Cybersecurity Specialist

ISHE

Town of Florida, Northern (NY, KY)

Hybrid

USD 110,000 - 160,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Therapy Management Corporation (TMC) is seeking a Cybersecurity Specialist to protect its systems, applications, and cloud infrastructure. The role combines security operations, cloud security, and compliance monitoring to improve the overall security posture.

You will manage Vanta and Aikido Security, monitor Azure security posture, respond to incidents, and support HIPAA, SOC 2, and HITRUST compliance. Strong collaboration with DevSecOps and IT teams is essential.

Qualifications

  • Bachelor's degree or higher in Cybersecurity, IT, CS, or related field, or equivalent work experience.
  • 3+ years in cybersecurity, security operations, or related role.
  • Hands-on experience securing Microsoft Azure environments.
  • Experience with Microsoft cloud security technologies (Entra ID, Defender for Cloud, RBAC, MFA, Conditional Access, Key Vault).
  • Experience with Vanta or similar GRC automation platforms.
  • Experience with Aikido Security, Snyk, or GitHub Advanced Security.
  • Vulnerability management and remediation coordination experience.
  • Knowledge of SAST, SCA, secrets detection, IaC security, container security.
  • Identity and access management, least-privilege, zero-trust concepts.
  • Incident response familiarity; HIPAA, SOC 2, HITRUST, ISO/NIST/CIS awareness.
  • Networking fundamentals, SIEM, logging, monitoring.
  • Scripting in PowerShell, Bash, Python; APIs.

Responsibilities

  • Own day-to-day administration and improvement of security platforms (Vanta and Aikido).
  • Monitor security systems, investigate threats, coordinate remediation.
  • Maintain compliance documentation, policies, and audit evidence.
  • Configure Defender for Cloud, Entra ID, Key Vault, Policy and Monitor.
  • Collaborate with DevSecOps and infrastructure teams to implement improvements.

Skills

Azure security
Vanta
Aikido Security
Cloud security
Incident response
RBAC / IAM

Education

Bachelor's degree in Cybersecurity or related field

Tools

Snyk
GitHub Advanced Security
Microsoft Defender for Cloud
Azure Key Vault
Entra ID

Job description

COMPANY OVERVIEW
Therapy Management Corporation (TMC) strives to be the preferred therapy provider and
employer in all communities we serve. We make a positive difference by delivering
compassionate, superior care to all. Our passionate commitment to service excellence creates
loyal customers and cultivates the best working environment for our TMC family. Our success is
built on unwavering integrity, ethics, and an environment of innovation.
DESCRIPTION
The Cybersecurity Specialist is responsible for helping protect TMC's systems, applications, cloud
infrastructure, and sensitive data from security threats and vulnerabilities. This role combines
hands-on security operations, cloud security, vulnerability management, and compliance
monitoring with a focus on continuously improving TMC's overall security posture.
As a Cybersecurity Specialist, you are expected to support the organization and its technology
through the security lifecycle:
Understand the environment: Build a thorough understanding of TMC's applications,
infrastructure, users, security controls, regulatory requirements, and evolving threat
landscape.
Protect the environment: Implement, maintain, and improve security controls across
TMC's Azure environment, applications, identities, endpoints, and supporting technology
platforms.
Monitor and respond: Continuously monitor security systems and findings, investigate
potential threats and vulnerabilities, coordinate remediation, and assist with incident
response.
Maintain compliance: Ensure security controls remain effective and audit-ready by
maintaining security and compliance platforms, evidence, documentation, policies, and
remediation activities.

RESPONSIBILITIES

Own the day-to-day administration, configuration, integration health, and continuous improvement of TMC's security platforms, with particular responsibility for Vanta and Aikido Security.

Manage Vanta control monitoring, automated tests, evidence collection, access reviews, security findings, and audit-readiness activities.

Manage Aikido Security capabilities including application security scanning, dependency analysis, secrets detection, infrastructure-as-code scanning, container security, and cloud security posture monitoring.

Monitor and improve TMC's Microsoft Azure security posture, including identity and access controls, resource configuration, logging, network protections, and cloud security controls.

Configure and maintain applicable Microsoft security technologies such as Microsoft Defender for Cloud, Microsoft Entra ID, Azure Key Vault, Azure Policy, Azure Monitor, and Microsoft Sentinel.

Review security findings and vulnerabilities, assess their severity and business risk, prioritize remediation, and verify resolution.

Coordinate security remediation with development, DevSecOps, infrastructure, and other technology teams.

Review identity and access controls to support least-privilege access, appropriate authentication controls, privileged-access management, and secure application identities.

Monitor security alerts and events, investigate suspicious activity, elevate significant threats, and participate in incident containment, remediation, root-cause analysis, and post-incident improvement.

Support TMC's compliance with applicable security and healthcare standards, including HIPAA, SOC 2, and HITRUST, by monitoring control effectiveness, identifying gaps, and coordinating corrective actions.

Support internal and external audits by maintaining security evidence, responding to findings, and ensuring corrective actions are tracked to completion.

Assist with third-party security reviews, vendor risk assessments, security questionnaires, and other security-assurance activities as needed.

Develop and maintain security dashboards, reports, procedures, runbooks, and technical documentation.

