About OpenLoop OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states. About the Role OpenLoop's mission is to bring care anywhere by powering telehealth solutions at scale. The Security Governance, Risk, and Compliance (GRC) team builds the guardrails that let OpenLoop move fast while managing risk — enterprise risk management, security compliance, third-party risk, business resilience, and AI governance. We are hiring a Sr. Staff Risk Management Analyst to own enterprise risk management, which exists today as an assigned responsibility with no dedicated owner. You will mature and operate the enterprise risk program so it becomes something the business runs on. The role also governs the security program portfolio and the security organization’s OKRs. You will own the security awareness program and the company’s insurance responsibilities. You will report directly to the VP, Security Governance, Risk, and Compliance. OpenLoop is a private, pre-IPO telehealth company handling protected health information. The role advises and supports the first line on cyber compliance audits and the continuing build-out of the GRC program. What You'll Do Own and deepen the enterprise risk register as an enterprise-wide view of risk, separate from the cyber risk register. Sharpen the enterprise risk appetite statement and put it to work in business decisions across the company. Operate and scale the ERM policy and enterprise risk assessment methodology. Run assessments across the business and hold named risk owners accountable. Report enterprise risk posture to executives and the Enterprise Risk Committee (ERC). Produce the risk-assessment and governance evidence required across OpenLoop’s control framework portfolio, including SOC 2, HITRUST, HIPAA, and NIST CSF 2.0 as the set grows. Set the reporting cadence for the security program portfolio, including commitments, critical dependencies, and priority initiatives, and use it to identify delivery risks before commitments slip. Maintain the multi-year view of the security program’s risk-reduction roadmap and report progress against it. Own the security organization’s OKRs from definition through measurement and reporting. Track critical dependencies and drive priority initiatives through to completion. Own the security awareness program. Manage property and casualty renewals, handle claims and certificates of insurance, coordinate carrier audits, and address insurance requirements in customer contracts. Extend second-line risk coverage into areas of the business that have not had it, including pharmacy, financial, and clinical risk, in partnership with the domain owners. Work with the third-party risk and resilience owner so vendor and concentration risks reach the enterprise risk register. Automate recurring work across register maintenance, assessment intake, evidence gathering, and reporting. Other duties as assigned. Who You Are You have built governance, risk, and compliance programs instead of inheriting finished ones, with a range that spans security compliance and governance as well as risk. Leaders have used your work to make real decisions about risks facing the business. You are looking for scope that keeps widening, including accountability for enterprise risk and a broader security portfolio. When a process repeats, you would rather automate it than hire someone to keep it moving. Required Qualifications 10+ years in information security, risk management, or GRC. Demonstrated ownership of a governance, risk, and compliance program or an enterprise risk program, including registers, policy, and assessment methodology. Experience maintaining a multi-year risk-reduction roadmap and reporting progress against it. Hands-on risk and control self-assessment (RCSA) work or a comparable enterprise risk assessment methodology you have run yourself. Experience authoring and presenting risk reports to executives and a board or equivalent governing body. A record of holding owners across other teams to commitments without direct authority over them. Program experience against SOC 2, HITRUST, HIPAA, NIST CSF, or a comparable control framework. Experience as the first person dedicated full time to a function, operating without a team of your own or a dedicated budget line. Preferred Qualifications CRISC, CISA, CISSP, or equivalent certification. Healthcare work involving sensitive data. Agentic AI systems you have built that automate governance intake, evidence gathering, or reporting. Direct support for SOC 2, HITRUST, or HIPAA assurance cycles. Development of a security awareness program from scratch. Ownership or administration of a GRC platform. What Success Looks Like Within 30 days: The current state of enterprise risk is documented, the security program’s commitments and OKRs are current, and audit, GRC, and awareness obligations are mapped to owners and reporting cadences. Within 90 days: The enterprise risk register has named risk owners, the assessment methodology is operating on a defined cadence, and the security portfolio, OKR, and audit support reporting is current. Within 6 months: The risk appetite statement and ERM policy are in active use, the first cycle of enterprise risk assessments is complete, the awareness program is running on a defined cadence, and the first line has the governance and evidence support needed for cyber compliance audits. Within 12 months: Decision records for priority work reference the enterprise risk register and risk appetite, identify who reduced or accepted each risk, and show work moving faster with fewer unresolved risks. Register maintenance, assessment intake, evidence gathering, and reporting are automated. Our Benefits In addition, for salaried positions you would also be eligible for: Medical, Dental, and Vision plans Flexible Spending/Health Savings Accounts Flexible PTO 401(k) + Company Match Life Insurance, Pet insurance, and more Our Company We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work. Sound like a good fit? We’d love to meet you.
ICAM Program Analyst - Program Management Operations/PMO
Gdit
Analyst, Case Management, Field
Cvshealth
Analyst, Case Management – Transition of Care (Care Coordinator)
Cvshealth
ICAM Program Analyst - Program Management Operations/PMO
Gdit
Product Analyst – Customer Solutions – Revenue Growth Management
Enusapply Danone
IT Program & Project Management Analyst II
Conduent