SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
OpenLoop is a telehealth platform that powers virtual care delivery solutions across all 50 states. As Sr Staff Security Engineer, you will be the most senior technical authority on security architecture, responsible for defining how security is designed into every system supporting virtual care delivery.
You will own and continuously evolve OpenLoop's security architecture across cloud infrastructure, applications, and corporate systems—defining standards, patterns, and reference architectures that engineering teams build against. Key responsibilities include leading threat modeling across product and infrastructure initiatives with particular attention to PHI data flows and patient-facing interfaces; conducting architecture reviews for new and existing systems; designing and improving the architecture review process to scale with engineering velocity; and partnering with the CTO to embed security review within technical governance.
You will define application security standards including secure design principles, API security, authentication/authorization patterns (OAuth/OIDC, SAML), and healthcare interoperability standards (HL7, FHIR). You'll establish and maintain zero trust architecture strategy across identity, network, endpoint, and data layers; architect key management and secrets management practices; and own security architecture for third-party integrations.
As a primary security partner for product and engineering leaders, you'll be embedded in design cycles to shape secure-by-default systems. You'll maintain security architecture documentation including ADRs and reference designs, translate GRC and compliance requirements into concrete architectural controls with deep expertise in HIPAA Security Rule technical safeguards, and mentor the broader security team. You'll also research emerging threats targeting healthcare to keep the organization ahead of the threat landscape.
Required: Bachelor's in Computer Science, Information Security, or equivalent; 10+ years progressive security experience with 5+ years focused on security architecture in enterprise and cloud environments; deep expertise across application security, cloud security, IAM, network security, and data protection; hands-on cloud architecture experience; proven threat modeling leadership using structured methodologies; strong SSDLC and OWASP knowledge; and proficiency in modern authentication/authorization patterns.