Base Career helps you apply smarter for this job.
Key skills for this role
OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Our Security Operations team protects the clinical and operational systems that OpenLoop and our partners run patient care on. As a Senior Incident Response Analyst, you’ll be a dedicated responder on our DFIR function — owning incidents end to end, deepening our forensic capability, and making sure containment happens fast when PHI and clinical operations are on the line.
OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.
OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Our Security Operations team protects the clinical and operational systems that OpenLoop and our partners run patient care on. As a Senior Incident Response Analyst, you’ll be a dedicated responder on our DFIR function — owning incidents end to end, deepening our forensic capability, and making sure containment happens fast when PHI and clinical operations are on the line.
Own tier-1 and tier-2 incidents end to end: detection validation, triage, scoping, containment, eradication, recovery, and post-incident review.
Run host, memory, network, cloud, and identity forensic investigations independently, with evidence handling that holds up to legal, regulatory, and client scrutiny.
Investigate from EDR and SIEM telemetry — write and refine queries, build correlation logic, and reconstruct incident timelines from log data.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, USA
, USA
, USA
, USA
, USA
, USA
, USA
, USA
Share the IR on-call rotation with the Lead Incident Responder and Senior Staff Security Analyst, and exercise named containment authority (host isolation, session revocation) within a defined threshold.
Author and rewrite IR playbooks based on incidents you personally work, and run post-incident reviews with findings tracked to closure.
Automate or AI-assist repetitive triage and evidence-collection steps so the team’s time goes to investigation rather than toil.
Write for two audiences — a defensible technical timeline and an executive summary of the same incident.
You’re a hands-on responder who has led real incidents under real ambiguity, and you’re straight about what you got wrong. We hire for the discipline, not the tool SKU or the credential: no specific degree is required, and strong responders from Defender, SentinelOne, Splunk, or Sentinel environments are fully in scope. This is an individual contributor role.
In your first 6 months: fully onboarded and taking primary responder duty on a defined rotation, independently owning tier-1 and tier-2 incidents without escalation for routine cases.
Forensic capability is genuinely two-deep — you can run a host, memory, cloud, or identity investigation without the Lead Incident Responder in the room.
At least three IR playbooks rewritten or newly authored from incidents you worked, with post-incident reviews running on a consistent cadence and findings tracked to closure.
In your first 12 months: measurable reduction in MTTD and MTTR against baseline, with repetitive triage and evidence collection automated or AI-assisted rather than manual.
We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.
Sound like a good fit? We’d love to meet you.
Privately held white-label telehealth infrastructure provider helping healthcare organizations launch and operate virtual care programs.
Visit company websiteJobs and hiring trendsFull-time
Senior · 6+ years experience
Remote
Apply faster on company sites with our extension.