Cloud Security Engineer

Socket.dev

Philadelphia (Philadelphia County)

On-site

USD 110,000 - 150,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
Health insurance
Retirement plan
Profit sharing
Mentorship program
Comprehensive onboarding

Job summary

TherapyNotes LLC seeks an experienced Cloud Security Engineer to secure cloud infrastructure, containerized workloads, and IaC pipelines. The role emphasizes Azure, Kubernetes (AKS), CSPM, and Zero Trust within a HIPAA-regulated environment, contributing to incident response and governance.

Responsibilities include CSPM remediation, IAM management in Entra ID, and securing CI/CD with IaC tooling. Join a small security team driving robust cloud security operations.

Qualifications

  • Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered.
  • 5+ years of experience in cloud security engineering or related role.
  • Deep experience securing cloud infrastructure and cloud-based applications (Azure preferred, AWS a plus).
  • Hands-on network security and firewall controls knowledge.
  • Experience with containerized workloads and Kubernetes environments (AKS).
  • Experience with CSPM and remediating misconfigurations.
  • Experience with IaC orchestration platforms (Terraform/OpenTofu).
  • Experience with Microsoft Entra ID and JIT privileged access models.
  • Experience with Zero Trust / SASE tooling and security frameworks (NIST, ISO 27001, CIS).
  • Certifications such as CISSP/SSCP/Security+ or cloud security certs preferred.

Responsibilities

  • Manage and secure cloud infrastructure and cloud-based applications, focusing on Azure.
  • Secure containerized workloads and Kubernetes environments and perform image scanning.
  • Own CSPM process and remediate misconfigurations across cloud environments.
  • Secure IaC orchestration platforms with access control and secrets management.
  • Manage identities in Entra ID with Conditional Access and entitlement management.
  • Review network diagrams and connectivity changes for secure segmentation.
  • Administer Zero Trust network access and edge security tooling.
  • Oversee SIEM, DLP, E/XDR, and vulnerability management.
  • Monitor alerts, respond to incidents, and participate in on-call rotation.
  • Conduct threat analysis and risk evaluations; document findings for leadership.

Skills

Cloud security engineering
Kubernetes
Azure
Threat modeling
IAM
CSPM
Terraform
OpenTofu
Zero Trust
Incident response

Education

Bachelor's degree in information security or related field

Tools

AKS
Argo
Flux
Terraform
OpenTofu

Job description

About Us

TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.

We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!

The Position

TherapyNotes is seeking an experienced, hands-on Cloud Security Engineer to secure our cloud infrastructure, containerized workloads, and infrastructure-as-code pipelines. The right candidate brings deep expertise in cloud security posture management, Kubernetes and container security, and Zero Trust network access, and is comfortable working in a healthcare-regulated environment (HIPAA, HITRUST, HITECH). This role also contributes to broader security engineering efforts — vulnerability management, incident response, and identity and access security — as part of a small, collaborative security team.

