Cyber Security Engineer (Application Security)
Quick Summary
About Us TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth,
TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.
We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!
TherapyNotes is seeking an experienced, hands-on Cyber Security Engineer to own application security across our SDLC and CI/CD pipeline. The right candidate brings deep expertise securing CI/CD pipelines, code and dependency scanning workflows, and infrastructure-as-code, and is comfortable working in a healthcare-regulated environment (HIPAA, HITRUST, HITECH). This role also contributes to broader security engineering efforts — vulnerability management, incident response, and identity and access security — as part of a small, collaborative security team.
Requirements
~1 min read- Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered.
- 5+ years in application security or security engineering.
- Demonstrated experience securing CI/CD pipelines and GitHub Actions — including SAST/DAST, code/secret/dependency-scanning triage (e.g., GitHub Advanced Security, Snyk), runner and workflow-permission security, and third-party action/supply-chain risk.
- Experience reviewing Terraform or other infrastructure-as-code for security misconfigurations.
- Working knowledge of SIEM, EDR/XDR, and DLP platforms — deployment, tuning, and alert triage.
- Understanding of Zero Trust architecture principles and how they apply to application and identity access.
- Strong understanding of healthcare regulations (HIPAA, HITECH, HITRUST) and their impact on application security.
- Experience with API security, particularly integrations with other healthcare systems; familiarity with HL7 or other healthcare data standards preferred.
- Prior experience securing cloud environments (Azure preferred, AWS a plus).
- Willingness to participate in an incident response on-call rotation.
- Industry certifications such as GWAPT, OSWE, GPEN, or a cloud security certification (Azure/AWS) are ideal; CISSP or HCISPP a plus but not a substitute for hands-on tooling experience.
Responsibilities
~2 min read- →Collaborate with developmental teams to ensure security is continuously integrated into the Software Development Lifecycle (SDLC) and CI/CD pipeline.
- →Enforce secure coding standards and best practices to minimize vulnerabilities and to protect the confidentiality, integrity, and availability of our customer's data.
- →Perform in-depth security assessments, code reviews, and threat modeling on applications to identify potential vulnerabilities and risks.
- →Own and operate GitHub Advanced Security — triage code, secret, and dependency-scanning findings, identify recurring vulnerability patterns and recommend broader fixes, and continuously improve scanning coverage, configuration, and workflows.
- →Secure CI/CD pipelines and GitHub Actions — identities, runners, permissions, and secrets — and reduce software supply chain risk through third-party action review, dependency controls, action pinning, and artifact provenance.
- →Review Terraform and other infrastructure-as-code for security issues, partnering with IT platform teams on IaC scanning and secure deployment practices.
- →Ensure application security measures align with healthcare regulations and standards (e.g., HIPAA, HITRUST, and HITECH) and support regular audits.
- →Collaborate with developers to remediate vulnerabilities, providing actionable guidance and ensuring effective patching or mitigation measures.
- →Develop, deploy, and manage security tools and technologies (e.g., SAST, DAST, vulnerability management systems) to automate security testing and scanning processes.
- →Support application security incident response activities, identifying the root cause of security incidents and contributing to resolution strategies.
- →Contribute to security awareness programs for the development teams, focusing on secure coding practices and proactive security measures.
- Passion for continuous learning and professional development, with a commitment to staying updated and trained on the latest trends and technologies.
- Eagerness to engage in new challenges and adapt quickly.
- Strong work ethic and drive to take ownership of projects and see them through to completion.
- Strong collaboration skills, able to work effectively with cross functional teams.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- September 2, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 25%
- Scored at
- September 29, 2026
Signal breakdown
Similar Cyber Security Engineer jobs
View all →Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.