About The Position

OpenLoop's mission is to bring care anywhere by powering telehealth solutions at scale. The Security Governance, Risk, and Compliance (GRC) team builds the guardrails that let OpenLoop move fast while managing risk — enterprise risk management, security compliance, third-party risk, business resilience, and AI governance. We are hiring a Sr. Staff Risk Management Analyst to own enterprise risk management, which exists today as an assigned responsibility with no dedicated owner. You will mature and operate the enterprise risk program so it becomes something the business runs on. The role also governs the security program portfolio and the security organization’s OKRs. You will own the security awareness program and the company’s insurance responsibilities. You will report directly to the VP, Security Governance, Risk, and Compliance. OpenLoop is a private, pre-IPO telehealth company handling protected health information. The role advises and supports the first line on cyber compliance audits and the continuing build-out of the GRC program.

Requirements

  • 10+ years in information security, risk management, or GRC.
  • Demonstrated ownership of a governance, risk, and compliance program or an enterprise risk program, including registers, policy, and assessment methodology.
  • Experience maintaining a multi-year risk-reduction roadmap and reporting progress against it.
  • Hands-on risk and control self-assessment (RCSA) work or a comparable enterprise risk assessment methodology you have run yourself.
  • Experience authoring and presenting risk reports to executives and a board or equivalent governing body.
  • A record of holding owners across other teams to commitments without direct authority over them.
  • Program experience against SOC 2, HITRUST, HIPAA, NIST CSF, or a comparable control framework.
  • Experience as the first person dedicated full time to a function, operating without a team of your own or a dedicated budget line.

Nice To Haves

  • CRISC, CISA, CISSP, or equivalent certification.
  • Healthcare work involving sensitive data.
  • Agentic AI systems you have built that automate governance intake, evidence gathering, or reporting.
  • Direct support for SOC 2, HITRUST, or HIPAA assurance cycles.
  • Development of a security awareness program from scratch.
  • Ownership or administration of a GRC platform.

Responsibilities

  • Own and deepen the enterprise risk register as an enterprise-wide view of risk, separate from the cyber risk register.
  • Sharpen the enterprise risk appetite statement and put it to work in business decisions across the company.
  • Operate and scale the ERM policy and enterprise risk assessment methodology. Run assessments across the business and hold named risk owners accountable.
  • Report enterprise risk posture to executives and the Enterprise Risk Committee (ERC).
  • Produce the risk-assessment and governance evidence required across OpenLoop’s control framework portfolio, including SOC 2, HITRUST, HIPAA, and NIST CSF 2.0 as the set grows.
  • Set the reporting cadence for the security program portfolio, including commitments, critical dependencies, and priority initiatives, and use it to identify delivery risks before commitments slip.
  • Maintain the multi-year view of the security program’s risk-reduction roadmap and report progress against it.
  • Own the security organization’s OKRs from definition through measurement and reporting.
  • Track critical dependencies and drive priority initiatives through to completion.
  • Own the security awareness program.
  • Manage property and casualty renewals, handle claims and certificates of insurance, coordinate carrier audits, and address insurance requirements in customer contracts.
  • Extend second-line risk coverage into areas of the business that have not had it, including pharmacy, financial, and clinical risk, in partnership with the domain owners.
  • Work with the third-party risk and resilience owner so vendor and concentration risks reach the enterprise risk register.
  • Automate recurring work across register maintenance, assessment intake, evidence gathering, and reporting.
  • Other duties as assigned.

Benefits

  • Medical, Dental, and Vision plans
  • Flexible Spending/Health Savings Accounts
  • Flexible PTO
  • 401(k) + Company Match
  • Life Insurance, Pet insurance, and more
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service