Vulnerability & Attack Surface Lead — Hybrid

OpenLoop Health

United States

Hybrid

USD 110,000 - 140,000

Full time

12 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings
Generous PTO and hybrid-work
401(k) with Company Match
Life Insurance
Pet Insurance

Job summary

OpenLoop Health is building a Vulnerability & Attack Surface Management program to protect PHI and HIPAA-relevant systems. You will own the lifecycle from discovery to remediation, prioritize risks, build a unified asset view, and drive fixes across engineering, IT, and platform teams.

You’ll leverage CNAPP integrations, AI tools, and dynamic scans to reduce exposure while coordinating with auditors and clients.

Qualifications

  • 3–6 years in security with vulnerability mgmt, ASM, or cloud security posture management.
  • Hands-on experience with vulnerability scanning / CNAPP platforms.
  • Ability to prioritize a large findings set using a risk-based model (CVSS/EPSS/CISA KEV).
  • Cloud provider fundamentals (GCP/AWS), container and image vulnerabilities, SCA in code repos.
  • Experience shipping fixes with engineering teams; automation of reporting and checks.

Responsibilities

  • Run the vulnerability lifecycle day to day: discovery, validation, prioritization, remediation tracking, verification, and reporting across cloud workloads, containers, code repos, and endpoints.
  • Prioritize by actual risk using the risk model; adjust priorities with evidence when needed.
  • Build a reliable asset inventory spanning cloud, endpoint, and SaaS, with asset ownership.
  • Drive remediation through Engineering, IT, and Platform teams; write actionable tickets with realistic timelines.
  • Automate repetitive work and roll out base images and dependencies to close many findings.
  • Own web application security; run dynamic scans and coordinate fixes with app teams.
  • Set up checks for the publishing platform; inventory and scan apps before go-live.
  • Manage vulnerability disclosure and bug bounty intake; validate, respond, and verify fixes.
  • Use AI tools daily to triage findings, draft remediation guidance, and produce reports.
  • Track metrics like mean time to remediated and backlog burn-down; support client/auditor requests.

Skills

Vulnerability mgmt
Attack surface mgmt
Cloud security
Scripting (Python/PowerShell)
AI tools usage
Technical writing

Tools

Wiz
Jira

Job description

OpenLoop Health is building a Vulnerability & Attack Surface Management program to protect PHI and HIPAA-relevant systems. You will own the lifecycle from discovery to remediation, prioritize risks, build a unified asset view, and drive fixes across engineering, IT, and platform teams.

You’ll leverage CNAPP integrations, AI tools, and dynamic scans to reduce exposure while coordinating with auditors and clients.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability & Attack Surface Lead — Security Ops
Vulnerability & Attack Surface Lead — Security Ops

OpenLoop • United States

On-site
USD 110,000 - 150,000
Healthcare benefits
Hybrid work
401(k) with company match
+2
Vulnerability & Attack Surface Strategy Analyst II
Vulnerability & Attack Surface Strategy Analyst II

Openloop-Health • Des Moines (IA)

On-site
USD 90,000 - 120,000
Senior Vulnerability & Attack Surface Leader (Hybrid)
Senior Vulnerability & Attack Surface Leader (Hybrid)

McLane Company, Inc. • Austin (TX)

On-site
USD 150,000 - 210,000
Senior Manager, Vulnerability & Attack Surface Leadership
Senior Manager, Vulnerability & Attack Surface Leadership

Insight Global • Austin (TX)

Hybrid
USD 167,000 - 204,000
Medical insurance
Dental insurance
Vision insurance
+2
Strategic Vulnerability Lead & SOAR Engineer
Strategic Vulnerability Lead & SOAR Engineer

New Balance Athletics, Inc. • Richardson (TX)

Hybrid
USD 105,000 - 156,000
Medical insurance
Dental insurance
Vision insurance
+5
Senior InfoSec Analyst - Attack Surface Lead (Hybrid)
Senior InfoSec Analyst - Attack Surface Lead (Hybrid)

Mass General Brigham (Enterprise Services) • Somerville (MA)

Hybrid
USD 94,000 - 137,000
Lead Security Engineer - Attack Surface & Automation
Lead Security Engineer - Attack Surface & Automation

Wellington Management Company LLP • United States

Hybrid
USD 150,000 - 210,000
Senior Vulnerability & Attack Surface Lead
Senior Vulnerability & Attack Surface Lead

McLane Company, Inc • Austin (TX)

Hybrid
USD 140,000 - 190,000
Day 1 Benefits: medical, dental, and视觉
Paid time off begins day one
401(k) Profit Sharing Plan after 90日
+3
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

Openloop-Health • Des Moines (IA)

On-site
USD 90,000 - 120,000
Lead Vulnerability Operations Manager
Lead Vulnerability Operations Manager

Vantive • United States

On-site
USD 124,000 - 155,000
Competitive compensation
Comprehensive health, dental & vision
401(k) with employer match
+4