OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.
OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. We deliver white-labeled clinical and operational infrastructure that helps companies scale virtual care across all 50 states: telehealth delivery, clinician staffing, licensing, payer coverage, and revenue cycle management. Our clients run on our platform under their own brand, which means their patients’ trust depends on how well we protect it. We operate in a regulated environment (HIPAA, HITRUST, SOC 2) with protected health information in scope across much of the business — security here is not a checkbox, it is part of how we deliver care.
We’re hiring a Staff Security Engineer to own and mature the security of the systems our workforce depends on every day, with a focus on endpoints and email. You’ll be a hands-on generalist with deep engineering expertise in those two areas, and you’ll set the technical bar for them across OpenLoop and our subsidiaries.
Security Architecture & Engineering (SAE) builds and owns the security platform; our Security Operations team consumes it for detection and response. In this role you engineer, deploy, and harden the controls, and you partner closely with SecOps so the telemetry and tooling you build actually serve their mission.
At the Staff level, your impact goes beyond your own tickets. You’ll build controls that hold up for years, write the standards and baselines other engineers follow, and raise the technical bar of the team around you.
Own the engineering of security controls for our macOS and Windows fleet, including device management (MDM), disk encryption, patch compliance, and local admin controls.
Engineer MDM and mobile application management (MAM) policies that protect company and PHI data on both managed devices and BYOD, including app protection, conditional access, and selective wipe.
Deploy and manage an enterprise browser to secure SaaS and web access, including data controls (copy/paste, download, print), session policies, and extension management.
Build, apply, and continuously measure CIS Benchmark baselines across the fleet. Track drift, manage documented exceptions, and produce fleet-level evidence that holds up to HITRUST and SOC 2 auditors.
Drive application control and least-privilege on endpoints without breaking the clinicians and operators who depend on them.
Own email security for our Google Workspace environment: SPF, DKIM, DMARC enforcement, phishing and BEC defenses, attachment and link protection, and data loss prevention for PHI.
Tune controls to reduce real risk and false positives, and partner with SecOps on phishing triage workflows.
Write security standards, configuration baselines, and runbooks that others can follow without you in the room.
Implement and validate controls identified through threat modeling and security reviews.
Contribute to audit readiness by mapping controls to HITRUST and SOC 2 requirements and owning evidence for your domains.
Automate repetitive work. If you’ve done it twice by hand, script it.
Mentor engineers on SAE and adjacent teams, and serve as an escalation point during incidents in your domains.
Partner with IT, Engineering, Compliance, and SecOps, translating security risk into business and operational terms.
Other duties as assigned.
You treat patient safety and integrity as non-negotiable — speed never outruns integrity where care is involved. You own outcomes end to end, not just your part. You say the thing and explain the why, and you start from what we’re solving and why it matters now. At the Staff level that shows up as judgment other engineers borrow: you build the control that holds up, write the standard people actually follow, and leave the team more capable than you found it.
8+ years in security engineering, with a track record of owning outcomes end to end.
Deep, hands-on expertise in endpoint security and email security.
Experience deploying and operating MDM/MAM platforms (Kandji, Jamf, Intune, or similar) and email security platforms.
Experience deploying and managing an enterprise browser platform.
Hands-on experience implementing CIS Benchmarks and measuring compliance against them at fleet scale.
Exposure to network security: secure remote access (ZTNA/VPN), DNS filtering, segmentation, or firewall policy.
Working knowledge of cloud security fundamentals (AWS preferred): IAM, network controls, logging, and how workforce access reaches cloud environments.
Exposure to DevSecOps practices: infrastructure as code, CI/CD security, secrets management, or security tooling in pipelines.
Scripting ability in Python, Bash, PowerShell, or similar.
Experience working in a regulated environment (HIPAA, HITRUST, SOC 2, PCI, or similar) and producing audit evidence.
Clear written communication. You can write a standard, defend a decision, and explain a risk to a non-security executive.
Healthcare or health tech experience, especially environments handling PHI.
Experience with Okta or another enterprise identity provider.
Experience supporting a multi-entity organization with subsidiaries or acquisitions.
Relevant certifications (GIAC, CISSP, OSCP, or cloud security certs) — a plus, not a requirement.
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings Accounts
Generous PTO and hybrid-work flexibility
401(k) with Company Match
Life Insurance, Pet Insurance, and more
We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.
Sound like a good fit? We’d love to meet you.