Cyber Security Engineer (Application Security)

TherapyNotes.com

Philadelphia (Philadelphia County)

On-site

USD 110,000 - 150,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Salary up to $150k
Insurance
Retirement plan
Profit sharing
Training budget
Open environment
Onboarding program
Mentorship program

Job summary

TherapyNotes.com is seeking an experienced Cyber Security Engineer to own application security across the SDLC and CI/CD pipeline in a HIPAA-regulated environment. You will secure GitHub Actions, perform SAST/DAST, review IaC (Terraform), and coordinate vulnerability management as part of a small security team.

Requirements include 5+ years in application security, strong knowledge of regulatory requirements (HIPAA/HITRUST/HITECH), and experience with cloud security (Azure/AWS).

Qualifications

  • Bachelor's degree or equivalent experience in information security, CS, or related field.
  • 5+ years in application security or security engineering.
  • Proven experience securing CI/CD pipelines and GitHub Actions, including SAST/DAST and code/secret/dependency scanning.
  • Experience reviewing Terraform or other IaC for security misconfigurations.
  • Working knowledge of SIEM, EDR/XDR, and DLP platforms.
  • Understanding of Zero Trust principles as applied to apps and identity access.
  • Strong knowledge of healthcare regulations (HIPAA, HITECH, HITRUST) and their impact on security.
  • Experience with API security and healthcare data standards (HL7 preferred).
  • Experience securing cloud environments (Azure preferred; AWS a plus).
  • Willingness to participate in on-call incident response.
  • Industry certs (GWAPT, OSWE, GPEN, Azure/AWS cloud cert) are a plus.

Responsibilities

  • Collaborate with developers to integrate security into the SDLC and CI/CD pipeline.
  • Enforce secure coding standards to protect data confidentiality, integrity, and availability.
  • Perform security assessments, code reviews, and threat modeling on applications.
  • Own and operate GitHub Advanced Security, triaging findings and improving coverage and workflows.
  • Secure CI/CD pipelines and GitHub Actions—manage identities, runners, permissions, and secrets.
  • Review IaC for security, partnering with IT for secure deployment practices.
  • Ensure measures align with HIPAA, HITRUST, and HITRUST regulations and support audits.
  • Remediate vulnerabilities with actionable guidance and effective patching.
  • Develop and manage security tooling (SAST, DAST, vulnerability mgmt) to automate testing.
  • Support incident response activities and root-cause analysis.
  • Contribute to security awareness programs for dev teams.

Skills

Application security
CI/CD security
Threat modeling
Incident response
Zero Trust
HIPAA/HITRUST
Cloud security
API security

Education

Bachelor's degree in information security, computer science, or related field

Tools

GitHub Actions
SAST/DAST
Snyk
Terraform
SIEM
EDR/XDR
DLP
Azure
AWS

Job description

About Us

TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.

We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!

The Position

TherapyNotes is seeking an experienced, hands-on Cyber Security Engineer to own application security across our SDLC and CI/CD pipeline. The right candidate brings deep expertise securing CI/CD pipelines, code and dependency scanning workflows, and infrastructure-as-code, and is comfortable working in a healthcare-regulated environment (HIPAA, HITRUST, HITECH). This role also contributes to broader security engineering efforts — vulnerability management, incident response, and identity and access security — as part of a small, collaborative security team.