Automate repetitive security monitoring, reporting, evidence collection, and remediation activities where appropriate using scripting, APIs, and platform integrations.

Collaborate with development, DevSecOps, infrastructure, compliance, and business stakeholders to implement practical security improvements while minimizing unnecessary operational friction.

Evaluate existing security controls and recommend improvements to technologies, configurations, processes, and security practices.

Stay current with cybersecurity threats, vulnerabilities, Azure security capabilities, regulatory requirements, and industry best practices.

REQUIRED QUALIFICATIONS

Bachelor's degree or higher in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field, or equivalent work experience.

3+ years of hands-on experience in cybersecurity, security operations, cloud security, information security, or a related technical security role.

Hands-on experience securing and monitoring Microsoft Azure environments.

Working knowledge of Microsoft cloud security technologies and concepts including Microsoft Entra ID, Defender for Cloud, RBAC, Multi-Factor Authentication, Conditional Access, Key Vault, Azure networking, logging, and monitoring.

Experience administering or supporting security compliance or GRC automation platforms such as Vanta, or similar platforms. Direct Vanta experience is strongly preferred.

Experience administering or supporting application and vulnerability security platforms such as Aikido Security, Snyk, GitHub Advanced Security, or comparable tools. Direct Aikido experience is strongly preferred.

Practical experience with vulnerability management, including risk assessment, prioritization, remediation coordination, and validation.

Understanding of application and cloud security concepts including SAST, SCA, secrets detection, dependency vulnerabilities, infrastructure-as-code security, container security, and cloud misconfiguration.

Working knowledge of identity and access management, least-privilege principles, zero-trust concepts, and privileged-access management.

Experience investigating security alerts and participating in cybersecurity incident response.

Understanding of security and compliance frameworks applicable to regulated organizations, including HIPAA, SOC 2, HITRUST, ISO 42007, NIST, and CIS guidance.

Understanding of networking fundamentals including firewalls, DNS, TCP/IP, VPNs, virtual networks, network security groups, and private endpoints.

Familiarity with SIEM technologies, security logging, threat detection, and log analysis.

Ability to use scripting or automation technologies such as PowerShell, Bash, Python, APIs, or Microsoft Graph to improve security operations.

Strong analytical, troubleshooting, documentation, and communication skills.

Ability to effectively collaborate across development, DevSecOps, infrastructure, compliance, leadership, and business teams.

Demonstrated ability to take ownership, work independently, and continuously improve security processes.

Relevant security certifications such as CompTIA Security+, Microsoft AZ-500, SC-200, SC-300, CISSP, or CCSP are preferred.

Organized, detail-oriented, and process- and improvement-minded.

CULTURE FIT

The culture at TMC embraces those that demonstrate a deep passion for solving the problems of healthcare with enthusiasm for building positive working relationships and winning as a team.

Creating a strong workplace culture has been one of our staples, which we believe encourages and inspires employees to do their best. We also embrace an "All In" mindset and give back to our communities through personal and company initiatives. Individuals in this role should embrace a mindset of continuous improvement and be prepared to have some fun along the way!

TMC is an Equal Opportunity Employer

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Specialist
Cybersecurity Specialist

Colorado Psychiatric • Town of Florida (NY), Northern (KY)

Hybrid
USD 90,000 - 130,000
Cybersecurity Specialist
Cybersecurity Specialist

Houston Hospitality Alliance • Town of Florida (NY), Northern (KY)

Hybrid
USD 110,000 - 140,000
Cybersecurity Specialist
Cybersecurity Specialist

Sustainable World, Inc. • Town of Florida (NY), Northern (KY)

Hybrid
USD 90,000 - 130,000
Cybersecurity Specialist
Cybersecurity Specialist

Koitecc Solutions • Town of Florida (NY), Northern (KY)

On-site
USD 110,000 - 170,000
Cybersecurity Specialist
Cybersecurity Specialist

TMC: Therapy Management Corporation • Homosassa Springs (FL)

On-site
USD 90,000 - 120,000
Cloud Security Specialist | Azure & Compliance Expert
Cloud Security Specialist | Azure & Compliance Expert

ISHE • Town of Florida (NY), Northern (KY)

Hybrid
USD 110,000 - 160,000
Azure Cloud Security Engineer & Compliance Specialist
Azure Cloud Security Engineer & Compliance Specialist

Colorado Psychiatric • Town of Florida (NY), Northern (KY)

Hybrid
USD 90,000 - 130,000
Azure Cybersecurity Engineer - Cloud Security & Compliance
Azure Cybersecurity Engineer - Cloud Security & Compliance

Houston Hospitality Alliance • Town of Florida (NY), Northern (KY)

Hybrid
USD 110,000 - 140,000
Azure Security Engineer — Healthcare, Compliance & Incident Response
Azure Security Engineer — Healthcare, Compliance & Incident Response

Sustainable World, Inc. • Town of Florida (NY), Northern (KY)

Hybrid
USD 90,000 - 130,000
Azure Cybersecurity Engineer - Cloud Security & Compliance
Azure Cybersecurity Engineer - Cloud Security & Compliance

Koitecc Solutions • Town of Florida (NY), Northern (KY)

Hybrid
USD 110,000 - 170,000