Required Skills and Experience
  • Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered.
  • 5+ years of experience in cloud security engineering or related role.
  • Deep, hands-on experience securing cloud infrastructure and cloud-based applications (Azure preferred, AWS a plus).
  • Hands-on network security experience and a strong understanding of network architecture, connectivity, segmentation, and firewall controls.
  • Experience securing containerized workloads and Kubernetes environments (e.g., AKS) — network policy, workload identity, runtime protection.
  • Experience with cloud security posture management (CSPM) and remediating misconfigurations across cloud environments.
  • Experience securing IaC orchestration platforms — access control, secrets management, and deployment approval workflows (e.g., Terraform, OpenTofu).
  • Experience with Microsoft Entra ID, including Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access models.
  • Experience with Zero Trust / SASE tooling (e.g., Cloudflare Zero Trust, WAF, Gateway, or equivalent).
  • Knowledge of security frameworks (NIST, ISO 27001, CIS) and compliance frameworks (HITRUST, PCI DSS).
  • Proven ability to conduct security assessments, vulnerability management, and incident response.
  • Strong understanding of OS platforms (Windows, Linux) and endpoint security.
  • Industry certifications such as CISSP, SSCP, Security+, or a cloud security certification (Azure/AWS) preferred.
Responsibilities
  • Manage and secure cloud infrastructure and cloud-based applications, with a focus on Azure.
  • Secure containerized workloads and Kubernetes environments (e.g., AKS) — network policy, workload identity, runtime protection, and container image scanning.
  • Own and mature cloud security posture management (CSPM) — continuously identify and remediate misconfigurations across cloud environments.
  • Secure infrastructure-as-code orchestration platforms — access control, secrets management, and deployment approval workflows for Terraform/OpenTofu pipelines.
  • Manage and secure identities in Microsoft Entra ID through Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access models.
  • Review network diagrams and proposed connectivity changes, provide security input on segmentation and sensitive data flows, and work with IT and SRE teams to address identified concerns.
  • Administer Zero Trust network access and edge security tooling to secure access to corporate and cloud resources.
  • Hands-on management of broader security solutions across the organization: SIEM, DLP, E/XDR, vulnerability management.
  • Monitor security alerts, respond to and **es**calate incidents, and participate in the incident response on-call rotation.
  • Conduct threat analysis, vulnerability assessments, and risk evaluations; document findings, manage mitigation, and report status to leadership.
  • Develop queries, scripts, integrations, and automated workflows that improve cloud security operations.
  • Collaborate with development teams to ensure security is continuously integrated into the SDLC and CI/CD pipeline.
  • Conduct periodic cloud configuration and access reviews to ensure compliance with security standards.
  • Participate in audits and assessments, supporting governance, risk management, and compliance (GRC) efforts.
Additional Skills
  • Familiarity with GitOps tooling (Argo, Flux) for secure deployment in Kubernetes environments.
  • Network or Systems Engineering background a huge plus.
  • Familiarity with programming/scripting languages a plus.
  • Passion for continuous learning and professional development, with a commitment to staying updated and trained on the latest trends and technologies.
  • Eagerness to engage in new challenges and adapt quickly.
  • Strong work ethic and drive to take ownership of projects and see them through to completion.
  • Strong collaboration skills, able to work effectively with cross functional teams.
Benefits
  • Competitive salary - $110,000-$150,000
  • Employer sponsored health, dental, vision, life, and disability insurance
  • Retirement plan with company contribution
  • Annual company profit sharing
  • Personal development/training budget
  • Open, collaborative work environment
  • Extensive 2-week onboarding plan
  • Comprehensive mentorship program
Equal Opportunity Employer Statement & Applicant Rights

TherapyNotes LLC is an Equal Opportunity Employer and does not discriminate based on race, color, religion, sex, national origin, age, disability, genetic information, or any other protected status under federal, state, or local law. We are committed to providing a workplace free of discrimination and harassment.For more information about your rights under federal employment laws, please review the following:

  • Know Your Rights: Workplace Discrimination is Illegal
  • Family and Medical Leave Act (FMLA): Employee Rights Under FMLA

If you require a reasonable accommodation during the application process, please contact humanresources@therapynotes.com.

9/2/2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

TherapyNotes.com • Pennsylvania

On-site
USD 110,000 - 150,000
Health, dental, vision, life, and STD
401(k) with company contributions
Profit sharing
+2
Cyber Security Engineer (Application Security)
Cyber Security Engineer (Application Security)

TherapyNotes.com • Pennsylvania

On-site
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+8
Cyber Security Engineer (Application Security)
Cyber Security Engineer (Application Security)

Socket.dev • Philadelphia

On-site
USD 110,000 - 150,000
Competitive salary
Health, dental, vision, life, and disa
Retirement plan
+3
Cloud Systems Engineer
Cloud Systems Engineer

TherapyNotes, LLC • United States

On-site
USD 100,000 - 120,000
Employer sponsored health insurance
Dental insurance
Vision insurance
+7
Senior Cyber Security Engineer
Senior Cyber Security Engineer

SCAN • Long Beach (CA)

On-site
USD 106,000 - 183,000
Annual bonus
Wellness program
PTO
+3
Sr. Cloud Security Engineer
Sr. Cloud Security Engineer

LHH • San Francisco (CA)

Hybrid
USD 180,000 - 250,000
Medical, dental, and vision insurance
401(k) plan with match
19 days of PTO + 11 paid holidays
+1
Staff Security Engineer
Staff Security Engineer

Grow Therapy • New York (NY)

Hybrid
USD 150,000 - 210,000
Comprehensive health coverage
Access to therapy through our platform
Retirement savings and equity
+7
Staff Cloud Security Engineer
Staff Cloud Security Engineer

Included Health, Inc. • Northern (KY)

Hybrid
USD 190,000 - 280,000
Remote‑first culture
401(k) savings plan
DevSecOps Service Engineer
DevSecOps Service Engineer

CloudFit Software • Lynchburg (VA)

On-site
USD 44,000 - 100,000
Medical, dental, vision insurance
401(k), HSA, FSAs
3 Weeks of PTO, Paid Company Holidays
+2
Senior Security Engineer - Application Security
Senior Security Engineer - Application Security

K Health • New York (NY)

On-site
USD 150,000 - 185,000
Hybrid work schedule
18 vacation days
Stock options
+2