Sr. Staff Security Engineer

OpenLoop Health, Inc.

Northern (KY)

Hybrid

USD 170,000 - 260,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, and Vision plans
Flexible Spending/Health Savings
Flexible PTO
401(k) + Company Match
Life Insurance, Pet insurance, and for

Job summary

OpenLoop Health, Inc. is seeking a Sr Staff Security Architect to be the most senior technical authority on security architecture, approving architecture decisions and leading reviews.

You will drive threat modeling, define standards, and create reference designs that engineering builds against. You will own security architecture across cloud, applications, and corporate systems, guiding secure-by-default practices, and partnering with CTO and security leadership to map long-term architecture

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
  • 10+ years of progressive security experience, with at least 5 years focused on security architecture across enterprise and cloud environments.
  • Deep expertise across application, cloud, IAM, network, and data protection.
  • Hands-on experience architecting security solutions in cloud environments, including IAM, key management, encryption, and cloud-native security services.
  • Proven threat modeling experience (STRIDE, PASTA, or equivalent) at varying scales, including training engineers.
  • Strong SSDLC, OWASP principles, and secure design patterns.
  • Proficiency in OAuth 2.0, OIDC, and SAML across multi-tenant and patient-facing apps.
  • Experience with HIPAA Security Rule technical safeguards, HITRUST CSF, NIST CSF, SOC 2.
  • Ability to communicate complex architectural risk to technical and executive audiences.

Responsibilities

  • Own and evolve OpenLoop's security architecture across cloud infrastructure, applications, and corporate systems with standards and reference architectures.
  • Lead threat modeling for product, engineering, and infrastructure initiatives, coaching engineers to threat model their own work.
  • Conduct architecture reviews and provide actionable recommendations against security principles and regulatory requirements.
  • Design and improve the architecture review process to scale with engineering velocity and self-service patterns.
  • Partner with CTO and enterprise architecture to embed security review within governance.
  • Define and champion application security standards including OAuth/OIDC, SAML, data protection controls, and HL7/FHIR interoperability.
  • Establish and maintain a zero trust architecture strategy across identity, network, endpoint, and data layers.
  • Oversee key management, secrets management, and certificate lifecycle practices in cloud environments.
  • Own security architecture for third-party integrations and supply chain risk control at design stage.
  • Mentor the security team and raise architectural thinking across domains.
  • Translate GRC and privacy requirements into concrete architectural controls for PHI architecture.

Skills

Security architecture
Threat modeling
SSDLC
OAuth/OIDC
SAML
Cloud security
Zero trust
Key management
HIPAA & regulatory knowledge
Communication of risk

Education

Bachelor's degree in CS or related field

Tools

ADR / architecture reviews
Cloud IAM & encryption services

Job description

About OpenLoop

OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.

About the Role

OpenLoop's mission is to bring care anywhere by powering telehealth solutions at scale. The Security Architecture & Engineering team defines how security is designed into every system that supports virtual care delivery across all 50 states.

As Sr Staff Security Architect, you will be the most senior technical authority on security architecture at OpenLoop, with approval authority over architecture decisions and responsibility for leading architecture reviews, driving threat modeling, and defining the standards and reference designs that engineering builds against.

What You'll Do
  • Own and continuously evolve OpenLoop's security architecture across cloud infrastructure, applications, and corporate systems — defining standards, patterns, and reference architectures that teams build to.

  • Lead threat modeling across product, engineering, and infrastructure initiatives, with particular attention to PHI data flows, patient-facing interfaces, and virtual care delivery systems — and coach engineers to threat model their own work.

  • Conduct architecture reviews for new and existing systems, evaluating designs against security principles and regulatory requirements and producing actionable recommendations.

  • Design and continuously improve the architecture review process itself so that it scales with engineering velocity — including self-service patterns, risk-tiered review paths, and clear criteria for when full review is required.

  • Partner with the CTO and enterprise architecture function, embedding security review within existing technical governance rather than running a parallel process.

  • Define and champion application security standards, including secure design principles, API security, authentication and authorization patterns (OAuth/OIDC, SAML), and data protection controls — including healthcare interoperability standards such as HL7 and FHIR.

  • Establish and maintain a zero trust architecture strategy across identity, network, endpoint, and data layers.

  • Architect and govern key management, secrets management, and certificate lifecycle practices across cloud-native environments.

  • Own the security architecture for third-party integrations, defining how external systems connect to OpenLoop's environment and ensuring supply chain risk is controlled at the design stage.

  • Serve as the primary security partner for product and engineering leaders, embedded in design and planning cycles to shape secure-by-default systems.

  • Maintain security architecture documentation, including architecture decision records (ADRs), reference designs, and control frameworks.

  • Take security and compliance requirements from GRC, Privacy, and audit partners and translate them into concrete architectural controls — with particular depth in the HIPAA Security Rule's technical safeguards as they apply to PHI architecture.

  • Partner with the CISO and security leadership on the long-term architecture roadmap, producing clear metrics and executive-ready reporting on architecture risk posture.

  • Mentor and elevate the broader security team, raising architectural thinking and design quality across all security domains.

  • Research emerging threats and attack techniques — including threat actors actively targeting healthcare — to keep OpenLoop ahead of the threat landscape.

  • Other duties as assigned.

Who You Are
  • An architect who has owned the function, not contributed to it — you've built standards other teams actually adopted.

  • Someone who scales themselves rather than becoming the queue everyone waits in. You'd rather teach ten engineers to threat model than review ten threat models.

  • Comfortable being the most senior security voice in the room, and equally comfortable being overruled and managing the residual risk.

