About OpenLoop
OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian
Williams, with the vision to bring healing anywhere. Our tele-health support
solutions are thoughtfully designed to streamline and simplify go-to-market care
delivery for companies offering meaningful virtual support to patients across an
expansive array of specialties, in all 50 states.
Our Company Culture
We have a relatively flat organizational structure
here at OpenLoop. Everyone is encouraged to bring ideas to the table and make
things happen. This fits in well with our core values of Autonomy, Competence
and Belonging, as we want everyone to feel empowered and supported to do their
best work.
Cyber
Intelligence & Insider Threat Manager
About The Role
OpenLoop is looking for
a strategic, hands-on Cyber Intelligence & Insider Threat
Manager to join our team (remote or Des Moines, IA). This role leads
our intelligence and insider threat programs, ensuring we can detect, respond
to, and reduce risks across employees, contractors, vendors, and partners. You
will oversee efforts to identify harmful or high-risk behavior, manage
cybersecurity threat intelligence, and help protect the business and brand. The
position also builds and maintains key relationships with intelligence-sharing
groups, law enforcement, government agencies, and industry peers.
This leadership role
works across the business—including, but not limited to HR, data owners, legal,
physical security, SOC/CSIRT, software development, and IT. Its role focuses on
developing a comprehensive IT Security & SecOps roadmap to protect our
platform, data, systems, and clients, while ensuring compliance with HIPAA,
HITRUST, and other healthcare regulations.
What You’ll Do:
- Lead and manage the cyber intelligence and
insider threat program, ensuring 24/7 security monitoring, incident detection,
response, and escalation processes (in coordination with
SecOps/SOC/MSSP).
- Develop and execute the insider threat strategy,
policies, and response playbooks.
- Lead insider threat response, including investigation,
containment, remediation, and root cause analysis.
- Develop and execute a
cyber intelligence program to deliver an intelligence-driven and
risk-prioritized security program (awareness/technologies/controls) and
identification of key risks to the business.
- Collaborate with external threat
intelligence sources, law enforcement, and government/industry organizations
(e.g., H-ISAC) to stay updated on evolving threats, vulnerabilities, and TTPs
(tactics, techniques, and procedures).
- Centralize multiple threat sources
(premium, industry-shared, open-source, dark web), correlate indicators and
threats, and distill actionable intelligence, outlining severity, urgency and
impact, and ensure they can be understood by both management and technical
teams.
- Actively inform and engage in security projects across the business to
disrupt active or potential threats.
- Maintain an up-to-date level of knowledge
related to security threats, vulnerabilities and mitigations to reduce attack
surface.
- Develop metrics and scorecards to measure risk to the organization, as
well as effectiveness and efficiency of threat analysis and
response.
- Ensure regulatory compliance (e.g., PCI, HIPAA, HITRUST, NIST CSF)
through effective security operations controls and processes.
- Other duties as
assigned.
Who You
Are:
- Bachelor's degree in Information Security, Computer
Science, Information Technology, or a related field is preferred.
- 8+ years of
experience in Information Security, with at least 5 years focused on Cyber
Intelligence and Insider Threat.
- Applicable knowledge of adversary tactics, techniques
and procedures (TTPs), MITRE ATT&ACK framework, CVSS, open source
intelligence (OSINT) and deception techniques.
- Demonstrated ability to
investigate, handle and track incidents.
- Experience in healthcare or digital health
is a plus / Experience in government cyber intelligence is a
plus.
- Deep expertise in security operations, cyber intelligence, threat
detection, incident response, and insider threat.
- Strong understanding of
cyber threat landscape, attack vectors, security technologies, and defensive
tactics.
- Familiarity with regulatory frameworks (HIPAA, HITRUST, NIST
CSF).
- Excellent leadership and communication skills with the ability to engage
technical and non-technical stakeholders, including senior executives and the
board.
- Excellent organizational and documentation skills.
- Ability to effectively
collaborate and communicate with business partners, customers, third parties,
and regulatory agencies.
- Analytical and problem-solving abilities with a
proactive, risk-based approach.
- Strategic thinking and the ability to align security
risks and initiatives with business objectives.
- Detail-oriented with a
strong focus on operational excellence and regulatory compliance.
- Strong customer
service orientation.
- Adaptability to handle dynamic and challenging
environments.
- Energetic, resourceful, and appropriate work intensity to get the work
done.
- Strong people acumen and relationship skills
Our Benefits
In addition, for salaried positions you would also
be eligible for:
- Medical, Dental, and Vision
plans
- Flexible Spending/Health Savings
Accounts
- Flexible PTO
- 401(k) +
Company Match
- Life Insurance, Pet insurance, and
more
Sound like a
good fit? We’d love to meet you.