Search Remote Jobs

Vulnerability & Attack Surface Management Analyst II

Job not on LinkedIn

🔥 1 minute ago

🇺🇸 United States – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🧐 Business Analyst

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of OpenLoop

OpenLoop

201 - 500 employees

Founded 2020

💼 Consulting

⚖️ Legal

📦 Logistics

💰 $15M Series A - OpenLoop Health on 2023-03

Consulting • Legal • Logistics

OpenLoop is a white-label telehealth platform and managed services provider that helps organizations launch and scale virtual care programs. It combines SaaS-based, brandable technology (scheduling, booking, payments, EHR/API integrations) with clinical staffing, credentialing, payer coverage and RCM, regulatory/legal support, and 24/7 patient support. OpenLoop serves health plans, hospitals and health systems, retailers, employers and digital health companies with AI-powered operations, a nationwide clinician network and broad insurance coverage including Medicare and Medicaid.

📋 Description

• Run the vulnerability lifecycle across cloud workloads, containers, code repositories, and endpoints, including discovery, validation, prioritization, remediation tracking, verification, and reporting • Apply and improve a risk model using internet exposure, exploitability, asset criticality, and data sensitivity • Build a reliable asset inventory combining cloud, endpoint, and SaaS inventory, with named owners • Conduct scheduled external attack surface discovery to identify internet-exposed assets • Drive remediation through Engineering, IT, and Platform teams; create actionable tickets, agree timelines, escalate blockers, and verify fixes • Roll out hardened base images and dependency baselines to address root causes • Connect scanner and CNAPP APIs to ticketing and reporting systems and automate repetitive reporting • Own web application security through dynamic scanning, application-team remediation, and temporary edge/WAF mitigation • Establish security checks for internally built, externally published applications before launch • Manage vulnerability disclosure and bug bounty intake, including report validation, researcher communication, duplicate handling, and verified remediation • Use AI tools to triage findings, correlate data, draft remediation guidance, and produce reports while protecting PHI • Track mean time to remediate, backlog burn-down, and SLA coverage • Prepare leadership reporting and evidence for client, partner, and auditor requests in a HIPAA-regulated environment • Report to the Director of Information Security and advise on changing program priorities

🎯 Requirements

• 3 to 6 years in security, with significant hands-on experience in vulnerability management, attack surface management, or cloud security posture management • Hands-on experience running and tuning a vulnerability scanning or CNAPP platform • Experience prioritizing a large set of findings with a risk-based model • Working knowledge of CVSS, EPSS, and the CISA KEV catalog • Cloud security fundamentals in at least one major provider, preferably GCP or AWS • Experience with container and image vulnerabilities and dependency (SCA) findings in code repositories • Comfort starting with an incomplete inventory and determining what exists and who owns it • Experience working directly with engineering teams to get fixes shipped • Scripting skills in Python, PowerShell, or similar, sufficient to query APIs and automate reporting • Regular, hands-on use of AI tools such as Claude, ChatGPT, or GitHub Copilot in security work • Ability to explain safe handling of PHI, credentials, and sensitive data in AI tools • Strong writing skills for engineering tickets and executive risk summaries • Preferred experience with Wiz, Orca, Prisma Cloud, Defender for Cloud, Lacework, CrowdStrike Falcon Exposure Management or Spotlight, Tenable, Qualys, or Rapid7 • Preferred experience with external ASM tools, DNS, certificate transparency, subdomain and shadow IT discovery, CAASM, Axonius, runZero, and SaaS discovery tools • Preferred experience with DAST, WAF, Invicti, Burp Suite, Cloudflare, Akamai, HackerOne, or Bugcrowd • Preferred experience with hardened base images, Kubernetes, GKE, EKS, Vercel, Netlify, Cloudflare Pages, SBOMs, and software supply chain security • Preferred experience in healthcare, fintech, or another regulated industry, including HIPAA, HITRUST, or SOC 2 work • Preferred certifications include GCLD, GCPN, GWEB, GSEC, AWS or GCP security specialty, OSCP, or equivalent experience

🏖️ Benefits

• Competitive compensation • Medical, Dental & Vision • Flexible Spending / Health Savings Accounts • Generous PTO and hybrid-work flexibility • 401(k) with Company Match • Life Insurance, Pet Insurance, and more

Apply Now

Similar Jobs

🔥 3 hours ago

CACI International Inc

10,000+ employees

🎖️ Defense

🏛️ Government

🔒 Cybersecurity

Oracle EBS UMX Business Analyst supporting CACI’s federal financial systems and access management solutions. Designing, implementing, testing, and supporting Oracle EBS User Management.

🇺🇸 United States – Remote

💵 $75.2k - $158.1k / year

🔥 Funding within the last year

💰 $500M Post-IPO Debt on 2026-02

⏰ Full Time

🟡 Mid-level

🟠 Senior

🧐 Business Analyst

🔥 11 hours ago

Kidde Global Solutions

5001 - 10000

🏭 Manufacturing

🔧 Hardware

🔐 Security

E-commerce Business Analyst turning POS, digital shelf, and consumer data into growth strategies. Building executive dashboards and recommendations for retail and commercial stakeholders.

🔥 14 hours ago

S2Tech

51 - 200

💼 Consulting

🏥 Healthcare

📦 Logistics

Senior Business Analyst modernizing Medicaid provider enrollment portals, workflows, and integrations. Supporting S2Tech’s health and human services IT consulting projects.

🔥 19 hours ago

RR Donnelley

10,000+ employees

💼 Consulting

📦 Logistics

🏭 Manufacturing

IT Business Analyst defining requirements and integrated solutions for RRD, a global marketing, packaging, print, and supply-chain provider. Supporting development projects, testing, process design, and business-technology collaboration.

🔥 21 hours ago

Guidehouse

10,000+ employees

🏥 Healthcare

🎖️ Defense

📦 Logistics

ServiceNow Business Analyst leading federal consulting projects for Guidehouse. Translating requirements into ServiceNow solutions, processes, documentation, testing, and training.