Cyber Security Engineer
Job Description
TherapyNotes.com is looking for a hands-on Cyber Security Engineer to drive application security throughout the Software Development Lifecycle (SDLC) and the CI/CD pipeline. The position emphasizes securing CI/CD and GitHub Actions, improving automated scanning coverage, and supporting vulnerability management, incident response, and identity and access security in a healthcare-regulated environment.
Role Focus
- Own application security across the SDLC and CI/CD pipeline, with emphasis on CI/CD and GitHub Actions security.
- Secure GitHub Advanced Security workflows, including triage of code, secret, and dependency scanning findings.
- Review infrastructure-as-code, including Terraform, and partner with IT platform teams to support secure deployment practices.
- Contribute to vulnerability management, incident response activities, and identity and access security.
Responsibilities
- Collaborate with development teams to embed security continuously into the SDLC and CI/CD pipeline.
- Enforce secure coding standards and best practices to reduce vulnerabilities and protect the confidentiality, integrity, and availability of customer data.
- Conduct in-depth security assessments, code reviews, and threat modeling to identify application vulnerabilities and risks.
- Own and operate GitHub Advanced Security, triaging findings and identifying recurring vulnerability patterns to recommend broader fixes and improve scanning coverage, configuration, and workflows.
- Secure CI/CD pipelines and GitHub Actions by addressing identities, runners, permissions, and secrets, and reduce software supply chain risk through third-party action review, dependency controls, action pinning, and artifact provenance.
- Review Terraform and other infrastructure-as-code for security issues, supporting IaC scanning and secure deployment practices with IT platform teams.
- Ensure application security measures align with healthcare regulations and standards such as HIPAA, HITRUST, and HITECH, and support regular audits.
- Partner with developers on vulnerability remediation by providing actionable guidance and ensuring effective patching or mitigation.
- Develop, deploy, and manage security tools and technologies, including SAST, DAST, and vulnerability management systems, to automate security testing and scanning.
- Support application security incident response activities, contributing to root-cause identification and resolution strategies.
- Contribute to security awareness programs for development teams focused on secure coding practices and proactive security measures.
Requirements
- Bachelor’s degree in information security, computer science, or related field preferred (equivalent experience considered).
- 5+ years in application security or security engineering.
- Proven experience securing CI/CD pipelines and GitHub Actions, including SAST/DAST and triage of code, secret, and dependency scanning findings (e.g., GitHub Advanced Security, Snyk), with experience covering runner and workflow-permission security as well as third-party action and supply-chain risk.
- Experience reviewing Terraform or other infrastructure-as-code for security misconfigurations.
- Working knowledge of SIEM, EDR/XDR, and DLP platforms, including deployment, tuning, and alert triage.
- Understanding of Zero Trust architecture principles as they apply to application security and identity access.
- Strong understanding of healthcare regulations including HIPAA, HITECH, and HITRUST and how they influence application security.
- Experience with API security, especially integrations with other healthcare systems; familiarity with HL7 or other healthcare data standards preferred.
- Experience securing cloud environments (Azure preferred, AWS a plus).
- Willingness to participate in an incident response on-call rotation.
- Industry certifications such as GWAPT, OSWE, GPEN, or a cloud security certification (Azure/AWS) are ideal; CISSP or HCISPP is a plus and not a substitute for hands-on tooling experience.
Technologies
- GitHub Actions, GitHub Advanced Security, Snyk
- Terraform
- SIEM, EDR/XDR, DLP
- Zero Trust architecture
- API security, HL7
- Azure, AWS
- SAST, DAST, vulnerability management systems
- GWAPT, OSWE, GPEN
- CISSP, HCISPP
Location
Philadelphia, PA (onsite)
Compensation
USD 110,000 - 150,000 per year
Benefits
- Competitive salary range: $110,000-$150,000
- Employer-sponsored health, dental, vision, life, and disability insurance
- Retirement plan with company contribution
- Annual company profit sharing
- Personal development and training budget
- Open, collaborative work environment
- Extensive 2-week onboarding plan
- Comprehensive mentorship program
Team Context
TherapyNotes.com is building a security program that supports application security across the SDLC and CI/CD pipeline. The role operates as part of a small, collaborative security team and includes responsibilities spanning vulnerability management, incident response, and identity and access security while working within healthcare regulatory expectations.