All jobs

Director Information Security - ASM / VM

100% Remote Full-time Open now

About OpenLoop OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring healing anywhere. Our tele-health support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states. Our Company Culture We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.

About the Role

OpenLoop is looking for a Director Information Security, ASM / VM to join our team remotely or at our HQ in Des Moines, IA. In this role, you will be responsible for identifying, tracking and verifying the remediation of vulnerabilities, misconfigurations, and risks across internal and external applications and systems. This leader will possess both business and technical acumen with a strong understanding of the many different systems and applications across the company. A diverse understanding of cybersecurity principles, enterprise systems, Artificial Intelligence (AI) applications, and business process dependencies is required. The ideal candidate will support both short- and long-term strategic initiatives outlined by cybersecurity and IT leadership, identifying and reducing attack surface vulnerabilities, fostering automation, innovation and operational efficiency. What You'll Do:

  • Lead the attack surface and vulnerability management of applications, endpoints, databases, networking, operating systems, mobile, third parties and cloud services.
  • Liaise with IT and security leadership to manage internal- and external-facing systems to identify, track and remediate system and application vulnerabilities.
  • Develop strategies to identify vulnerabilities and align applicable remediations.
  • Manage vulnerability remediations, exploitation probability, and business risks.
  • Cultivate relationships across all operational teams to support security goals
  • Collaborate with IT, product, engineering, and cybersecurity leadership to develop practices and plans, to reduce potential attacks.
  • Partner closely with various teams, supporting all remediation efforts
  • Support employees in managing emerging threats and practices to strong security
  • Maintain an active asset inventory, including asset vulnerability state, remediation recommendations, across all business units.
  • Define key performance indicators, objectives and key results, to illustrate efficacy with attack surface and vulnerability management.
  • Embrace automation with asset inventory and vulnerability discovery reporting.
  • Certify testing and validation of vulnerability remediation and controls.
  • Communicate the state of vulnerability management to stakeholders, developers, IT and business leaders.
  • Participate in vulnerability special interest groups and consortiums for knowledge and building relationships.
  • Exhibit an above and beyond attitude and work ethic to support the business in response to security threats, providing timely support and action.
  • Manage the bug bounty program to surface and address security risks
  • Develop and execute an ASM/VM strategy, policies, standards, and procedures.
  • Collaborate with internal and external threat intelligence sources, law enforcement, and government bodies (e.g., H-ISAC) to stay updated on evolving threats, risks, and TTPs (tactics, techniques, and procedures).
  • Keep up to date on security knowledge and technology best practices
  • Ensure regulatory compliance (e.g., PCI, HIPAA, HITRUST, NIST CSF) through effective security operations controls and processes.
  • Other duties as assigned.

Who You Are

  • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field is preferred.
  • 10-15 years of experience in Information Security, with at least 5 of those years focused on security operations, attack surface management, vulnerability management operations.
  • Experienced with commercial and open source VMS solutions and processes.
  • Applicable knowledge of adversary tactics, techniques and procedures (TTPs), MITRE ATT&ACK framework, CVSS, open source intelligence (OSINT) and deception techniques.
  • Strong understanding of cloud security environments and technologies (AWS, GCP, SaaS, IaaS, PaaS)
  • Strong handle of cyber threat landscapes, attack vectors, and defensive tactics.
  • Familiarity with regulatory frameworks (HIPAA, HITRUST, NIST CSF).
  • Excellent leadership and communication skills with the ability to engage technical and non-technical stakeholders, including senior executives
  • Ability to effectively collaborate and communicate with various teams
  • Analytical and problem-solving abilities with a proactive, risk-based approach.
  • Experience with handling a dynamic, challenging and fast-paced environment.
  • Strong people acumen and relationship skills
  • Excellent organizational and documentation skills.
  • Experience in healthcare or digital health is a plus.

Our Benefits In addition, for salaried positions you would also be eligible for:

  • Medical, Dental, and Vision plans
  • Flexible Spending/Health Savings Accounts
  • Flexible PTO
  • 401(k) + Company Match
  • Life Insurance, Pet insurance, and more

Sound like a good fit? We’d love to meet you. Apply tot his job Apply To this Job

You might also like

Director, Information Security Trust officer Remote or hybrid in MN or DC

100% Remote Full-time

Sr. Director, Business Information Security Officer - Remote or Hybrid from MN or DC

100% Remote Full-time

Information Security Officer

100% Remote Full-time

Information Systems Security Officer, Isso, Authority to Operate & Compliance

100% Remote Full-time

Director, IT Infrastructure & Security Officer

100% Remote Full-time

[Remote] IT Infrastructure & Service Management Consultant (Temporary)

100% Remote Full-time

Infrastructure Data Center Consultant - Contract - (12 Months)

100% Remote Full-time

Senior Consultant: OCP Infrastructure - Full-time

100% Remote Full-time

IT Audit Consultant - Technology Infrastructure & Operations

100% Remote Full-time

Inspector (Mid - Senior Level) - Division 10, 12, & 13

100% Remote Full-time

Senior Security Architect & Engineer

100% Remote Full-time

Apple At Home Jobs - Data Entry Remote Careers (Part-Time) $32/H

100% Remote Full-time

Senior Software Sales Specialist - SLED

100% Remote Full-time

Online Customer Service Jobs for Teens Entry Level

100% Remote Full-time

Head of Total Rewards – People Operations

100% Remote Full-time

Financial Manager I - Limited Service (Waterbury, VT, US)

100% Remote Full-time

Job Title: Experienced Customer Service Representative – High-Paying Remote Opportunity with careerzynith

100% Remote Full-time

Sr Director Analyst, AI Technologies - Generative AI/Machine Learning (Remote Eu

100% Remote Full-time

Logistics Management Trainee in Indianapolis, IN

100% Remote Full-time

Experienced Customer Experience Consultant – Hybrid Role with Remote and On-Site Opportunities at blithequark

100% Remote Full-time