--- title: 'Senior Incident Response Analyst at OpenLoop Health' canonical: 'https://feeny.ai/job/senior-incident-response-analyst-openloop-health-united-states-aa8gtm5efztc' type: 'job' last_seen: '2026-09-10' --- # Senior Incident Response Analyst at OpenLoop Health - **Company:** OpenLoop Health - **Location:** United States - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-09-08 - **Last confirmed live:** 2026-09-10 - **Apply:** https://jobs.ashbyhq.com/openloophealth/4906263d-871e-4702-a9ab-68ff52d37f38 ## Job description ## About OpenLoop OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states. ## About the Role OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Our Security Operations team protects the clinical and operational systems that OpenLoop and our partners run patient care on. As a Senior Incident Response Analyst, you’ll be a dedicated responder on our DFIR function — owning incidents end to end, deepening our forensic capability, and making sure containment happens fast when PHI and clinical operations are on the line. ## What You’ll Do - Own tier-1 and tier-2 incidents end to end: detection validation, triage, scoping, containment, eradication, recovery, and post-incident review. - Run host, memory, network, cloud, and identity forensic investigations independently, with evidence handling that holds up to legal, regulatory, and client scrutiny. - Investigate from EDR and SIEM telemetry — write and refine queries, build correlation logic, and reconstruct incident timelines from log data. - Share the IR on-call rotation with the Lead Incident Responder and Senior Staff Security Analyst, and exercise named containment authority (host isolation, session revocation) within a defined threshold. - Author and rewrite IR playbooks based on incidents you personally work, and run post-incident reviews with findings tracked to closure. - Automate or AI-assist repetitive triage and evidence-collection steps so the team’s time goes to investigation rather than toil. - Write for two audiences — a defensible technical timeline and an executive summary of the same incident. ## Who You Are You’re a hands-on responder who has led real incidents under real ambiguity, and you’re straight about what you got wrong. We hire for the discipline, not the tool SKU or the credential: no specific degree is required, and strong responders from Defender, SentinelOne, Splunk, or Sentinel environments are fully in scope. This is an individual contributor role. Required Qualifications - 6–8 years of hands-on security experience, with the majority in incident response and/or digital forensics. - Demonstrated ownership of the full incident lifecycle, from detection validation through post-incident review. - Digital forensics breadth across host/disk, memory, network, cloud, and identity — from real casework, not coursework. - Working depth in EDR/EPP: investigating from endpoint telemetry, running response actions, and tuning what the tool surfaces. - Working depth in SIEM: query authoring, correlation logic, and timeline reconstruction from log data. - Hands-on fluency with a forensic toolchain (e.g., Velociraptor, KAPE, Volatility, Autopsy/EnCase/FTK/X-Ways, plaso, Zeek, Wireshark). - Evidence handling discipline — chain of custody, sound acquisition, and documentation that survives legal, regulatory, and client scrutiny. - MITRE ATT&CK fluency applied to real investigations. - Scripting for investigation and automation (Python, PowerShell, or similar). - Demonstrated, hands-on use of AI tools (Claude, ChatGPT, Copilot, or equivalent) in security work, with specific examples of their impact on speed or quality — and sound judgment about AI and sensitive data (PHI, credentials, telemetry). - Clear incident writing: able to produce both a technical timeline and an executive summary of the same incident. - Willingness to participate in a shared IR on-call rotation. ## Preferred Qualifications - CrowdStrike Falcon EDR — hands-on investigation and response in the console. - CrowdStrike Falcon Next-Gen SIEM — CQL query authoring, correlation rules, and dashboards. - CrowdStrike Falcon Shield — SaaS app, identity, and third-party integration risk. - Cloud incident response in AWS (CloudTrail, GuardDuty, IAM abuse patterns). - Identity-centric investigation, particularly Okta (session hijacking, MFA fatigue, token theft, SSO abuse). - Healthcare, fintech, or other regulated-industry