CybersecurityJobs.io
← Back to all jobs

Job Description

TherapyNotes.com is looking for a hands-on Cyber Security Engineer to drive application security throughout the Software Development Lifecycle (SDLC) and the CI/CD pipeline. The position emphasizes securing CI/CD and GitHub Actions, improving automated scanning coverage, and supporting vulnerability management, incident response, and identity and access security in a healthcare-regulated environment.

Role Focus

  • Own application security across the SDLC and CI/CD pipeline, with emphasis on CI/CD and GitHub Actions security.
  • Secure GitHub Advanced Security workflows, including triage of code, secret, and dependency scanning findings.
  • Review infrastructure-as-code, including Terraform, and partner with IT platform teams to support secure deployment practices.
  • Contribute to vulnerability management, incident response activities, and identity and access security.

Responsibilities

  • Collaborate with development teams to embed security continuously into the SDLC and CI/CD pipeline.
  • Enforce secure coding standards and best practices to reduce vulnerabilities and protect the confidentiality, integrity, and availability of customer data.
  • Conduct in-depth security assessments, code reviews, and threat modeling to identify application vulnerabilities and risks.
  • Own and operate GitHub Advanced Security, triaging findings and identifying recurring vulnerability patterns to recommend broader fixes and improve scanning coverage, configuration, and workflows.
  • Secure CI/CD pipelines and GitHub Actions by addressing identities, runners, permissions, and secrets, and reduce software supply chain risk through third-party action review, dependency controls, action pinning, and artifact provenance.
  • Review Terraform and other infrastructure-as-code for security issues, supporting IaC scanning and secure deployment practices with IT platform teams.
  • Ensure application security measures align with healthcare regulations and standards such as HIPAA, HITRUST, and HITECH, and support regular audits.
  • Partner with developers on vulnerability remediation by providing actionable guidance and ensuring effective patching or mitigation.
  • Develop, deploy, and manage security tools and technologies, including SAST, DAST, and vulnerability management systems, to automate security testing and scanning.
  • Support application security incident response activities, contributing to root-cause identification and resolution strategies.
  • Contribute to security awareness programs for development teams focused on secure coding practices and proactive security measures.

Requirements

  • Bachelor’s degree in information security, computer science, or related field preferred (equivalent experience considered).
  • 5+ years in application security or security engineering.
  • Proven experience securing CI/CD pipelines and GitHub Actions, including SAST/DAST and triage of code, secret, and dependency scanning findings (e.g., GitHub Advanced Security, Snyk), with experience covering runner and workflow-permission security as well as third-party action and supply-chain risk.
  • Experience reviewing Terraform or other infrastructure-as-code for security misconfigurations.
  • Working knowledge of SIEM, EDR/XDR, and DLP platforms, including deployment, tuning, and alert triage.
  • Understanding of Zero Trust architecture principles as they apply to application security and identity access.
  • Strong understanding of healthcare regulations including HIPAA, HITECH, and HITRUST and how they influence application security.
  • Experience with API security, especially integrations with other healthcare systems; familiarity with HL7 or other healthcare data standards preferred.
  • Experience securing cloud environments (Azure preferred, AWS a plus).
  • Willingness to participate in an incident response on-call rotation.
  • Industry certifications such as GWAPT, OSWE, GPEN, or a cloud security certification (Azure/AWS) are ideal; CISSP or HCISPP is a plus and not a substitute for hands-on tooling experience.

Technologies

  • GitHub Actions, GitHub Advanced Security, Snyk
  • Terraform
  • SIEM, EDR/XDR, DLP
  • Zero Trust architecture
  • API security, HL7
  • Azure, AWS
  • SAST, DAST, vulnerability management systems
  • GWAPT, OSWE, GPEN
  • CISSP, HCISPP

Location

Philadelphia, PA (onsite)

Compensation

USD 110,000 - 150,000 per year

Benefits

  • Competitive salary range: $110,000-$150,000
  • Employer-sponsored health, dental, vision, life, and disability insurance
  • Retirement plan with company contribution
  • Annual company profit sharing
  • Personal development and training budget
  • Open, collaborative work environment
  • Extensive 2-week onboarding plan
  • Comprehensive mentorship program

Team Context

TherapyNotes.com is building a security program that supports application security across the SDLC and CI/CD pipeline. The role operates as part of a small, collaborative security team and includes responsibilities spanning vulnerability management, incident response, and identity and access security while working within healthcare regulatory expectations.

Similar Jobs