Vulnerability & Attack Surface Lead — Security Ops

OpenLoop

United States

On-site

USD 110,000 - 150,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Healthcare benefits
Hybrid work
401(k) with company match
Generous PTO
Life/Pet Insurance

Job summary

OpenLoop seeks a Vulnerability & Attack Surface Management Analyst II to build and scale security programs across cloud workloads, endpoints, and applications. You will own the end-to-end vulnerability lifecycle, collaborate with engineering teams to ship fixes, and refine risk-based prioritization in a HIPAA-like, high-sensitivity environment.

You will also automate repetitive tasks, manage web app security, and contribute to publishing platform security checks as the org expands its external

Qualifications

  • 3 to 6 years in security with hands-on vulnerability management, attack surface management, or cloud security posture management.
  • Hands-on experience running and tuning a vulnerability scanning or CNAPP platform.
  • Experience prioritizing large findings with a risk-based model; knowledge of CVSS, EPSS, and the CISA KEV catalog.
  • Cloud security fundamentals in AWS or GCP; container/image vulnerabilities and SCA findings in code repos.
  • Comfort starting with an incomplete inventory and driving ownership across assets.
  • Experience collaborating with engineering teams to ship fixes.
  • Scripting skills (Python, PowerShell) to query APIs and automate reporting.
  • Regular use of AI tools (Claude, ChatGPT, GitHub Copilot) with PHI handling considerations.
  • Strong writing for tickets and risk summaries.

Responsibilities

  • Run the vulnerability lifecycle end-to-end: discovery, validation, prioritization, remediation tracking, verification, and reporting across cloud workloads, containers, code repos and endpoints.
  • Prioritize by actual risk using the risk model; iterate on model with evidence when changes are needed.
  • Build a reliable asset inventory integrating cloud, endpoint, and SaaS data with owners.
  • Drive remediation by coordinating with Engineering, IT, and Platform teams; write actionable tickets with timelines and escalations.
  • Automate repetitive tasks; roll out base images and dependency baselines; connect scanners to ticketing and reporting.
  • Own web app security: dynamic scans, coordinate fixes with application teams, use edge/WAF for temporary mitigation.
  • Define checks for new publishing platform; ensure inventoried and scanned before going live.
  • Manage vulnerability disclosure and bug bounty intake; validate reports and coordinate fixes.

Skills

Vulnerability management
Attack surface mgmt
Cloud security
Risk-based prioritization
Scripting (Python)
AI tools in security
Technical writing
Cross-functional collaboration
CVSS/EPSS knowledge

Tools

Wiz
Orca
Prisma Cloud
Defender for Cloud
Lacework
CrowdStrike Falcon Exposure Management
Jira
Slack

Job description

OpenLoop seeks a Vulnerability & Attack Surface Management Analyst II to build and scale security programs across cloud workloads, endpoints, and applications. You will own the end-to-end vulnerability lifecycle, collaborate with engineering teams to ship fixes, and refine risk-based prioritization in a HIPAA-like, high-sensitivity environment.

You will also automate repetitive tasks, manage web app security, and contribute to publishing platform security checks as the org expands its external

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability & Attack Surface Strategy Analyst II
Vulnerability & Attack Surface Strategy Analyst II

Openloop-Health • Des Moines (IA)

On-site
USD 90,000 - 120,000
Vulnerability & Attack Surface Lead — Hybrid
Vulnerability & Attack Surface Lead — Hybrid

OpenLoop Health • United States

Hybrid
USD 110,000 - 140,000
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings
+4
Strategic Vulnerability Lead & SOAR Engineer
Strategic Vulnerability Lead & SOAR Engineer

New Balance Athletics, Inc. • Richardson (TX)

Hybrid
USD 105,000 - 156,000
Medical insurance
Dental insurance
Vision insurance
+5
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

Openloop-Health • Des Moines (IA)

On-site
USD 90,000 - 120,000
Lead Vulnerability Operations Manager
Lead Vulnerability Operations Manager

Vantive • United States

On-site
USD 124,000 - 155,000
Competitive compensation
Comprehensive health, dental & vision
401(k) with employer match
+4
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

OpenLoop Health • United States

Hybrid
USD 110,000 - 140,000
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings
+4
Senior Manager, Vulnerability & Attack Surface Leadership
Senior Manager, Vulnerability & Attack Surface Leadership

Insight Global • Austin (TX)

Hybrid
USD 167,000 - 204,000
Medical insurance
Dental insurance
Vision insurance
+2
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

OpenLoop • United States

On-site
USD 110,000 - 150,000
Healthcare benefits
Hybrid work
401(k) with company match
+2
Vulnerability Operations Leader
Vulnerability Operations Leader

Vantive • Northern (KY)

Hybrid
USD 124,000 - 155,000
Medical, dental & vision
401(k) retirement plan
Paid time off 20–35 days
Vulnerability Management Lead: Drive Security Remediation
Vulnerability Management Lead: Drive Security Remediation

Altice USA • Norwalk (CT)

Hybrid
USD 150,000 - 210,000