The PositionTherapyNotes is seeking an experienced, hands-on Cloud Security Engineer to secure our cloud infrastructure, containerized workloads, and infrastructure-as-code pipelines. The right candidate brings deep expertise in cloud security posture management, Kubernetes and container security, and Zero Trust network access, and is comfortable working in a healthcare-regulated environment (HIPAA, HITRUST, HITECH). This role also contributes to broader security engineering efforts - vulnerability management, incident response, and identity and access security - as part of a small, collaborative security team.
Required Skills and Experience- Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered.
- 5+ years of experience in cloud security engineering or related role.
- Deep, hands-on experience securing cloud infrastructure and cloud-based applications (Azure preferred, AWS a plus).
- Hands-on network security experience and a strong understanding of network architecture, connectivity, segmentation, and firewall controls.
- Experience securing containerized workloads and Kubernetes environments (e.g., AKS) - network policy, workload identity, runtime protection.
- Experience with cloud security posture management (CSPM) and remediating misconfigurations across cloud environments.
- Experience securing IaC orchestration platforms - access control, secrets management, and deployment approval workflows (e.g., Terraform, OpenTofu).
- Experience with Microsoft Entra ID, including Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access models.
- Experience with Zero Trust / SASE tooling (e.g., Cloudflare Zero Trust, WAF, Gateway, or equivalent).
- Knowledge of security frameworks (NIST, ISO 27001, CIS) and compliance frameworks (HITRUST, PCI DSS).
- Proven ability to conduct security assessments, vulnerability management, and incident response.
- Strong understanding of OS platforms (Windows, Linux) and endpoint security.
- Industry certifications such as CISSP, SSCP, Security+, or a cloud security certification (Azure/AWS) preferred.
Responsibilities- Manage and secure cloud infrastructure and cloud-based applications, with a focus on Azure.
- Secure containerized workloads and Kubernetes environments (e.g., AKS) - network policy, workload identity, runtime protection, and container image scanning.
- Own and mature cloud security posture management (CSPM) - continuously identify and remediate misconfigurations across cloud environments.
- Secure infrastructure-as-code orchestration platforms - access control, secrets management, and deployment approval workflows for Terraform/OpenTofu pipelines.
- Manage and secure identities in Microsoft Entra ID through Conditional Access, Entitlement Management, and just-in-time (JIT) privileged access models.
- Review network diagrams and proposed connectivity changes, provide security input on segmentation and sensitive data flows, and work with IT and SRE teams to address identified concerns.
- Administer Zero Trust network access and edge security tooling to secure access to corporate and cloud resources.
- Hands-on management of broader security solutions across the organization: SIEM, DLP, E/XDR, vulnerability management.
- Monitor security alerts, respond to and escalate incidents, and participate in the incident response on-call rotation.
- Conduct threat analysis, vulnerability assessments, and risk evaluations; document findings, manage mitigation, and report status to leadership.
- Develop queries, scripts, integrations, and automated workflows that improve cloud security operations.
- Collaborate with development teams to ensure security is continuously integrated into the SDLC and CI/CD pipeline.
- Conduct periodic cloud configuration and access reviews to ensure compliance with security standards.
- Participate in audits and assessments, supporting governance, risk management, and compliance (GRC) efforts.
Additional Skills- Familiarity with GitOps tooling (Argo, Flux) for secure deployment in Kubernetes environments.
- Network or Systems Engineering background a huge plus.
- Familiarity with programming/scripting languages a plus.
- Passion for continuous learning and professional development, with a commitment to staying updated and trained on the latest trends and technologies.
- Eagerness to engage in new challenges and adapt quickly.
- Strong work ethic and drive to take ownership of projects and see them through to completion.
- Strong collaboration skills, able to work effectively with cross functional teams.
Benefits- Competitive salary - $110,000-$150,000
- Employer sponsored health, dental, vision, life, and disability insurance
- Retirement plan with company contribution
- Annual company profit sharing
- Personal development/training budget
- Open, collaborative work environment
- Extensive 2-week onboarding plan
- Comprehensive mentorship program
9/2/2026