SlipstreamJobsFresh Startup & VC-Backed Jobs

Sr. Staff Risk Management Analyst

OpenLoop - Remote - Remote - posted 2026-08-26

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

OpenLoop is a pre-IPO telehealth company delivering virtual care solutions across all 50 states. The Security Governance, Risk, and Compliance (GRC) team is seeking a Sr. Staff Risk Management Analyst to own enterprise risk management—a function currently without dedicated leadership. You will mature and operate the enterprise risk program as a core business capability, reporting directly to the VP of Security Governance, Risk, and Compliance. This is a high-impact individual contributor role with company-wide scope and influence across multiple business functions. Key responsibilities include: - Building and deepening the enterprise risk register as a distinct view from cyber risk, with named owners and accountability across the organization - Developing and operationalizing the enterprise risk appetite statement and assessment methodology - Running enterprise-wide risk assessments and reporting risk posture to executives and the Enterprise Risk Committee - Producing governance evidence for SOC 2, HITRUST, HIPAA, and NIST CSF 2.0 compliance frameworks - Setting reporting cadence for the security program portfolio and identifying delivery risks early - Owning the security organization's OKRs from definition through measurement - Managing the security awareness program end-to-end - Handling property and casualty insurance renewals, claims, and carrier audits - Extending risk coverage into pharmacy, financial, and clinical domains - Automating recurring governance, assessment, and reporting workflows You bring 10+ years in information security, risk management, or GRC with demonstrated ownership of governance, risk, and compliance programs. You have built programs from scratch (not inherited finished ones), authored risk reports for executives and boards, and held cross-functional teams accountable without direct authority. You are comfortable operating independently, automating repetitive processes, and expanding scope as the business grows. Healthcare experience with sensitive data and familiarity with GRC platforms are valued. Certifications such as CRISC, CISA, or CISSP are preferred.

Similar roles