Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
TherapyNotes, LLC

Cyber Security Engineer – Application Security

TherapyNotes, LLC

. Own application security across the SDLC and CI/CD pipeline .

Posted 10/7/2026full-timeRemote • Pennsylvania • United StatesMid-LevelSenior💰 $110,000 - $150,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in application security across the SDLC and CI/CD pipeline, with a strong focus on secure coding practices, vulnerability management, and compliance with HIPAA, HITECH, and HITRUST standards. Proficient in utilizing tools such as SAST, DAST, and GitHub Advanced Security to enhance security measures and mitigate risks.

Highest-signal resume keywords
Application SecurityCI/CD Pipeline SecuritySAST/DAST ToolsVulnerability ManagementHIPAA Compliance

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Application SecurityCI/CD Pipeline SecuritySASTDASTVulnerability ManagementTerraform Security ReviewAPI SecurityCloud SecurityZero Trust ArchitectureInfrastructure-as-Code
Soft Skills
CollaborationProblem-SolvingCommunication
Tools & Technologies
GitHub Advanced SecuritySIEMEDR/XDRDLP PlatformsGitHub Actions
Certifications & Qualifications
GWAPTOSWEGPENAzure Security CertificationAWS Security CertificationCISSPHCISPP
Industry Keywords
HIPAAHITECHHITRUSTHealthcare Data StandardsHL7

Tech Stack

Tools & technologies
AWSAzureCloudSDLCTerraform

About the role

Key responsibilities & impact
  • Own application security across the SDLC and CI/CD pipeline
  • Collaborate with development teams to continuously integrate security into the SDLC and CI/CD pipeline
  • Enforce secure coding standards and best practices to protect customer data confidentiality, integrity, and availability
  • Perform security assessments, code reviews, and threat modeling
  • Own and operate GitHub Advanced Security, triaging code, secret, and dependency-scanning findings
  • Identify recurring vulnerability patterns and recommend broader fixes
  • Improve scanning coverage, configuration, and workflows
  • Secure CI/CD pipelines and GitHub Actions, including identities, runners, permissions, and secrets
  • Reduce software supply-chain risk through third-party action review, dependency controls, action pinning, and artifact provenance
  • Review Terraform and other infrastructure-as-code for security issues
  • Partner with IT platform teams on IaC scanning and secure deployment practices
  • Align application security measures with HIPAA, HITRUST, and HITECH and support regular audits
  • Collaborate with developers to remediate vulnerabilities and ensure effective patching or mitigation
  • Develop, deploy, and manage SAST, DAST, and vulnerability management tools
  • Support application security incident response, root-cause identification, and resolution strategies
  • Contribute to secure-coding awareness programs for development teams
  • Contribute to broader security engineering efforts including vulnerability management, incident response, and identity and access security

Requirements

What you’ll need
  • Bachelor's degree in information security, computer science, or related field preferred; equivalent experience considered
  • 5+ years in application security or security engineering
  • Demonstrated experience securing CI/CD pipelines and GitHub Actions, including SAST/DAST, code/secret/dependency-scanning triage, runner and workflow-permission security, and third-party action/supply-chain risk
  • Experience reviewing Terraform or other infrastructure-as-code for security misconfigurations
  • Working knowledge of SIEM, EDR/XDR, and DLP platforms, including deployment, tuning, and alert triage
  • Understanding of Zero Trust architecture principles and their application to application and identity access
  • Strong understanding of HIPAA, HITECH, and HITRUST and their impact on application security
  • Experience with API security, particularly integrations with other healthcare systems
  • Prior experience securing cloud environments; Azure preferred and AWS a plus
  • Willingness to participate in an incident response on-call rotation
  • Industry certifications such as GWAPT, OSWE, GPEN, or an Azure/AWS cloud security certification are ideal; CISSP or HCISPP a plus but not a substitute for hands-on tooling experience
  • Familiarity with HL7 or other healthcare data standards preferred

Benefits

Comp & perks
  • Employer sponsored health, dental, vision, life, and disability insurance
  • Retirement plan with company contribution
  • Annual company profit sharing
  • Personal development/training budget
  • Open, collaborative work environment
  • Extensive 2-week onboarding plan
  • Comprehensive mentorship program