SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
OpenLoop is a telehealth platform that powers virtual care delivery across all 50 US states. The Security Operations team protects clinical and operational systems handling patient care at scale.
As a Senior Incident Response Analyst, you will own the full incident lifecycle for tier-1 and tier-2 security incidents. You'll conduct independent digital forensics investigations across host, memory, network, cloud, and identity systems. Your responsibilities include detection validation, triage, scoping, containment, eradication, recovery, and post-incident review. You'll investigate from EDR and SIEM telemetry, writing and refining queries to reconstruct incident timelines. You'll share on-call rotation duties and exercise named containment authority (host isolation, session revocation) within defined thresholds.
You'll author and rewrite incident response playbooks based on real incidents you work, run post-incident reviews with tracked findings, and automate repetitive triage and evidence-collection steps. You'll produce both defensible technical timelines and executive summaries for stakeholders.
This is a hands-on individual contributor role requiring 6–8 years of hands-on security experience, with the majority in incident response and/or digital forensics. You need demonstrated ownership of the full incident lifecycle, digital forensics breadth across multiple domains, working depth in EDR/EPP and SIEM platforms, fluency with forensic toolchains (Velociraptor, KAPE, Volatility, Autopsy, etc.), evidence handling discipline, MITRE ATT&CK fluency, scripting capability (Python, PowerShell), and demonstrated hands-on use of AI tools in security work with sound judgment about sensitive data. Clear incident writing ability and willingness to participate in shared IR on-call rotation are essential.
Preferred qualifications include CrowdStrike Falcon experience, AWS cloud incident response, identity-centric investigation (Okta), healthcare/regulated-industry experience, HIPAA/HITRUST/SOC 2 knowledge, GIAC certifications, malware triage skills, SOAR/automation platform experience, and community engagement in DFIR.