Summary
β¨ AIβGenerated
Take ownership of application security across the full software development lifecycle and CI/CD pipeline in a regulated healthcare technology environment. You will secure build and deployment workflows, implement code and dependency scanning, manage Infrastructure as Code security, and contribute to vulnerability management, incident response, and identity and access security. This is a hands-on role suited to an experienced security engineer.
Highlights
Hands-on ownership of application security across the software development lifecycle and CI/CD pipeline. The role combines application security with vulnerability management, incident response, and identity security in a regulated healthcare environment, offering broad security engineering responsibility.
Description
About Us
TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.
We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge.
Join us, and let's revolutionize behavioral health software together while making a real difference!
The Position
TherapyNotes is seeking an experienced, hands-on Cyber Security Engineer to own application security across our SDLC and CI/CD pipeline.
The right candidate brings deep expertise securing CI/CD pipelines, code and dependency scanning workflows, and infrastructure-as-code, and is comfortable working in a healthcare-regulated environment (HIPAA, HITRUST, HITECH).
This role also contributes to broader security engineering efforts β vulnerability management, incident response, and identity and access security β as part of a small, collaborative security team.
Required Skills And Experience
Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered5+ years in application security or security engineeringDemonstrated experience securing CI/CD pipelines and GitHub Actions β including SAST/DAST, code/secret/dependency-scanning triage (e.g., GitHub Advanced Security, Snyk), runner and workflow-permission security, and third-party action/supply-chain riskExperience reviewing Terraform or other infrastructure-as-code for security misconfigurationsWorking knowledge of SIEM, EDR/XDR, and DLP platforms β deployment, tuning, and alert triageUnderstanding of Zero Trust architecture principles and how they apply to application and identity accessStrong understanding of healthcare regulations (HIPAA, HITECH, HITRUST) and their impact on application securityExperience with API security, particularly integrations with other healthcare systems; familiarity with HL7 or other healthcare data standards preferredPrior experience securing cloud environments (Azure preferred, AWS a plus)Willingness to participate in an incident response on-call rotationIndustry certifications such as GWAPT, OSWE, GPEN, or a cloud security certification (Azure/AWS) are ideal; CISSP or HCISPP a plus but not a substitute for hands-on tooling experience
Application Security Responsibilities
Collaborate with developmental teams to ensure security is continuously integrated into the Software Development Lifecycle (SDLC) and CI/CD pipelineEnforce secure coding standards and best practices to minimize vulnerabilities and to protect the confidentiality, integrity, and availability of our customer's dataPerform in-depth security assessments, code reviews, and threat modeling on applications to identify potential vulnerabilities and risksOwn and operate GitHub Advanced Security β triage code, secret, and dependency-scanning findings, identify recurring vulnerability patterns and recommend broader fixes, and continuously improve scanning coverage, configuration, and workflowsSecure CI/CD pipelines and GitHub Actions β identities, runners, permissions, and secrets β and reduce software supply chain risk through third-party action review, dependency controls, action pinning, and artifact provenanceReview Terraform and other infrastructure-as-code for security issues, partnering with IT platform teams on IaC scanning and secure deployment practicesEnsure application security measures align with healthcare regulations and standards (e.g., HIPAA, HITRUST, and HITECH) and support regular auditsCollaborate with developers to remediate vulnerabilities, providing actionable guidance and ensuring effective patching or mitigation measuresDevelop, deploy, and manage security tools and technologies (e.g., SAST, DAST, vulnerability management systems) to automate security testing and scanning processesSupport application security incident response activities, identifying the root cause of security incidents and contributing to resolution strategiesContribute to security awareness programs for the development teams, focusing on secure coding practices and proactive security measures
Additional Skills
Passion for continuous learning and professional development, with a commitment to staying updated and trained on the latest trends and technologiesEagerness to engage in new challenges and adapt quicklyStrong work ethic and drive to take ownership of projects and see them through to completionStrong collaboration skills, able to work effectively with cross functional teams
Benefits
Competitive salary - $110,000-$150,000Employer sponsored health, dental, vision, life, and disability insuranceRetirement plan with company contributionAnnual company profit sharingPersonal development/training budgetOpen, collaborative work environmentExtensive 2-week onboarding planComprehensive mentorship program
Equal Opportunity Employer Statement & Applicant Rights
TherapyNotes LLC is an Equal Opportunity Employer and does not discriminate based on race, color, religion, sex, national origin, age, disability, genetic information, or any other protected status under federal, state, or local law.
We are committed to providing a workplace free of discrimination and harassment.For more information about your rights under federal employment laws, please review the following{{:}}
Know Your Rights{{:}} Workplace Discrimination is IllegalFamily and Medical Leave Act (FMLA){{:}} Employee Rights Under FMLA
If you require a reasonable accommodation during the application process, please contact humanresources@therapynotes.com.
10/6/2026