Cyber Security Engineer (Application Security)

TherapyNotes.com

$110K — $150K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered.
  • 5+ years in application security or security engineering.
  • Experience securing CI/CD pipelines and GitHub Actions, including SAST/DAST and dependency scanning.
  • Proficiency reviewing Terraform or other infrastructure-as-code for security misconfigurations.
  • Knowledge of SIEM, EDR/XDR, and DLP platforms for deployment and alert management.
  • Familiarity with Zero Trust architecture in application and identity access contexts.
  • Understanding of healthcare regulations (HIPAA, HITECH, HITRUST) and their impact on security.

Responsibilities

  • Collaborate with development teams to integrate security into the SDLC and CI/CD pipeline.
  • Enforce secure coding standards to protect customer data.
  • Conduct security assessments, code reviews, and threat modeling to identify vulnerabilities.
  • Manage GitHub Advanced Security, triaging various security findings and recommending fixes.
  • Secure CI/CD pipelines by managing identities, permissions, and reducing supply chain risks.
  • Review infrastructure-as-code for security issues while partnering with IT teams.
  • Align application security measures with healthcare regulations and support audits.
  • Support incident response activities to address security incidents and their root causes.

Benefits

  • Employer sponsored health, dental, vision, life, and disability insurance
  • Retirement plan with company contribution
  • Annual company profit sharing
  • Personal development/training budget
  • Open, collaborative work environment
  • Extensive 2-week onboarding plan
  • Comprehensive mentorship program
Full Job Description
The Position

TherapyNotes is seeking an experienced, hands-on Cyber Security Engineer to own application security across our SDLC and CI/CD pipeline. The right candidate brings deep expertise securing CI/CD pipelines, code and dependency scanning workflows, and infrastructure-as-code, and is comfortable working in a healthcare-regulated environment (HIPAA, HITRUST, HITECH). This role also contributes to broader security engineering efforts - vulnerability management, incident response, and identity and access security - as part of a small, collaborative security team.

Required Skills and Experience
  • Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered.
  • 5+ years in application security or security engineering.
  • Demonstrated experience securing CI/CD pipelines and GitHub Actions - including SAST/DAST, code/secret/dependency-scanning triage (e.g., GitHub Advanced Security, Snyk), runner and workflow-permission security, and third-party action/supply-chain risk.
  • Experience reviewing Terraform or other infrastructure-as-code for security misconfigurations.
  • Working knowledge of SIEM, EDR/XDR, and DLP platforms - deployment, tuning, and alert triage.
  • Understanding of Zero Trust architecture principles and how they apply to application and identity access.
  • Strong understanding of healthcare regulations (HIPAA, HITECH, HITRUST) and their impact on application security.
  • Experience with API security, particularly integrations with other healthcare systems; familiarity with HL7 or other healthcare data standards preferred.
  • Prior experience securing cloud environments (Azure preferred, AWS a plus).
  • Willingness to participate in an incident response on-call rotation.
  • Industry certifications such as GWAPT, OSWE, GPEN, or a cloud security certification (Azure/AWS) are ideal; CISSP or HCISPP a plus but not a substitute for hands-on tooling experience.

Application Security Responsibilities
  • Collaborate with developmental teams to ensure security is continuously integrated into the Software Development Lifecycle (SDLC) and CI/CD pipeline.
  • Enforce secure coding standards and best practices to minimize vulnerabilities and to protect the confidentiality, integrity, and availability of our customer's data.
  • Perform in-depth security assessments, code reviews, and threat modeling on applications to identify potential vulnerabilities and risks.
  • Own and operate GitHub Advanced Security - triage code, secret, and dependency-scanning findings, identify recurring vulnerability patterns and recommend broader fixes, and continuously improve scanning coverage, configuration, and workflows.
  • Secure CI/CD pipelines and GitHub Actions - identities, runners, permissions, and secrets - and reduce software supply chain risk through third-party action review, dependency controls, action pinning, and artifact provenance.
  • Review Terraform and other infrastructure-as-code for security issues, partnering with IT platform teams on IaC scanning and secure deployment practices.
  • Ensure application security measures align with healthcare regulations and standards (e.g., HIPAA, HITRUST, and HITECH) and support regular audits.
  • Collaborate with developers to remediate vulnerabilities, providing actionable guidance and ensuring effective patching or mitigation measures.
  • Develop, deploy, and manage security tools and technologies (e.g., SAST, DAST, vulnerability management systems) to automate security testing and scanning processes.
  • Support application security incident response activities, identifying the root cause of security incidents and contributing to resolution strategies.
  • Contribute to security awareness programs for the development teams, focusing on secure coding practices and proactive security measures.

Additional Skills
  • Passion for continuous learning and professional development, with a commitment to staying updated and trained on the latest trends and technologies.
  • Eagerness to engage in new challenges and adapt quickly.
  • Strong work ethic and drive to take ownership of projects and see them through to completion.
  • Strong collaboration skills, able to work effectively with cross functional teams.

Benefits
  • Competitive salary - $110,000-$150,000
  • Employer sponsored health, dental, vision, life, and disability insurance
  • Retirement plan with company contribution
  • Annual company profit sharing
  • Personal development/training budget
  • Open, collaborative work environment
  • Extensive 2-week onboarding plan
  • Comprehensive mentorship program


9/2/2026

Similar Jobs

More Jobs at TherapyNotes.com

More Healthcare Jobs

Find similar Cyber Security Engineer (Application Security) jobs: