Cloud Security Engineer
Job Description
TherapyNotes.com is looking for a hands-on Cloud Security Engineer to help protect cloud infrastructure, containerized workloads, and infrastructure-as-code pipelines with a strong emphasis on Azure. This role supports cloud security posture management and security engineering initiatives such as vulnerability management, incident response, and identity and access controls, within a healthcare-regulated environment.
Key Responsibilities
- Manage and secure cloud infrastructure and cloud-based applications, with a focus on Azure.
- Secure containerized workloads and Kubernetes environments (for example AKS), including network policy, workload identity, runtime protection, and container image scanning.
- Own and mature cloud security posture management (CSPM) by continuously identifying and remediating misconfigurations across cloud environments.
- Secure infrastructure-as-code orchestration platforms by implementing access control, secrets management, and deployment approval workflows for Terraform and OpenTofu pipelines.
- Manage and secure identities in Microsoft Entra ID using Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access models.
- Review network diagrams and proposed connectivity changes, provide security guidance on segmentation and sensitive data flows, and coordinate with IT and SRE teams on concerns.
- Administer Zero Trust network access and edge security tooling to secure access to corporate and cloud resources.
- Support broader security engineering capabilities, including SIEM, DLP, E/XDR, and vulnerability management.
- Monitor security alerts, respond to and escalate incidents, and participate in the incident response on-call rotation.
- Conduct threat analysis, vulnerability assessments, and risk evaluations; document results, manage mitigation, and report status to leadership.
- Develop queries, scripts, integrations, and automated workflows that improve cloud security operations.
- Collaborate with development teams to integrate security into the SDLC and CI/CD pipeline.
- Perform periodic cloud configuration and access reviews to support compliance with security standards.
- Participate in audits and assessments to support governance, risk management, and compliance (GRC) efforts.
Requirements
- 5+ years of experience in cloud security engineering or a related role.
- Deep, hands-on experience securing cloud infrastructure and cloud-based applications, with Azure preferred and AWS a plus.
- Hands-on network security experience and strong understanding of network architecture, connectivity, segmentation, and firewall controls.
- Experience securing containerized workloads and Kubernetes environments (for example AKS), including network policy and workload identity.
- Experience with cloud security posture management (CSPM) and remediating misconfigurations across cloud environments.
- Experience securing IaC orchestration platforms with access control, secrets management, and deployment approval workflows (for example Terraform, OpenTofu).
- Experience with Microsoft Entra ID, including Conditional Access, Entitlement Management, and JIT privileged access models.
- Experience with Zero Trust / SASE tooling (for example Cloudflare Zero Trust, WAF, Gateway, or equivalent).
- Knowledge of security frameworks (NIST, ISO 27001, CIS) and compliance frameworks (HITRUST, PCI DSS).
- Proven ability to conduct security assessments, vulnerability management, and incident response.
- Strong understanding of Windows and Linux platforms and endpoint security.
- Industry certifications such as CISSP, SSCP, Security+, or a cloud security certification (Azure/AWS) are preferred.
- Bachelor’s degree in information security, computer science, or a related field is preferred; equivalent experience will be considered.
Technologies
- Azure, AWS
- Kubernetes, AKS
- Cloud Security Posture Management (CSPM)
- Terraform, OpenTofu
- Microsoft Entra ID, Conditional Access, Entitlement Management, just-in-time (JIT) privileged access models
- Zero Trust / SASE, Cloudflare Zero Trust, WAF, Gateway
- NIST, ISO 27001, CIS, HITRUST, PCI DSS
- Windows, Linux
- CISSP, SSCP, Security+
- SIEM, DLP, E/XDR
- GitOps tooling: Argo, Flux
Compensation and Benefits
- Competitive salary: $110,000 - $150,000 per year
- Employer sponsored health, dental, vision, life, and disability insurance
- Retirement plan with company contribution
- Annual company profit sharing
- Personal development and training budget
- Open, collaborative work environment
- Extensive 2-week onboarding plan
- Comprehensive mentorship program
Additional Skills
- Familiarity with GitOps tooling (Argo, Flux) for secure Kubernetes deployments
- Network or systems engineering background is a plus
- Familiarity with programming or scripting languages is a plus
- Commitment to continuous learning and staying current with industry trends and technologies
- Strong ownership mindset and ability to drive projects to completion
- Strong collaboration skills across cross-functional teams
Equal Opportunity Employer: TherapyNotes LLC is an Equal Opportunity Employer and does not discriminate based on race, color, religion, sex, national origin, age, disability, genetic information, or any other protected status under federal, state, or local law. The company is committed to providing a workplace free of discrimination and harassment. If you require a reasonable accommodation during the application process, contact [email protected]. 10/6/2026.
Location: Philadelphia, PA (onsite)
Education: Bachelor’s degree in information security, computer science, or related field (preferred); equivalent experience considered