Cloud Security Engineer
About UsTherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!The PositionTherapyNotes is seeking an experienced, hands-on Cloud Security Engineer to secure our cloud infrastructure, containerized workloads, and infrastructure-as-code pipelines. The right candidate brings deep expertise in cloud security posture management, Kubernetes and container security, and Zero Trust network access, and is comfortable working in a healthcare-regulated environment (HIPAA, HITRUST, HITECH). This role also contributes to broader security engineering efforts — vulnerability management, incident response, and identity and access security — as part of a small, collaborative security team.Required Skills And ExperienceBachelor's degree in information security, computer science, or related field preferred; equivalent experience considered5+ years of experience in cloud security engineering or related roleDeep, hands-on experience securing cloud infrastructure and cloud-based applications (Azure preferred, AWS a plus)Hands-on network security experience and a strong understanding of network architecture, connectivity, segmentation, and firewall controlsExperience securing containerized workloads and Kubernetes environments (e.g., AKS) — network policy, workload identity, runtime protectionExperience with cloud security posture management (CSPM) and remediating misconfigurations across cloud environmentsExperience securing IaC orchestration platforms — access control, secrets management, and deployment approval workflows (e.g., Terraform, OpenTofu)Experience with Microsoft Entra ID, including Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access modelsExperience with Zero Trust / SASE tooling (e.g., Cloudflare Zero Trust, WAF, Gateway, or equivalent)Knowledge of security frameworks (NIST, ISO 27001, CIS) and compliance frameworks (HITRUST, PCI DSS)Proven ability to conduct security assessments, vulnerability management, and incident responseStrong understanding of OS platforms (Windows, Linux) and endpoint securityIndustry certifications such as CISSP, SSCP, Security+, or a cloud security certification (Azure/AWS) preferredResponsibilitiesManage and secure cloud infrastructure and cloud-based applications, with a focus on AzureSecure containerized workloads and Kubernetes environments (e.g., AKS) — network policy, workload identity, runtime protection, and container image scanningOwn and mature cloud security posture management (CSPM) — continuously identify and remediate misconfigurations across cloud environmentsSecure infrastructure-as-code orchestration platforms — access control, secrets management, and deployment approval workflows for Terraform/OpenTofu pipelinesManage and secure identities in Microsoft Entra ID through Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access modelsReview network diagrams and proposed connectivity changes, provide security input on segmentation and sensitive data flows, and work with IT and SRE teams to address identified concernsAdminister Zero Trust network access and edge security tooling to secure access to corporate and cloud resourcesHands-on management of broader security solutions across the organization{{:}} SIEM, DLP, E/XDR, vulnerability managementMonitor security alerts, respond to and escalate incidents, and participate in the incident response on-call rotationConduct threat analysis, vulnerability assessments, and risk evaluations; document findings, manage mitigation, and report status to leadershipDevelop queries, scripts, integrations, and automated workflows that improve cloud security operationsCollaborate with development teams to ensure security is continuously integrated into the SDLC and CI/CD pipelineConduct periodic cloud configuration and access reviews to ensure compliance with security standardsParticipate in audits and assessments, supporting governance, risk management, and compliance (GRC) effortsAdditional SkillsFamiliarity with GitOps tooling (Argo, Flux) for secure deployment in Kubernetes environmentsNetwork or Systems Engineering background a huge plusFamiliarity with programming/scripting languages a plusPassion for continuous learning and professional development, with a commitment to staying updated and trained on the latest trends and technologiesEagerness to engage in new challenges and adapt quicklyStrong work ethic and drive to take ownership of projects and see them through to completionStrong collaboration skills, able to work effectively with cross functional teamsBenefitsCompetitive salary - $110,000-$150,000Employer sponsored health, dental, vision, life, and disability insuranceRetirement plan with company contributionAnnual company profit sharingPersonal development/training budgetOpen, collaborative work environmentExtensive 2-week onboarding planComprehensive mentorship programEqual Opportunity Employer Statement & Applicant RightsTherapyNotes LLC is an Equal Opportunity Employer and does not discriminate based on race, color, religion, sex, national origin, age, disability, genetic information, or any other protected status under federal, state, or local law. We are committed to providing a workplace free of discrimination and harassment.For more information about your rights under federal employment laws, please review the following{{:}}Know Your Rights{{:}} Workplace Discrimination is IllegalFamily and Medical Leave Act (FMLA){{:}} Employee Rights Under FMLAIf you require a reasonable accommodation during the application process, please contact humanresources@therapynotes.com.9/2/2026