OpenLoop Health

Staff Security Engineer

OpenLoop Health
Apply
4 hours ago
Remote, United States +2 moreStaff+

Responsibilities

  • Engineer and operate endpoint security controls for macOS and Windows, including MDM, disk encryption, patch compliance, local administrator controls, application control, and least privilege.
  • Design MDM and MAM policies for managed devices and BYOD, including app protection, conditional access, and selective wipe.
  • Deploy and manage an enterprise browser with data controls, session policies, and extension management.
  • Build and measure CIS Benchmark baselines, manage configuration drift and exceptions, and produce audit evidence.
  • Own Google Workspace email security, including SPF, DKIM, DMARC, phishing and BEC defenses, attachment and link protection, and PHI data loss prevention.
  • Write security standards, configuration baselines, and runbooks; implement controls from threat modeling and security reviews.
  • Map controls to HITRUST and SOC 2 requirements and support audit readiness.
  • Automate repetitive security work and partner with SecOps on telemetry, tooling, and phishing triage.
  • Mentor engineers, serve as an escalation point during incidents, and partner with IT, Engineering, Compliance, and SecOps.

Requirements

  • 8+ years of security engineering experience with end-to-end ownership of outcomes.
  • Deep hands-on expertise in endpoint security and email security.
  • Experience deploying and operating MDM/MAM platforms such as Kandji, Jamf, or Intune, and email security platforms.
  • Experience deploying and managing an enterprise browser platform.
  • Hands-on experience implementing CIS Benchmarks and measuring fleet-scale compliance.
  • Exposure to network security, including ZTNA/VPN, DNS filtering, segmentation, or firewall policy.
  • Working knowledge of cloud security fundamentals, preferably AWS, including IAM, network controls, logging, and workforce access to cloud environments.
  • Exposure to DevSecOps practices such as infrastructure as code, CI/CD security, secrets management, or security tooling in pipelines.
  • Scripting ability in Python, Bash, PowerShell, or similar.
  • Experience working in a regulated environment such as HIPAA, HITRUST, SOC 2, or PCI and producing audit evidence.
  • Clear written communication and ability to explain security risks to non-security executives.
  • Healthcare or health technology experience, especially with PHI, is preferred.
  • Experience with Okta or another enterprise identity provider and with multi-entity organizations is preferred.
  • Relevant certifications such as GIAC, CISSP, OSCP, or cloud security certifications are preferred but not required.

Benefits

  • Medical, dental, and vision insurance.
  • Flexible Spending and Health Savings Accounts.
  • Generous paid time off.
  • Hybrid-work flexibility.
  • 401(k) with company match.
  • Life insurance, pet insurance, and other benefits.

Tech Stack

AWSBashmacOSPowerShellPythonWindows

Categories

OpenLoop Health

About OpenLoop Health

501-1,000 employees

OpenLoop Health provides white-label telehealth infrastructure and clinical operations for digital health companies, health plans, and health systems. Its end-to-end services span provider staffing and licensing, payer coverage, a virtual care platform with AI, pharmacy and diagnostics coordination, RPM fulfillment, and revenue cycle management, enabling nationwide virtual care delivery. Founded in 2020 and headquartered in Des Moines, Iowa, the company is privately held and supports programs operating across all 50 U.S. states.

Contact me