Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
OpenLoop

Staff Security Engineer

OpenLoop

. Own engineering of security controls for OpenLoop’s macOS and Windows fleet, including MDM, disk encryption, patch compliance, and local admin controls .

Posted 10/7/2026full-timeRemote • United StatesLeadWebsite

Tech Stack

Tools & technologies
CloudDNSJamfMacOSPython

About the role

Key responsibilities & impact
  • Own engineering of security controls for OpenLoop’s macOS and Windows fleet, including MDM, disk encryption, patch compliance, and local admin controls
  • Engineer MDM and MAM policies protecting company and PHI data on managed devices and BYOD
  • Deploy and manage an enterprise browser securing SaaS and web access through data controls, session policies, and extension management
  • Build, apply, and continuously measure CIS Benchmark baselines across the fleet
  • Track configuration drift, manage documented exceptions, and produce fleet-level evidence for HITRUST and SOC 2 auditors
  • Drive application control and least privilege on endpoints
  • Own Google Workspace email security, including SPF, DKIM, DMARC, phishing and BEC defenses, attachment and link protection, and PHI data loss prevention
  • Tune security controls to reduce risk and false positives and partner with SecOps on phishing triage workflows
  • Write security standards, configuration baselines, and runbooks
  • Implement and validate controls identified through threat modeling and security reviews
  • Map controls to HITRUST and SOC 2 requirements and own audit evidence
  • Automate repetitive work through scripting
  • Mentor SAE and adjacent-team engineers and serve as an incident escalation point
  • Partner with IT, Engineering, Compliance, and SecOps to translate security risk into business and operational terms
  • Perform other duties as assigned

Requirements

What you’ll need
  • 8+ years in security engineering, with a track record of owning outcomes end to end
  • Deep, hands-on expertise in endpoint security and email security
  • Experience deploying and operating MDM/MAM platforms (Kandji, Jamf, Intune, or similar) and email security platforms
  • Experience deploying and managing an enterprise browser platform
  • Hands-on experience implementing CIS Benchmarks and measuring compliance against them at fleet scale
  • Exposure to network security: secure remote access (ZTNA/VPN), DNS filtering, segmentation, or firewall policy
  • Working knowledge of cloud security fundamentals, including IAM, network controls, logging, and workforce access to cloud environments
  • Exposure to DevSecOps practices, including infrastructure as code, CI/CD security, secrets management, or security tooling in pipelines
  • Scripting ability in Python, Bash, PowerShell, or similar
  • Experience working in a regulated environment (HIPAA, HITRUST, SOC 2, PCI, or similar) and producing audit evidence
  • Clear written communication; ability to write standards, defend decisions, and explain risks to non-security executives
  • Relevant certifications such as GIAC, CISSP, OSCP, or cloud security certifications are preferred, not required
  • Must answer whether visa sponsorship is required now or in the future

Benefits

Comp & perks
  • Medical, Dental & Vision
  • Flexible Spending / Health Savings Accounts
  • Generous PTO
  • Hybrid-work flexibility
  • 401(k) with Company Match
  • Life Insurance
  • Pet Insurance
  • Competitive compensation