TherapyNotes, LLC
TherapyNotes, LLC
51 – 200 Employees
ConsultingHealthcareLegal
TherapyNotes, LLC develops practice management software for behavioral health professionals, including psychologists, therapists, psychiatrists, and social workers. Its integrated platform brings together scheduling, telehealth, electronic health records, billing, and client portal tools to help mental health practices manage clinical and administrative work in one secure system. The company combines customer support with ongoing product development informed by feedback from the professionals who use its software.

Cloud Security Engineer — Pennsylvania Remote

Secure TherapyNotes’ behavioral health SaaS platform across Azure infrastructure, Kubernetes workloads, and identity systems. Lead cloud compliance, incident response, and Zero Trust security operations.

Description

  • Manage and secure Azure-focused cloud infrastructure and cloud applications
  • Protect containerized workloads and Kubernetes environments through network policies, workload identity, runtime defenses, and image scanning
  • Own and improve cloud security posture management by finding and correcting misconfigurations
  • Secure Terraform and OpenTofu infrastructure-as-code pipelines with access controls, secrets management, and deployment approvals
  • Administer Microsoft Entra ID using Conditional Access, Entitlement Management, and just-in-time privileged access
  • Review network designs and connectivity changes, advising IT and SRE teams on segmentation and sensitive data flows
  • Operate Zero Trust network access and edge security tools
  • Manage SIEM, DLP, E/XDR, and vulnerability management platforms
  • Monitor alerts, handle and escalate incidents, and join the incident response on-call rotation
  • Perform threat analysis, vulnerability assessments, and risk evaluations; document findings, oversee mitigation, and report progress to leadership
  • Build queries, scripts, integrations, and automated workflows that strengthen cloud security operations
  • Partner with development teams to embed security into the SDLC and CI/CD pipelines
  • Perform recurring cloud configuration and access reviews for compliance
  • Support GRC activities through audits and security assessments

Requirements

  • Bachelor’s degree in information security, computer science, or a related field preferred; equivalent experience is considered
  • At least five years of experience in cloud security engineering or a related position
  • Deep hands-on experience securing cloud infrastructure and applications; Azure experience preferred, with AWS experience beneficial
  • Practical network security experience and a strong grasp of architecture, connectivity, segmentation, and firewall controls
  • Experience protecting containerized workloads and Kubernetes environments, including network policies, workload identity, and runtime security
  • Experience with cloud security posture management and remediation of cloud misconfigurations
  • Experience securing infrastructure-as-code orchestration platforms through access controls, secrets management, and deployment approvals, using Terraform or OpenTofu
  • Experience administering Microsoft Entra ID, including Conditional Access, Entitlement Management, and just-in-time privileged access
  • Experience with Zero Trust or SASE tools such as Cloudflare Zero Trust, WAF, and Gateway
  • Knowledge of NIST, ISO 27001, CIS, HITRUST, and PCI DSS frameworks
  • Demonstrated ability to perform security assessments, vulnerability management, and incident response
  • Strong knowledge of Windows, Linux, and endpoint security
  • Industry certification such as CISSP, SSCP, Security+, or an Azure or AWS cloud security credential preferred
  • Familiarity with GitOps tools such as Argo and Flux for secure Kubernetes deployments
  • Familiarity with programming or scripting languages is beneficial

Benefits

  • Employer-paid health, dental, vision, life, and disability insurance
  • Retirement plan with a company contribution
  • Annual company profit-sharing program
  • Budget for personal development and training
  • Open and collaborative workplace
  • Structured two-week onboarding program
  • Comprehensive mentorship program

Related Jobs