage and coordinate remediation with development teams in accordance with defined timelines. • Implement and manage IAM least-privilege policies, secrets, and encryption using AWS KMS, Secrets Manager, and SSM. • Ensure encryption in transit and at rest across all in-scope systems. • Configure and maintain monitoring and observability using CloudWatch, Prometheus, Grafana, and centralized logging solutions. • Support Tier 2 and Tier 3 incident response for production systems, meeting SLA requirements. • Participate in root-cause analysis and continuous improvement initiatives. • Participate in Agile sprints, including backlog grooming, sprint planning, stand-ups, and retrospectives. • Track work in JIRA, using story-point estimation and sprint metrics. • Support reprioritization of backlog items in coordination with the COR and Product Owner. • Produce and maintain technical documentation covering architecture, pipelines, monitoring, security, and disaster recovery. • Support Business Continuity and Disaster Recovery (BCDR) planning, documentation, and exercises. • Ensure all deliverables comply with ADA, Section 508, WCAG 2.2 A/AA, and digital accessibility standards.
• Design, operate, and continuously improve automated CI/CD pipelines using GitLab CI to support zero-downtime deployments across multiple environments. • Support development teams with standardized deployment tooling, automation, and operational best practices. • Administer and support containerized workloads using Kubernetes (EKS) and Docker-based container platforms. • Configure and manage Linux-based servers and systems. • Implement Infrastructure as Code (IaC) using Terraform and/or AWS CDK for repeatable, auditable deployments. • Support provisioning and configuration of AWS services including EC2, EKS, ECS, S3, RDS, VPC, Lambda, and related services. • Coordinate infrastructure changes without performing AWS account provisioning or organizational administration. • Integrate security scanning into CI/CD pipelines using tools such as Trivy, AWS Inspector, and AWS Security Hub. • Perform vulnerability triage and coordinate remediation with development teams in accordance with defined timelines. • Implement and manage IAM least-privilege policies, secrets, and encryption using AWS KMS, Secrets Manager, and SSM. • Ensure encryption in transit and at rest across all in-scope systems. • Configure and maintain monitoring and observability using CloudWatch, Prometheus, Grafana, and centralized logging solutions. • Support Tier 2 and Tier 3 incident response for production systems, meeting SLA requirements. • Participate in root-cause analysis and continuous improvement initiatives. • Participate in Agile sprints, including backlog grooming, sprint planning, stand-ups, and retrospectives. • Track work in JIRA, using story-point estimation and sprint metrics. • Support reprioritization of backlog items in coordination with the COR and Product Owner. • Produce and maintain technical documentation covering architecture, pipelines, monitoring, security, and disaster recovery. • Support Business Continuity and Disaster Recovery (BCDR) planning, documentation, and exercises. • Ensure all deliverables comply with ADA, Section 508, WCAG 2.2 A/AA, and digital accessibility standards.

