Senior Incident Response Analyst
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
OpenLoop’s mission is to bring care anywhere by powering telehealth solutions at scale. Our Security Operations team protects the clinical and operational systems that OpenLoop and our partners run patient care on. As a Senior Incident Response Analyst, you’ll be a dedicated responder on our DFIR function — owning incidents end to end, deepening our forensic capability, and ensuring containment happens fast when PHI and clinical operations are on the line.
What You’ll Do
Own tier-1 and tier-2 incidents end to end: detection validation, triage, scoping, containment, eradication, recovery, and post-incident review.
Run host, memory, network, cloud, and identity forensic investigations independently, with evidence handling that holds up to legal, regulatory, and client scrutiny.
Investigate from EDR and SIEM telemetry — write and refine queries, build correlation logic, and reconstruct incident timelines from log data.
Share the IR on-call rotation with the Lead Incident Responder and Senior Staff Security Analyst, and exercise named containment authority (host isolation, session revocation) within a defined threshold.
Author and rewrite IR playbooks based on incidents you personally work, and run post-incident reviews with findings tracked to closure.
Automate or AI-assist repetitive triage and evidence-collection steps so the team’s time goes to investigation rather than toil.
Write for two audiences — a defensible technical timeline and an executive summary of the same incident.
Who You Are
You’re a hands-on responder who has led real incidents under real ambiguity, and you’re straight about what you got wrong. We hire for the discipline, not the tool SKU or the credential: no specific degree is required, and strong responders from Defender, SentinelOne, Splunk, or Sentinel environments are fully in scope. This is an individual contributor role.
Required Qualifications
6–8 years of hands-on security experience, with the majority in incident response and/or digital forensics.
Demonstrated ownership of the full incident lifecycle, from detection validation through post-incident review.
Digital forensics breadth across host/disk, memory, network, cloud, and identity — from real casework, not coursework.
Working depth in EDR/EPP: investigating from endpoint telemetry, running response actions, and tuning what the tool surfaces.
Working depth in SIEM: query authoring, correlation logic, and timeline reconstruction from log data.
Hands-on fluency with a forensic toolchain (e.g., Velociraptor, KAPE, Volatility, Autopsy/EnCase/FTK/X-Ways, plaso, Zeek, Wireshark).
Evidence handling discipline — chain of custody, sound acquisition, and documentation that survives legal, regulatory, and client scrutiny.
MITRE ATT&CK fluency applied to real investigations.
Scripting for investigation and automation (Python, PowerShell, or similar).
Demonstrated, hands-on use of AI tools (Claude, ChatGPT, Copilot, or equivalent) in security work, with specific examples of their impact on speed or quality — and sound judgment about AI and sensitive data (PHI, credentials, telemetry).
Clear incident writing: able to produce both a technical timeline and an executive summary of the same incident.
Willingness to participate in a shared IR on-call rotation.
Preferred Qualifications
CrowdStrike Falcon EDR — hands-on investigation and response in the console.
CrowdStrike Falcon Next-Gen SIEM — CQL query authoring, correlation rules, and dashboards.
CrowdStrike Falcon Shield — SaaS app, identity, and third-party integration risk.
Cloud incident response in AWS (CloudTrail, GuardDuty, IAM abuse patterns).
Identity-centric investigation, particularly Okta (session hijacking, MFA fatigue, token theft, SSO abuse).
Healthcare, fintech, or other regulated-industry experience with sensitive data.
HIPAA, HITRUST, or SOC 2 from the operator side, including breach determination workflow.
GCFA, GCFE, GCIH, GNFA, GCIA, GREM, or equivalent demonstrated expertise.
Malware triage and reverse engineering fundamentals.
SOAR / automation platform experience, or AI-assisted IR workflows built on LLM APIs.
Multi-entity or M&A environment experience — we operate across several subsidiaries.
Open-source contributions to DFIR or security tooling; CTF history, conference talks, or other community engagement.
Experience maturing an IR program from a lower baseline.
Threat intelligence consumption applied to active investigations.
What Success Looks Like
In your first 6 months: fully onboarded and taking primary responder duty on a defined rotation, independently owning tier-1 and tier-2 incidents without escalation for routine cases.
Forensic capability is genuinely two-deep — you can run a host, memory, cloud, or identity investigation without the Lead Incident Responder in the room.
At least three IR playbooks rewritten or newly authored from incidents you worked, with post-incident reviews running on a consistent cadence and findings tracked to closure.
In your first 12 months: measurable reduction in MTTD and MTTR against baseline, with repetitive triage and evidence collection automated or AI-assisted rather than manual.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
Technical Program Manager - Infrastructure Delivery
Lightning AI
United StatesSenior Product Manager, Core Product Portfolio (Agentic Marketing Platform)
Hightouch
United StatesElectrical Field Engineer
Crusoe
United StatesSenior Technical Program Manager at Pencil
Pencil
United StatesMore Openings at OpenLoop Health
Explore Top Companies in this Space
SteadyMD
HealthTech / Telehealth / B2B Healthcare
Blueberry Pediatrics
Telehealth / Healthcare Services / SaaS / Digital Health
Heartbeat Health
Healthcare / Telehealth / Digital Health / Specialty Care
AnswersNow
Healthcare / Telehealth / Autism Therapy / Digital Health
OpenLoop Health
View Company ProfileOpenLoop Health (operating at openloophealth.com) is a digital health infrastructure provider engineered for powering virtual care delivery. Founded in 2020 by Jon Lensing and Christian Williams and headquartered in Des Moines, Iowa, OpenLoop Health delivers smarter, faster care using AI to streamline clinical workflows, enhance patient support and guide optimized care pathways. Under the hood, the platform leverages AI to handle everything from provider staffing and licensing to care coordination and patient engagement. This allows healthcare organizations and employers to expand access to quality care for patients in all 50 states. Backed by Techstars.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.