OpenLoop logo
OpenLoopPosted 2 weeks ago

Sr. Staff Security Engineer

RemoteUnited States or Canada

Full TimeSenior LevelSmall

Job Summary

Own and evolve OpenLoop's security architecture across cloud infrastructure, applications, and corporate systems by defining standards, patterns, and reference designs that engineering teams build against. Lead threat modeling across product, engineering, and infrastructure initiatives with particular attention to PHI data flows, patient-facing interfaces, and virtual care delivery systems, while coaching engineers to model their own work. Conduct architecture reviews for new and existing systems, evaluating designs against security principles and regulatory requirements to produce actionable recommendations. Design and improve the architecture review process itself to scale with engineering velocity, including self-service patterns and risk-tiered review paths. Partner with the CTO and enterprise architecture function to embed security review within existing technical governance. Define and champion application security standards, including secure design principles, API security, authentication patterns, and healthcare interoperability standards such as HL7 and FHIR. Establish and maintain a zero trust architecture strategy across identity, network, endpoint, and data layers. Architect and govern key management, secrets management, and certificate lifecycle practices across cloud-native environments. Serve as the primary security partner for product and engineering leaders, embedded in design cycles to shape secure-by-default systems. Translate security and compliance requirements from GRC, Privacy, and audit partners into concrete architectural controls, with particular depth in the HIPAA Security Rule's technical safeguards. Mentor the broader security team to raise architectural thinking and design quality across all domains. Research emerging threats and attack techniques targeting healthcare to keep OpenLoop ahead of the threat landscape.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent professional experience
  • 10+ years of progressive security experience, with at least 5 years focused specifically on security architecture across enterprise and cloud environments
  • Deep expertise across multiple security domains: application security, cloud security, identity and access management, network security, and data protection
  • Hands-on experience architecting security solutions in cloud environments, including network security design, IAM, key and secrets management, encryption, and cloud-native security services
  • Proven experience leading threat modeling using structured methodologies (STRIDE, PASTA, or equivalent) at varying scales — from individual features to whole systems — including evaluating others' threat models and training engineers to produce their own
  • Strong command of secure software development lifecycle (SSDLC), OWASP principles, and application security design patterns
  • Proficiency in modern authentication and authorization patterns (OAuth 2.0, OIDC, SAML), including across multi-tenant and patient-facing applications
  • Experience architecting key management, secrets management, and PKI/certificate lifecycle controls in cloud-native environments
  • Working knowledge of HIPAA (including Security Rule technical safeguards), HITRUST CSF, NIST CSF, and SOC 2, sufficient to design controls that satisfy them
  • Demonstrated ability to communicate complex architectural risk to both technical and executive audiences

Desired Qualifications

  • Experience in healthcare, digital health, or another highly regulated industry
  • Experience designing and evaluating zero trust architectures in production
  • Experience designing or scaling an architecture review process — including risk-tiering, self-service patterns, or integration with an existing technical review board
  • Familiarity with API security architecture and healthcare data exchange standards (HL7, FHIR)
  • Familiarity with security architecture frameworks such as SABSA or TOGAF security extensions
  • Experience mentoring senior engineers or establishing architecture practices from scratch

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce