Cyber Security Engineer (Cloud Security)

TherapyNotes.com

Pennsylvania

On-site

USD 150,000 - 190,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

TherapyNotes.com seeks an experienced Cloud Security Engineer to secure Azure-based cloud infrastructure, container workloads, and IaC pipelines. You will drive CSPM, Zero Trust, and identity security across our healthcare SaaS platform.

Join a small, collaborative security team and contribute to vulnerability management, incident response, and governance while ensuring secure SDLC integration and HIPAA/HITRUST compliance.

Qualifications

  • Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered.
  • 5+ years of experience in cloud security engineering or related role.
  • Deep hands-on experience securing cloud infrastructure and cloud-based applications (Azure preferred, AWS a plus).
  • Hands-on network security experience and understanding of network architecture, connectivity, segmentation, and firewall controls.
  • Experience securing containerized workloads and Kubernetes environments (e.g., AKS) - network policy, workload identity, runtime protection.
  • Experience with cloud security posture management (CSPM) and remediating misconfigurations across cloud environments.
  • Experience securing IaC orchestration platforms - access control, secrets management, and deployment workflows (Terraform, OpenTofu).
  • Experience with Microsoft Entra ID, including Conditional Access, Entitlement Management, and just-in-time privileged access models.
  • Experience with Zero Trust / SASE tooling (Cloudflare Zero Trust, WAF, Gateway, or equivalent).
  • Knowledge of security frameworks (NIST, ISO 27001, CIS) and compliance frameworks (HITRUST, PCI DSS).
  • Proven ability to conduct security assessments, vulnerability management, and incident response.

Responsibilities

  • Manage and secure cloud infrastructure and cloud-based applications, with a focus on Azure.
  • Secure containerized workloads and Kubernetes environments (e.g., AKS) - network policy, workload identity, runtime protection, and container image scanning.
  • Own and mature cloud security posture management (CSPM) - continuously identify and remediate misconfigurations across cloud environments.
  • Secure infrastructure-as-code orchestration platforms - access control, secrets management, and deployment approval workflows for Terraform/OpenTofu pipelines.
  • Manage and secure identities in Microsoft Entra ID through Conditional Access, Entitlement Management, and just-in-time privileged access models.
  • Review network diagrams and proposed connectivity changes, provide security input on segmentation and sensitive data flows, and work with IT and SRE teams to address concerns.
  • Administer Zero Trust network access and edge security tooling to secure access to corporate and cloud resources.
  • Hands-on management of broader security solutions across the organization: SIEM, DLP, E/XDR, vulnerability management.
  • Monitor security alerts, respond to and escalate and participate in the incident response on-call rotation.
  • Conduct threat analysis, vulnerability assessments, and risk evaluations; document findings, manage mitigation, and report status to leadership.
  • Develop queries, scripts, integrations, and automated workflows that improve cloud security operations.
  • Collaborate with development teams to ensure security is continuously integrated into the SDLC and CI/CD pipeline.
  • Conduct periodic cloud configuration and access reviews to ensure compliance with security standards.
  • Participate in audits and assessments, supporting governance, risk management, and compliance (GRC) efforts.

Skills

Cloud security
Azure
Kubernetes security
Identity management
Zero Trust

Education

Bachelor's degree in information security

Tools

Terraform
OpenTofu
Argo
Flux
Cloudflare Zero Trust

Job description

About Us

TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.

We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!

The Position

TherapyNotes is seeking an experienced, hands-on Cloud Security Engineer to secure our cloud infrastructure, containerized workloads, and infrastructure-as-code pipelines. The right candidate brings deep expertise in cloud security posture management, Kubernetes and container security, and Zero Trust network access, and is comfortable working in a healthcare-regulated environment (HIPAA, HITRUST, HITECH). This role also contributes to broader security engineering efforts - vulnerability management, incident response, and identity and access security - as part of a small, collaborative security team.

Required Skills and Experience
  • Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered.
  • 5+ years of experience in cloud security engineering or related role.
  • Deep, hands-on experience securing cloud infrastructure and cloud-based applications (Azure preferred, AWS a plus).
  • Hands-on network security experience and a strong understanding of network architecture, connectivity, segmentation, and firewall controls.
  • Experience securing containerized workloads and Kubernetes environments (e.g., AKS) - network policy, workload identity, runtime protection.
  • Experience with cloud security posture management (CSPM) and remediating misconfigurations across cloud environments.
  • Experience securing IaC orchestration platforms - access control, secrets management, and deployment approval workflows (e.g., Terraform, OpenTofu).
  • Experience with Microsoft Entra ID, including Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access models.
  • Experience with Zero Trust / SASE tooling (e.g., Cloudflare Zero Trust, WAF, Gateway, or equivalent).
  • Knowledge of security frameworks (NIST, ISO 27001, CIS) and compliance frameworks (HITRUST, PCI DSS).
  • Proven ability to conduct security assessments, vulnerability management, and incident response.
  • Strong understanding of OS platforms (Windows, Linux) and endpoint security.
  • Industry certifications such as CISSP, SSCP, Security+, or a cloud security certification (Azure/AWS) preferred.
Responsibilities
  • Manage and secure cloud infrastructure and cloud-based applications, with a focus on Azure.
  • Secure containerized workloads and Kubernetes environments (e.g., AKS) - network policy, workload identity, runtime protection, and container image scanning.
  • Own and mature cloud security posture management (CSPM) - continuously identify and remediate misconfigurations across cloud environments.
  • Secure infrastructure-as-code orchestration platforms - access control, secrets management, and deployment approval workflows for Terraform/OpenTofu pipelines.
  • Manage and secure identities in Microsoft Entra ID through Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access models.
  • Review network diagrams and proposed connectivity changes, provide security input on segmentation and sensitive data flows, and work with IT and SRE teams to address identified concerns.
  • Administer Zero Trust network access and edge security tooling to secure access to corporate and cloud resources.
  • Hands-on management of broader security solutions across the organization: SIEM, DLP, E/XDR, vulnerability management.
  • Monitor security alerts, respond to and escal ... and participate in the incident response on-call rotation.
  • Conduct threat analysis, vulnerability assessments, and risk evaluations; document findings, manage mitigation, and report status to leadership.
  • Develop queries, scripts, integrations, and automated workflows that improve cloud security operations.
  • Collaborate with development teams to ensure security is continuously integrated into the SDLC and CI/CD pipeline.
  • Conduct periodic cloud configuration and access reviews to ensure compliance with security standards.
  • Participate in audits and assessments, supporting governance, risk management, and compliance (GRC) efforts.
Additional Skills
  • Familiarity with GitOps tooling (Argo, Flux) for secure deployment in Kubernetes environments.
  • Network or Systems Engineering background a huge plus.
  • Familiarity with programming/scripting languages a plus.
  • Passion for continuous learning and professional development, with a commitment to staying updated and trained on
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

TherapyNotes.com • Pennsylvania

On-site
USD 110,000 - 150,000
Health, dental, vision, life, and STD
401(k) with company contributions
Profit sharing
+2
Security Engineer
Security Engineer

Healthmark Group • United States

On-site
USD 100,000 - 130,000
Cyber Security Engineer
Cyber Security Engineer

Cybersecurity Jobs • Philadelphia

On-site
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+7
Cloud Security Engineer
Cloud Security Engineer

UNAVAILABLE • McLean (VA)

On-site
USD 120,000 - 160,000
Senior Cloud Security Engineer (Azure & Zero Trust)
Senior Cloud Security Engineer (Azure & Zero Trust)

TherapyNotes.com • Pennsylvania

On-site
USD 150,000 - 190,000
Cloud Security Engineer
Cloud Security Engineer

UNAVAILABLE • Washington

On-site
USD 140,000 - 190,000
Cyber Security Engineer (Application Security)
Cyber Security Engineer (Application Security)

TherapyNotes.com • United States

Remote
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+3
Senior Cloud Security Engineer
Senior Cloud Security Engineer

UNAVAILABLE • Washington

On-site
USD 140,000 - 180,000
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Azure Cloud Security Engineer: CSPM, Kubernetes & Zero Trust
Azure Cloud Security Engineer: CSPM, Kubernetes & Zero Trust

TherapyNotes.com • Pennsylvania

On-site
USD 110,000 - 150,000
Health, dental, vision, life, and STD
401(k) with company contributions
Profit sharing
+2