Staff Security Engineer

Alt

Des Moines (IA)

Hybrid

USD 150,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, Dental & Vision
Hybrid-work flexibility
401(k) with Company Match
Generous PTO

Job summary

OpenLoop is seeking a Staff Security Engineer to own and mature security across endpoints and email, focusing on macOS/Windows fleets, MDM/MAM, and enterprise browser controls. You’ll write standards, implement CIS benchmarks, and drive HITRUST/SOC 2 readiness while mentoring engineers.

You’ll collaborate with SecOps, IT, Compliance, and Engineering, ensuring secure cloud usage and DevSecOps practices in a regulated healthcare environment. This hybrid role supports flexible work arrangements.

Qualifications

  • 8+ years in security engineering and end-to-end ownership of outcomes.
  • Hands-on expertise in endpoint and email security.
  • Experience deploying MDM/MAM platforms and email security.
  • Experience deploying an enterprise browser platform.
  • Experience implementing CIS Benchmarks at fleet scale.
  • Exposure to secure remote access, DNS filtering, segmentation, or firewall policy.
  • Cloud security fundamentals (AWS) and IAM, logging, network controls.
  • DevSecOps practices and security tooling in CI/CD pipelines.
  • Scripting in Python, Bash, or PowerShell.

Responsibilities

  • Own and mature security controls for macOS/Windows fleets (MDM, disk encryption, patching, local admin controls).
  • Engineer MDM/MAM policies to protect PHI on managed and BYOD devices.
  • Deploy and manage an enterprise browser for secure SaaS/web access with data controls and policies.
  • Develop CIS Benchmark baselines and track drift for HITRUST and SOC 2 audits.
  • Drive least-privilege and maintain controls without impacting clinicians and operators.
  • Own email security for Google Workspace (SPF, DKIM, DMARC, DLP).
  • Write security standards, baselines, and runbooks for teams to follow.
  • Align controls to HITRUST and SOC 2 evidence, support audits.
  • Automate repetitive tasks; mentor SAE and adjacent teams.
  • Collaborate with IT/Engineering/Compliance/SecOps translating risk into business terms.

Skills

Endpoint security
Email security
CIS Benchmarks
MDM/MAM platforms
Enterprise browser platform
Cloud security fundamentals
DevSecOps practices
Scripting (Python/Bash/PowerShell)

Tools

Kandji
Jamf
Intune

Job description

About OpenLoop

OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.

About the Role

OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. We deliver white-labeled clinical and operational infrastructure that helps companies scale virtual care across all 50 states: telehealth delivery, clinician staffing, licensing, payer coverage, and revenue cycle management. Our clients run on our platform under their own brand, which means their patients’ trust depends on how well we protect it. We operate in a regulated environment (HIPAA, HITRUST, SOC 2) with protected health information in scope across much of the business — security here is not a checkbox, it is part of how we deliver care.

We’re hiring a Staff Security Engineer to own and mature the security of the systems our workforce depends on every day, with a focus on endpoints and email. You’ll be a hands‑on generalist with deep engineering expertise in those two areas, and you’ll set the technical bar for them across OpenLoop and our subsidiaries.

Security Architecture & Engineering (SAE) builds and owns the security platform; our Security Operations team consumes it for detection and response. In this role you engineer, deploy, and harden the controls, and you partner closely with SecOps so the telemetry and tooling you build actually serve their mission.

At the Staff level, your impact goes beyond your own tickets. You’ll build controls that hold up for years, write the standards and baselines other engineers follow, and raise the technical bar of the team around you.

What You’ll Do
Endpoint security
  • Own the engineering of security controls for our macOS and Windows fleet, including device management (MDM), disk encryption, patch compliance, and local admin controls.

  • Engineer MDM and mobile application management (MAM) policies that protect company and PHI data on both managed devices and BYOD, including app protection, conditional access, and selective wipe.

  • Deploy and manage an enterprise browser to secure SaaS and web access, including data controls (copy/paste, download, print), session policies, and extension management.

  • Build, apply, and continuously measure CIS Benchmark baselines across the fleet. Track drift, manage documented exceptions, and produce fleet-level evidence that holds up to HITRUST and SOC 2 auditors.

  • Drive application control and least‑privilege on endpoints without breaking the clinicians and operators who depend on them.

Email security
  • Own email security for our Google Workspace environment: SPF, DKIM, DMARC enforcement, phishing and BEC defenses, attachment and link protection, and data loss prevention for PHI.

  • Tune controls to reduce real risk and false positives, and partner with SecOps on phishing triage workflows.

