Cybersecurity Specialist

Posted 1 hour ago
TMC: Therapy Management Corporation
Overview

1

JOB TITLE: CYBERSECURITY SPECIALIST

Company Overview

Therapy Management Corporation (TMC) strives to be the preferred therapy provider and

employer in all communities we serve. We make a positive difference by delivering

compassionate, superior care to all. Our passionate commitment to service excellence creates

loyal customers and cultivates the best working environment for our TMC family. Our success is

built on unwavering integrity, ethics, and an environment of innovation.

Description

The Cybersecurity Specialist is responsible for helping protect TMC's systems, applications, cloud

infrastructure, and sensitive data from security threats and vulnerabilities. This role combines

hands-on security operations, cloud security, vulnerability management, and compliance

monitoring with a focus on continuously improving TMC's overall security posture.

As a Cybersecurity Specialist, you are expected to support the organization and its technology

Through The Security Lifecycle

  • Understand the environment: Build a thorough understanding of TMC's applications,

infrastructure, users, security controls, regulatory requirements, and evolving threat

landscape.

  • Protect the environment: Implement, maintain, and improve security controls across

TMC's Azure environment, applications, identities, endpoints, and supporting technology

platforms.

  • Monitor and respond: Continuously monitor security systems and findings, investigate

potential threats and vulnerabilities, coordinate remediation, and assist with incident

response.

  • Maintain compliance: Ensure security controls remain effective and audit-ready by

maintaining security and compliance platforms, evidence, documentation, policies, and

remediation activities.

Responsibilities

  • Own the day-to-day administration, configuration, integration health, and continuous

improvement of TMC's security platforms, with particular responsibility for Vanta and

Aikido Security.

2

  • Manage Vanta control monitoring, automated tests, evidence collection, access reviews,

security findings, and audit-readiness activities.

  • Manage Aikido Security capabilities including application security scanning, dependency

analysis, secrets detection, infrastructure-as-code scanning, container security, and cloud

security posture monitoring.

  • Monitor and improve TMC's Microsoft Azure security posture, including identity and access

controls, resource configuration, logging, network protections, and cloud security controls.

  • Configure and maintain applicable Microsoft security technologies such as Microsoft

Defender for Cloud, Microsoft Entra ID, Azure Key Vault, Azure Policy, Azure Monitor, and

Microsoft Sentinel.

  • Review security findings and vulnerabilities, assess their severity and business risk,

prioritize remediation, and verify resolution.

  • Coordinate security remediation with development, DevSecOps, infrastructure, and other

technology teams.

  • Review identity and access controls to support least-privilege access, appropriate

authentication controls, privileged-access management, and secure application identities.

  • Monitor security alerts and events, investigate suspicious activity, escalate significant

threats, and participate in incident containment, remediation, root-cause analysis, and

post-incident improvement.

  • Support TMC's compliance with applicable security and healthcare standards, including

HIPAA, SOC 2, and HITRUST, by monitoring control effectiveness, identifying gaps, and

coordinating corrective actions.

  • Support internal and external audits by maintaining security evidence, responding to

findings, and ensuring corrective actions are tracked to completion.

  • Assist with third-party security reviews, vendor risk assessments, security questionnaires,

and other security-assurance activities as needed.

  • Develop and maintain security dashboards, reports, procedures, runbooks, and technical

documentation.

  • Automate repetitive security monitoring, reporting, evidence collection, and remediation

activities where appropriate using scripting, APIs, and platform integrations.

  • Collaborate with development, DevSecOps, infrastructure, compliance, and business

stakeholders to implement practical security improvements while minimizing unnecessary

operational friction.

3

  • Evaluate existing security controls and recommend improvements to technologies,

configurations, processes, and security practices.

  • Stay current with cybersecurity threats, vulnerabilities, Azure security capabilities,

regulatory requirements, and industry best practices.

Required Qualifications

  • Bachelor's degree or higher in Cybersecurity, Information Technology, Computer Science,

Information Systems, or a related field, or equivalent work experience.

  • 3+ years of hands-on experience in cybersecurity, security operations, cloud security,

information security, or a related technical security role.

  • Hands-on experience securing and monitoring Microsoft Azure environments.
  • Working knowledge of Microsoft cloud security technologies and concepts including

Microsoft Entra ID, Defender for Cloud, RBAC, Multi-Factor Authentication, Conditional

Access, Key Vault, Azure networking, logging, and monitoring.

  • Experience administering or supporting security compliance or GRC automation platforms

such as Vanta, or similar platforms. Direct Vanta experience is strongly preferred.

  • Experience administering or supporting application and vulnerability security platforms

such as Aikido Security, Snyk, GitHub Advanced Security, or comparable tools. Direct Aikido

Experience Is Strongly Preferred.

  • Practical experience with vulnerability management, including risk assessment,

prioritization, remediation coordination, and validation.

  • Understanding of application and cloud security concepts including SAST, SCA, secrets

detection, dependency vulnerabilities, infrastructure-as-code security, container security,

and cloud misconfiguration.

  • Working knowledge of identity and access management, least-privilege principles, zerotrust

concepts, and privileged-access management.

  • Experience investigating security alerts and participating in cybersecurity incident

response.

  • Understanding of security and compliance frameworks applicable to regulated

organizations, including HIPAA, SOC 2, HITRUST, ISO 42007, NIST, and CIS guidance.

  • Understanding of networking fundamentals including firewalls, DNS, TCP/IP, VPNs, virtual

networks, network security groups, and private endpoints.

  • Familiarity with SIEM technologies, security logging, threat detection, and log analysis.

4

  • Ability to use scripting or automation technologies such as PowerShell, Bash, Python, APIs,

or Microsoft Graph to improve security operations.

  • Strong analytical, troubleshooting, documentation, and communication skills.
  • Ability to effectively collaborate across development, DevSecOps, infrastructure,

compliance, leadership, and business teams.

  • Demonstrated ability to take ownership, work independently, and continuously improve

security processes.

  • Relevant security certifications such as CompTIA Security+, Microsoft AZ-500, SC-200, SC-

300, CISSP, or CCSP are preferred.

  • Organized, detail-oriented, and process- and improvement-minded

CULTURE FIT

The culture at TMC embraces those that demonstrate a deep passion for solving the problems of

healthcare with enthusiasm for building positive working relationships and winning as a team.

Creating a strong workplace culture has been one of our staples, which we believe encourages and

inspires employees to do their best. We also embrace an “All In” mindset and give back to our

communities through personal and company initiatives. Individuals in this role should embrace a

mindset of continuous improvement and be prepared to have some fun along the way!
Login to Apply Now

Recommended Jobs

Manager, Offensive Security

Posted 16 minutes ago

IT Security Analyst II

Posted 1 hour ago

Cyber Security Engineer

Posted 1 hour ago

API Security Engineer

Posted 1 hour ago