Required Skills and Experience
  • Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered.
  • 5+ years in application security or security engineering.
  • Demonstrated experience securing CI/CD pipelines and GitHub Actions — including SAST/DAST, code/secret/dependency-scanning triage (e.g., GitHub Advanced Security, Snyk), runner and workflow-permission security, and third-party action/supply-chain risk.
  • Experience reviewing Terraform or other infrastructure-as-code for security misconfigurations.
  • Working knowledge of SIEM, EDR/XDR, and DLP platforms — deployment, tuning, and alert triage.
  • Understanding of Zero Trust architecture principles and how they apply to application and identity access.
  • Strong understanding of healthcare regulations (HIPAA, HITECH, HITRUST) and their impact on application security.
  • Experience with API security, particularly integrations with other healthcare systems; familiarity with HL7 or other healthcare data standards preferred.
  • Prior experience securing cloud environments (Azure preferred, AWS a plus).
  • Willingness to participate in an incident response on-call rotation.
  • Industry certifications such as GWAPT, OSWE, GPEN, or a cloud security certification (Azure/AWS) are ideal; CISSP or HCISPP a plus but not a substitute for hands-on tooling experience.
Application Security Responsibilities
  • Collaborate with developmental teams to ensure security is continuously integrated into the Software Development Lifecycle (SDLC) and CI/CD pipeline.
  • Enforce secure coding standards and best practices to minimize vulnerabilities and to protect the confidentiality, integrity, and availability of our customer's data.
  • Perform in-depth security assessments, code reviews, and threat modeling on applications to identify potential vulnerabilities and risks.
  • Own and operate GitHub Advanced Security — triage code, secret, and dependency-scanning findings, identify recurring vulnerability patterns and recommend broader fixes, and continuously improve scanning coverage, configuration, and workflows.
  • Secure CI/CD pipelines and GitHub Actions — identities, runners, permissions, and secrets — and reduce software supply chain risk through third-party action review, dependency controls, action pinning, and artifact provenance.
  • Review Terraform and other infrastructure-as-code for security issues, partnering with IT platform teams on IaC scanning and secure deployment practices.
  • Ensure application security measures align with healthcare regulations and standards (e.g., HIPAA, HITRUST, and HITECH) and support regular audits.
  • Collaborate with developers to remediate vulnerabilities, providing actionable guidance and ensuring effective patching or mitigation measures.
  • Develop, deploy, and manage security tools and technologies (e.g., SAST, DAST, vulnerability management systems) to automate security testing and scanning processes.
  • Support application security incident response activities, identifying the root cause of security incidents and contributing to resolution strategies.
  • Contribute to security awareness programs for the development teams, focusing on secure coding practices and proactive security measures.
Additional Skills
  • Passion for continuous learning and professional development, with a commitment to staying updated and trained on the latest trends and technologies.
  • Eagerness to engage in new challenges and adapt quickly.
  • Strong work ethic and drive to take ownership of projects and see them through to completion.
  • Strong collaboration skills, able to work effectively with cross functional teams.
Benefits
  • Competitive salary - $110,000-$150,000
  • Employer sponsored health, dental, vision, life, and disability insurance
  • Retirement plan with company contribution
  • Annual company profit sharing
  • Personal development/training budget
  • Open, collaborative work environment
  • Extensive 2-week onboarding plan
  • Comprehensive mentorship program
Equal Opportunity Employer Statement & Applicant Rights

TherapyNotes LLC is an Equal Opportunity Employer and does not discriminate based on race, color, religion, sex, national origin, age, disability, genetic information, or any other protected status under federal, state, or local law. We are committed to providing a workplace free of discrimination and harassment.For more information about your rights under federal employment laws, please review the following:

  • Know Your Rights: Workplace Discrimination is Illegal
  • Family and Medical Leave Act (FMLA): Employee Rights Under FMLA

If you require a reasonable accommodation during the application process, please contact humanresources@therapynotes.com.

9/2/2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer (Application Security)
Cyber Security Engineer (Application Security)

Socket.dev • Philadelphia

On-site
USD 110,000 - 150,000
Competitive salary
Health, dental, vision, life, and disa
Retirement plan
+3
Cyber Security Engineer (Application Security)
Cyber Security Engineer (Application Security)

TherapyNotes.com • Pennsylvania

On-site
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+8
Cloud Security Engineer
Cloud Security Engineer

Socket.dev • Philadelphia

On-site
USD 110,000 - 150,000
Competitive salary
Health insurance
Retirement plan
+3
Cloud Security Engineer
Cloud Security Engineer

TherapyNotes.com • Pennsylvania

On-site
USD 110,000 - 150,000
Health, dental, vision, life, and STD
401(k) with company contributions
Profit sharing
+2
Cloud Security Engineer
Cloud Security Engineer

TherapyNotes.com • Philadelphia

On-site
USD 110,000 - 150,000
Competitive salary
Health insurance
Retirement plan
+5
Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

Remote
USD 90,000 - 130,000
Staff Security Engineer
Staff Security Engineer

Grow Therapy • New York (NY)

Hybrid
USD 150,000 - 210,000
Comprehensive health coverage
Access to therapy through our platform
Retirement savings and equity
+7
Cloud Systems Engineer
Cloud Systems Engineer

TherapyNotes, LLC • United States

On-site
USD 100,000 - 120,000
Employer sponsored health insurance
Dental insurance
Vision insurance
+7
Senior/Staff Security Engineer, Incident Response
Senior/Staff Security Engineer, Incident Response

Grow Therapy • Seattle (WA)

Hybrid
USD 220,000 - 240,000
Comprehensive Health Coverage
Parental Leave & Family Support
Financial Wellness
+5
Senior Security Engineer – Application Security
Senior Security Engineer – Application Security

K Health • New York (NY)

On-site
USD 150,000 - 200,000