Vulnerability & Attack Surface Strategy Analyst II

Openloop-Health

Des Moines (IA)

On-site

USD 90,000 - 120,000

Full time

12 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

OpenLoop is seeking a Vulnerability & Attack Surface Management Analyst II to help build and run our security program. You’ll own the vulnerability lifecycle, manage exposure and remediation across cloud workloads, code repos, and endpoints, and drive risk-based decisions with cross-functional partners.

Reporting to the Director of Information Security, you’ll shape prioritization, scale an evolving platform, and leverage AI tools to triage findings while protecting PHI under HIPAA.

Qualifications

  • 3–6 years in security with significant hands-on vulnerability management or ASM experience.
  • Hands-on experience running and tuning a vulnerability scanning or CNAPP platform.
  • Experience prioritizing findings with a risk-based model; familiarity with CVSS, EPSS, and CISA KEV.
  • Cloud security fundamentals (GCP or AWS) and container/image vulnerability awareness.

Responsibilities

  • Run the vulnerability lifecycle from discovery to reporting across cloud workloads and endpoints.
  • Prioritize by real risk, refine the risk model, and escalate decisions when needed.
  • Build and own a comprehensive asset inventory with owners for critical assets.
  • Drive remediation by coordinating with engineering, IT, and platform teams.
  • Automate repetitive tasks and connect scanners to ticketing and reporting workflows.
  • Own web app security: run DAST and coordinate fixes with application teams.
  • Ensure security checks for new publishing platforms before go-live.
  • Manage vulnerability disclosures and coordinate responses with researchers.

Skills

Vulnerability management
Attack surface management
Cloud security
Scripting (Python/PowerShell)
Risk-based prioritization
Stakeholder communication

Tools

Wiz
GCP
AWS

Job description

OpenLoop is seeking a Vulnerability & Attack Surface Management Analyst II to help build and run our security program. You’ll own the vulnerability lifecycle, manage exposure and remediation across cloud workloads, code repos, and endpoints, and drive risk-based decisions with cross-functional partners.

Reporting to the Director of Information Security, you’ll shape prioritization, scale an evolving platform, and leverage AI tools to triage findings while protecting PHI under HIPAA.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability & Attack Surface Lead — Security Ops
Vulnerability & Attack Surface Lead — Security Ops

OpenLoop • United States

On-site
USD 110,000 - 150,000
Healthcare benefits
Hybrid work
401(k) with company match
+2
Vulnerability & Attack Surface Lead — Hybrid
Vulnerability & Attack Surface Lead — Hybrid

OpenLoop Health • United States

Hybrid
USD 110,000 - 140,000
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings
+4
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

OpenLoop Health • United States

Hybrid
USD 110,000 - 140,000
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings
+4
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

Openloop-Health • Des Moines (IA)

On-site
USD 90,000 - 120,000
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

OpenLoop • United States

On-site
USD 110,000 - 150,000
Healthcare benefits
Hybrid work
401(k) with company match
+2
Senior 2 Cybersecurity Analyst - Attack Surface Management
Senior 2 Cybersecurity Analyst - Attack Surface Management

Brobston Group • Seattle (WA)

On-site
USD 140,000 - 170,000
Senior Vulnerability Governance & Risk Analyst
Senior Vulnerability Governance & Risk Analyst

System One • Knoxville (TN)

On-site
USD 120,000 - 180,000
Senior Vulnerability Analyst, SOC & Threat Research
Senior Vulnerability Analyst, SOC & Threat Research

Ultipro • Salt Lake City (UT)

On-site
USD 110,000 - 140,000
Lead Cybersecurity Risk & Vulnerability Management Analyst
Lead Cybersecurity Risk & Vulnerability Management Analyst

The Judge Group • Dallas (TX)

On-site
USD 85,000 - 110,000
Senior Vulnerability & Risk Analyst (Remote)
Senior Vulnerability & Risk Analyst (Remote)

Covington & Burling LLP • United States

On-site
USD 95,000 - 157,000
Healthcare insurance
Comprehensive benefits