Director Information Security - ASM / VM

Remote Full-time
About OpenLoop OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring healing anywhere. Our tele-health support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states. Our Company Culture We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work. About the Role OpenLoop is looking for a Director Information Security, ASM / VM to join our team remotely or at our HQ in Des Moines, IA. In this role, you will be responsible for identifying, tracking and verifying the remediation of vulnerabilities, misconfigurations, and risks across internal and external applications and systems. This leader will possess both business and technical acumen with a strong understanding of the many different systems and applications across the company. A diverse understanding of cybersecurity principles, enterprise systems, Artificial Intelligence (AI) applications, and business process dependencies is required. The ideal candidate will support both short- and long-term strategic initiatives outlined by cybersecurity and IT leadership, identifying and reducing attack surface vulnerabilities, fostering automation, innovation and operational efficiency. What You'll Do: • Lead the attack surface and vulnerability management of applications, endpoints, databases, networking, operating systems, mobile, third parties and cloud services. • Liaise with IT and security leadership to manage internal- and external-facing systems to identify, track and remediate system and application vulnerabilities. • Develop strategies to identify vulnerabilities and align applicable remediations. • Manage vulnerability remediations, exploitation probability, and business risks. • Cultivate relationships across all operational teams to support security goals • Collaborate with IT, product, engineering, and cybersecurity leadership to develop practices and plans, to reduce potential attacks. • Partner closely with various teams, supporting all remediation efforts • Support employees in managing emerging threats and practices to strong security • Maintain an active asset inventory, including asset vulnerability state, remediation recommendations, across all business units. • Define key performance indicators, objectives and key results, to illustrate efficacy with attack surface and vulnerability management. • Embrace automation with asset inventory and vulnerability discovery reporting. • Certify testing and validation of vulnerability remediation and controls. • Communicate the state of vulnerability management to stakeholders, developers, IT and business leaders. • Participate in vulnerability special interest groups and consortiums for knowledge and building relationships. • Exhibit an above and beyond attitude and work ethic to support the business in response to security threats, providing timely support and action. • Manage the bug bounty program to surface and address security risks • Develop and execute an ASM/VM strategy, policies, standards, and procedures. • Collaborate with internal and external threat intelligence sources, law enforcement, and government bodies (e.g., H-ISAC) to stay updated on evolving threats, risks, and TTPs (tactics, techniques, and procedures). • Keep up to date on security knowledge and technology best practices • Ensure regulatory compliance (e.g., PCI, HIPAA, HITRUST, NIST CSF) through effective security operations controls and processes. • Other duties as assigned. Who You Are • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field is preferred. • 10-15 years of experience in Information Security, with at least 5 of those years focused on security operations, attack surface management, vulnerability management operations. • Experienced with commercial and open source VMS solutions and processes. • Applicable knowledge of adversary tactics, techniques and procedures (TTPs), MITRE ATT&ACK framework, CVSS, open source intelligence (OSINT) and deception techniques. • Strong understanding of cloud security environments and technologies (AWS, GCP, SaaS, IaaS, PaaS) • Strong handle of cyber threat landscapes, attack vectors, and defensive tactics. • Familiarity with regulatory frameworks (HIPAA, HITRUST, NIST CSF). • Excellent leadership and communication skills with the ability to engage technical and non-technical stakeholders, including senior executives • Ability to effectively collaborate and communicate with various teams • Analytical and problem-solving abilities with a proactive, risk-based approach. • Experience with handling a dynamic, challenging and fast-paced environment. • Strong people acumen and relationship skills • Excellent organizational and documentation skills. • Experience in healthcare or digital health is a plus. Our Benefits In addition, for salaried positions you would also be eligible for: • Medical, Dental, and Vision plans • Flexible Spending/Health Savings Accounts • Flexible PTO • 401(k) + Company Match • Life Insurance, Pet insurance, and more Sound like a good fit? We’d love to meet you. Apply tot his job
Apply Now →

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

**Experienced Data Entry Specialist – Remote Opportunity at arenaflex**

Remote

Compliance Auditor - To 67K - Cherry Hill, NJ - Job # 2929

Remote

Family Law Attorney, 100% Remote - Boston Area

Remote

Clinical Research Coordinator 1

Remote

**Experienced Full Stack Live Chat Agents – Flexible Remote Work Opportunities at blithequark**

Remote

**Experienced Data Entry Specialist – Remote Opportunity for Beginners to Join the Magic of Disney**

Remote

Remote - Global Data Modeler

Remote

**Experienced Part-Time Remote Data Entry Specialist – Global Airline Operations Support**

Remote

Entry-Level Data Entry Specialist at blithequark - Part-Time Opportunity to Kickstart Your Career in a Dynamic Environment

Remote

Part-Time Data Entry Specialist – Walmart (Teens Welcome)

Remote
← Back