experience with sensitive data. - HIPAA, HITRUST, or SOC 2 from the operator side, including breach determination workflow. - GCFA, GCFE, GCIH, GNFA, GCIA, GREM, or equivalent demonstrated expertise. - Malware triage and reverse engineering fundamentals. - SOAR / automation platform experience, or AI-assisted IR workflows built on LLM APIs. - Multi-entity or M&A environment experience — we operate across several subsidiaries. - Open-source contributions to DFIR or security tooling; CTF history, conference talks, or other community engagement. - Experience maturing an IR program from a lower baseline. - Threat intelligence consumption applied to active investigations. What Success Looks Like - In your first 6 months: fully onboarded and taking primary responder duty on a defined rotation, independently owning tier-1 and tier-2 incidents without escalation for routine cases. - Forensic capability is genuinely two-deep — you can run a host, memory, cloud, or identity investigation without the Lead Incident Responder in the room. - At least three IR playbooks rewritten or newly authored from incidents you worked, with post-incident reviews running on a consistent cadence and findings tracked to closure. - In your first 12 months: measurable reduction in MTTD and MTTR against baseline, with repetitive triage and evidence collection automated or AI-assisted rather than manual. Our Benefits In addition, for salaried positions you would also be eligible for: - Medical, Dental, and Vision plans - Flexible Spending/Health Savings Accounts - Flexible PTO - 401(k) + Company Match - Life Insurance, Pet insurance, and more Our Company We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work. Sound like a good fit? We’d love to meet you. ## About OpenLoop Health ## Company Overview - **One-liner**: OpenLoop Health provides end-to-end, white-label telehealth infrastructure that enables healthcare and non-healthcare organizations to launch and scale digital health services. - **Entity Type**: Private - **Headquarters**: Des Moines, Iowa, United States - **Founded**: 2020 - **Founders**: Dr. Jon Lensing (CEO & Co-Founder) and Christian Williams (COO & Co-Founder) ## Core Business - **Primary industry**: Digital Health / Telehealth Infrastructure - **Target customers**: B2B — Digital health companies, hospitals & health systems, health plans, employers, retail & pharmacy, and non-healthcare entities looking to add virtual care offerings. - **Mission**: To bring healing anywhere, anytime to anyone across the nation. - **Vision**: A world where healthcare is accessible, efficient, and tailored to individual needs—delivered wherever the patient may be. ## Products & Services OpenLoop offers a full-stack, white-labeled suite of services: - **Technology Platform**: HIPAA-compliant EHR with flexible API integrations, scheduling, booking, payments, and support for both synchronous and asynchronous care. AI-powered operations to streamline clinical workflows. - **Provider Staffing & Credentialing**: Access to a nationwide, NCQA-credentialed network of clinicians across 30+ specialties and 15+ languages, with full 50-state coverage. Includes licensing, credentialing, and onboarding management. - **Payer Coverage & Revenue Cycle Management (RCM)**: A network of 600+ payer contracts including Medicare and Medicaid, paired with RCM services to streamline reimbursement. - **Regulatory, Legal & Compliance Support**: End-to-end legal, financial, and compliance setup, including ongoing regulatory maintenance and expert support. - **Clinical Pathways**: Over 100 repeatable, scalable, and vetted clinical protocols (e.g., medical weight loss, HRT, urgent care, mental health). - **Diagnostic Imaging & Labs**: A platform for diagnostic image ordering, referrals, and results, plus access to a network of pharmacy and lab partners for competitive medication costs. ## Market Standing - **Valuation**: Not publicly available (private company) - **Key Metric**: Trusted by 3M+ patients annually; serves patients in all 50 states; processes thousands of patient visits per month. - **Notable Investors/Partners**: Managing board includes Jack Berkowitz, Freddie Martignetti, and Ryan Morley. Client partners span digital health companies, hospitals, health plans, and employers. - **Growth Signals**: OpenLoop saw **700% YoY growth in 2024**, appointed key executive team members (including a Chief Medical Officer, CFO, CCO, and