Across the program
  • Write security standards, configuration baselines, and runbooks that others can follow without you in the room.

  • Implement and validate controls identified through threat modeling and security reviews.

  • Contribute to audit readiness by mapping controls to HITRUST and SOC 2 requirements and owning evidence for your domains.

  • Automate repetitive work. If you’ve done it twice by hand, script it.

  • Mentor engineers on SAE and adjacent teams, and serve as an escalation point during incidents in your domains.

  • Partner with IT, Engineering, Compliance, and SecOps, translating security risk into business and operational terms.

  • Other duties as assigned.

Who You Are

You treat patient safety and integrity as non‑negotiable — speed never outruns integrity where care is involved. You own outcomes end to end, not just your part. You say the thing and explain the why, and you start from what we’re solving and why it matters now. At the Staff level that shows up as judgment other engineers borrow: you build the control that holds up, write the standard people actually follow, and leave the team more capable than you found it.

Required Qualifications
  • 8+ years in security engineering, with a track record of owning outcomes end to end.

  • Deep, hands‑on expertise in endpoint security and email security.

  • Experience deploying and operating MDM/MAM platforms (Kandji, Jamf, Intune, or similar) and email security platforms.

  • Experience deploying and managing an enterprise browser platform.

  • Hands‑on experience implementing CIS Benchmarks and measuring compliance against them at fleet scale.

  • Exposure to network security: secure remote access (ZTNA/VPN), DNS filtering, segmentation, or firewall policy.

  • Working knowledge of cloud security fundamentals (AWS preferred): IAM, network controls, logging, and how workforce access reaches cloud environments.

  • Exposure to DevSecOps practices: infrastructure as code, CI/CD security, secrets management, or security tooling in pipelines.

  • Scripting ability in Python, Bash, PowerShell, or similar.

  • Experience working in a regulated environment (HIPAA, HITRUST, SOC 2, PCI, or similar) and producing audit evidence.

  • Clear written communication. You can write a standard, defend a decision, and explain a risk to a non‑security executive.

Preferred Qualifications
  • Healthcare or health tech experience, especially environments handling PHI.

  • Experience with Okta or another enterprise identity provider.

  • Experience supporting a multi‑entity organization with subsidiaries or acquisitions.

  • Relevant certifications (GIAC, CISSP, OSCP, or cloud security certs) — a plus, not a requirement.

What We Offer
  • Competitive compensation

  • Medical, Dental & Vision

  • Flexible Spending / Health Savings Accounts

  • Generous PTO and hybrid‑work flexibility

  • 401(k) with Company Match

  • Life Insurance, Pet Insurance, and more

Our Company

We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.

Sound like a good fit? We’d love to meet you.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Engineer
Staff Security Engineer

Alt • Dallas (TX), Nashville (TN), Des Moines (IA)

Hybrid
USD 180,000 - 240,000
Compensation
Medical/Dental/Vision
FSA/HSA
+3
Director, IT Operations
Director, IT Operations

Alt • United States

On-site
USD 180,000 - 240,000
Medical, Dental, Vision
Flexible PTO
401(k) + Company Match
+2
Forward Deployed Engineer
Forward Deployed Engineer

Alt • Northern (KY)

Hybrid
USD 120,000 - 180,000
Senior Implementation Manager
Senior Implementation Manager

OpenLoop Health, Inc. • Northern (KY)

On-site
USD 120,000 - 170,000
Medical benefits
Dental benefits
Vision benefits
+6
Implementation Manager
Implementation Manager

OpenLoop Health, Inc. • Northern (KY)

On-site
USD 90,000 - 130,000
Medical, Dental & Vision
Flexible PTO and remote-work options
401(k) with Company Match
+2
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

Alt • United States

Hybrid
USD 110,000 - 140,000
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings
+4
Forward Deployed Engineer
Forward Deployed Engineer

Alt • United States

Hybrid
USD 140,000 - 230,000
Medical/Dental/Vision
401(k) Match
Flexible PTO
+2
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

OpenLoop • United States

On-site
USD 110,000 - 150,000
Healthcare benefits
Hybrid work
401(k) with company match
+2
Senior IT Audit Manager
Senior IT Audit Manager

Alt • United States

Hybrid
USD 140,000 - 190,000
Medical, Dental & Vision
Hybrid-work flexibility
401(k) with Company Match
+1
API Security Engineer
API Security Engineer

OpenLoop • United States

On-site
USD 100,000 - 130,000
Medical, Dental, and Vision plans
Flexible Spending/Health Savings Accounts
Flexible PTO
+2