  • Cross-domain by instinct: you think about identity, network, application, and data together rather than in isolation.

  • Someone who understands that an elegant architecture nobody can operate is a failed architecture — and that a review process teams route around is a failed process.

  • An enabler, not a gatekeeper. You've seen security teams become the department of "no" and you have opinions about why that happens.

  • Self-directed, able to bring structure to ambiguous problems without waiting for it to be handed to you.

  • Motivated by the fact that the systems you design protect health information for patients getting care they might not otherwise access.

Required Qualifications
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience.

  • 10+ years of progressive security experience, with at least 5 years focused specifically on security architecture across enterprise and cloud environments.

  • Deep expertise across multiple security domains: application security, cloud security, identity and access management, network security, and data protection.

  • Hands-on experience architecting security solutions in cloud environments, including network security design, IAM, key and secrets management, encryption, and cloud-native security services.

  • Proven experience leading threat modeling using structured methodologies (STRIDE, PASTA, or equivalent) at varying scales — from individual features to whole systems — including evaluating others' threat models and training engineers to produce their own.

  • Strong command of secure software development lifecycle (SSDLC), OWASP principles, and application security design patterns.

  • Proficiency in modern authentication and authorization patterns (OAuth 2.0, OIDC, SAML), including across multi-tenant and patient-facing applications.

  • Experience architecting key management, secrets management, and PKI/certificate lifecycle controls in cloud-native environments.

  • Working knowledge of HIPAA (including Security Rule technical safeguards), HITRUST CSF, NIST CSF, and SOC 2, sufficient to design controls that satisfy them.

  • Demonstrated ability to communicate complex architectural risk to both technical and executive audiences.

Preferred Qualifications

  • Experience in healthcare, digital health, or another highly regulated industry.

  • Experience designing and evaluating zero trust architectures in production.

  • Experience designing or scaling an architecture review process — including risk-tiering, self-service patterns, or integration with an existing technical review board.

  • Familiarity with API security architecture and healthcare data exchange standards (HL7, FHIR).

  • Familiarity with security architecture frameworks such as SABSA or TOGAF security extensions.

  • Experience mentoring senior engineers or establishing architecture practices from scratch.

What Success Looks Like
  • First 90 days: Architecture review process documented and running without bottlenecking on the hiring manager. Baseline assessment of current architecture risk delivered. Working relationship established with the CTO org.

  • First 6 months: Threat modeling established as a standard design input for net-new initiatives, with at least two engineering teams modeling their own features. At least two published reference architectures adopted by engineering. Risk-tiered review paths in place.

  • First 12 months: Architecture-level HIPAA and SOC 2 findings closed. Measurable shift in security findings from late-stage to design-stage. Recognized by engineering leadership as a partner who is invited into design conversations rather than inserted into them.

Our Benefits

In addition, for salaried positions you would also be eligible for:

  • Medical, Dental, and Vision plans

  • Flexible Spending/Health Savings Accounts

  • Flexible PTO

  • 401(k) + Company Match

  • Life Insurance, Pet insurance, and more

Our Company

We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.

Sound like a good fit? We’d love to meet you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Staff IAM Engineer
Sr. Staff IAM Engineer

OpenLoop Health, Inc. • Northern (KY)

Hybrid
USD 180,000 - 240,000
Medical, Dental, Vision plans
Flexible PTO
401(k) + Company Match
Staff Software Engineer (Tech Lead)
Staff Software Engineer (Tech Lead)

OpenLoop Health, Inc. • United States

Hybrid
USD 180,000 - 260,000
Equity
Flexible Bay Area Hybrid
M-series Macs
Staff Software Engineer (Tech Lead)
Staff Software Engineer (Tech Lead)

OpenLoop Health • United States

Hybrid
USD 180,000 - 230,000
M-series Macs
Linear
GitHub
+3
Senior Software Engineer
Senior Software Engineer

OpenLoop Health, Inc. • San Jose (CA)

Hybrid
USD 100,000 - 130,000
Medical, Dental, and Vision plans
Flexible Spending/Health Savings Accounts
Flexible PTO
+2
Chief Compliance Officer
Chief Compliance Officer

Openloop-Health • United States

On-site
USD 180,000 - 320,000
Medical, Dental, and Vision plans
Flexible PTO
401(k) + Company Match
+2
Senior Technical Solutions Engineer
Senior Technical Solutions Engineer

OpenLoop • United States

On-site
USD 90,000 - 120,000
Medical, Dental, and Vision plans
Flexible Spending/Health Savings Accounts
Flexible PTO
+2
Staff Software Engineer (Tech Lead)
Staff Software Engineer (Tech Lead)

OpenLoop • United States

Hybrid
USD 180,000 - 240,000
Equity
Competitive compensation
Health benefits
+2
API Security Engineer
API Security Engineer

OpenLoop • United States

Remote
USD 100,000 - 130,000
Medical, Dental, and Vision plans
Flexible Spending/Health Savings Accounts
Flexible PTO
+2
Senior Director, Clinical Compliance
Senior Director, Clinical Compliance

OpenLoop Health, Inc. • Northern (KY)

Hybrid
USD 180,000 - 290,000
Medical, Dental, and Vision plans
Flexible PTO
401(k) + Company Match
+1
Enterprise Applications Engineering Manager
Enterprise Applications Engineering Manager

OpenLoop Health, Inc. • United States

Hybrid
USD 120,000 - 150,000
Medical, Dental, and Vision plans
Flexible PTO
401(k) + Company Match