CPO), and integrated AI technology into its operations. LinkedIn followers grew 124.8% year-over-year. ## Competitive Advantages - **Full-stack, end-to-end solution**: OpenLoop is the only white-label provider that covers clinical, administrative, regulatory, and technological needs under one roof — clients bring their brand and patients, OpenLoop handles everything else. - **Nationwide scale**: 50-state PC network, 600+ payer contracts (including Medicare/Medicaid), and a network of thousands of clinicians. - **NCQA-accredited credentialing**: A streamlined, accredited credentialing process that reduces administrative burden for clients. - **Proven, repeatable clinical pathways**: Over 100 pre-vetted, scalable protocols allow clients to launch new programs quickly and safely. - **Deep Midwest roots**: Headquarters in Des Moines, Iowa, with a commitment to building local talent and positioning Iowa as a hub for healthcare transformation. ## Strategic Focus - **AI integration**: Embedding AI to streamline clinical workflows, enhance patient support, and guide optimized care pathways. - **Expansion of clinical pathways**: Continuously developing new, ready-to-use care programs (e.g., medical weight loss, HRT, anti-aging, mental health). - **Scaling partnerships**: Serving a growing range of organizations from digital health startups to large employers and health systems. - **National reach**: Deepening 50-state coverage and payer relationships to enable truly national virtual care delivery. ## Why Work Here - **Culture & Mission**: Driven by a mission to “bring healing anywhere,” with a strong focus on expanding healthcare access. The team is described as passionate, energetic, and focused on driving long-lasting results. - **Work Environment**: Hybrid work environment with a pet-friendly office in Des Moines, Iowa. The company is deeply committed to its Iowa roots and building a skilled local workforce. - **Benefits**: Competitive salary, generous PTO, medical/dental/vision insurance, and a 401k program. - **Growth & Impact**: Employees report feeling empowered to make a lasting impact on virtual care delivery. The company saw explosive 700% YoY growth in 2024, indicating a dynamic and scaling environment. - **Leadership**: Experienced executive team including a CEO/co-founder with a personal connection to healthcare access challenges, a COO/co-founder, a CMO, CFO, CCO, CPO, and General Counsel. - **Caution**: The careers page explicitly warns of fraudulent job postings and fake recruiter outreach. Candidates should verify any role or offer by emailing fraud@openloophealth.com. ## Sources 1. [openloophealth.com](https://openloophealth.com/) 2. [openloophealth.com/careers](https://openloophealth.com/careers) 3. [openloophealth.com/team](https://openloophealth.com/team) 4. [openloophealth.com/blog/who-is-openloop-health](https://openloophealth.com/blog/who-is-openloop-health) 5. [linkedin.com/company/openloophealth](https://www.linkedin.com/company/openloophealth) ## Other roles at OpenLoop Health - [Senior Strategic Account Executive, Health Systems](https://feeny.ai/job/senior-strategic-account-executive-health-systems-openloop-health-united-states-3y40f49v3agc) — United States - [Manager, Internal Audit](https://feeny.ai/job/manager-internal-audit-openloop-health-united-states-g8hznwj5dxwf) — United States - [Sr. Staff IAM Architect](https://feeny.ai/job/sr-staff-iam-architect-openloop-health-united-states-q3bd1t5gda6y) — United States - [Sr. Director, Procurement](https://feeny.ai/job/sr-director-procurement-openloop-health-united-states-cqspczhjhthb) — United States - [Sr. Staff People Partner](https://feeny.ai/job/sr-staff-people-partner-openloop-health-united-states-70fm30ry72bv) — United States - [Director, Applications & Business Systems](https://feeny.ai/job/director-applications-business-systems-openloop-health-united-states-gftxseds5b97) — United States - [Manager, Enrollment](https://feeny.ai/job/manager-enrollment-openloop-health-united-states-t86a5fnsxr82) — United States - [AI Automation Analyst](https://feeny.ai/job/ai-automation-analyst-openloop-health-peru-d4491cs5b74e) — Peru - [Senior Implementation Manager](https://feeny.ai/job/senior-implementation-manager-openloop-health-united-states-5eb412verw9y) — United States - [Implementation Manager](https://feeny.ai/job/implementation-manager-openloop-health-united-states-hq9hek6n523g) — United States