Cloud Security Engineer
Listed on 2026-09-05
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Network Security, Information Security & Data Protection
About Us
Therapy Notes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.
We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!
The Position
Therapy Notes is seeking an experienced, hands-on Cloud Security Engineer to secure our cloud infrastructure, containerized workloads, and infrastructure-as-code pipelines. The right candidate brings deep expertise in cloud security posture management, Kubernetes and container security, and Zero Trust network access, and is comfortable working in a healthcare-regulated environment (HIPAA, HITRUST, HITECH). This role also contributes to broader security engineering efforts — vulnerability management, incident response, and identity and access security — as part of a small, collaborative security team.
Required Skills and Experience
- Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered.
- 5+ years of experience in cloud security engineering or related role.
- Deep, hands-on experience securing cloud infrastructure and cloud-based applications (Azure preferred, AWS a plus).
- Hands-on network security experience and a strong understanding of network architecture, connectivity, segmentation, and firewall controls.
- Experience securing containerized workloads and Kubernetes environments (e.g., AKS) — network policy, workload identity, runtime protection.
- Experience with cloud security posture management (CSPM) and remediating misconfigurations across cloud environments.
- Experience securing IaC orchestration platforms — access control, secrets management, and deployment approval workflows (e.g., Terraform, Open Tofu).
- Experience with Microsoft Entra , including Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access models.
- Experience with Zero Trust / SASE tooling (e.g., Cloudflare Zero Trust, WAF, Gateway, or equivalent).
- Knowledge of security frameworks (NIST, ISO 27001, CIS) and compliance frameworks (HITRUST, PCI DSS).
- Proven ability to conduct security assessments, vulnerability management, and incident response.
- Strong understanding of OS platforms (Windows, Linux) and endpoint security.
- Industry certifications such as CISSP, SSCP, Security+, or a cloud security certification (Azure/AWS) preferred.
Responsibilities
- Manage and secure cloud infrastructure and cloud-based applications, with a focus on Azure.
- Secure containerized workloads and Kubernetes environments (e.g., AKS) — network policy, workload identity, runtime protection, and container image scanning.
- Own and mature cloud security posture management (CSPM) — continuously identify and remediate misconfigurations across cloud environments.
- Secure infrastructure-as-code orchestration platforms — access control, secrets management, and deployment approval workflows for Terraform/Open Tofu pipelines.
- Manage and secure identities in Microsoft Entra Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access models.
- Review network diagrams and proposed connectivity changes, provide security input on segmentation and sensitive data flows, and work with IT and SRE teams to address identified concerns.
- Administer Zero Trust network access and edge security tooling to secure access to corporate and cloud resources.
- Hands-on management of broader security solutions across the organization: SIEM, DLP, E/XDR, vulnerability management.
- Monitor security alerts, respond to and elevate incidents, and participate in the incident response on-call rotation.
- Conduct threat analysis, vulnerability assessments, and risk evaluations; document findings, manage mitigation, and report status to leadership.
- Develop queries, scripts, integrations, and automated workflows that improve cloud security operations.
- Collaborate with development teams to ensure security is continuously integrated into the SDLC and CI/CD…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).