1
JOB TITLE: CYBERSECURITY SPECIALIST
COMPANY OVERVIEW
Therapy Management Corporation (TMC) strives to be the preferred therapy provider and
employer in all communities we serve. We make a positive difference by delivering
compassionate, superior care to all. Our passionate commitment to service excellence creates
loyal customers and cultivates the best working environment for our TMC family. Our success is
built on unwavering integrity, ethics, and an environment of innovation.
DESCRIPTION
The Cybersecurity Specialist is responsible for helping protect TMC's systems, applications, cloud
infrastructure, and sensitive data from security threats and vulnerabilities. This role combines
hands-on security operations, cloud security, vulnerability management, and compliance
monitoring with a focus on continuously improving TMC's overall security posture.
As a Cybersecurity Specialist, you are expected to support the organization and its technology
through the security lifecycle:
➢ Understand the environment: Build a thorough understanding of TMC's applications,
infrastructure, users, security controls, regulatory requirements, and evolving threat
landscape.
➢ Protect the environment: Implement, maintain, and improve security controls across
TMC's Azure environment, applications, identities, endpoints, and supporting technology
platforms.
➢ Monitor and respond: Continuously monitor security systems and findings, investigate
potential threats and vulnerabilities, coordinate remediation, and assist with incident
response.
➢ Maintain compliance: Ensure security controls remain effective and audit-ready by
maintaining security and compliance platforms, evidence, documentation, policies, and
remediation activities.
RESPONSIBILITIES
Own the day-to-day administration, configuration, integration health, and continuous
improvement of TMC's security platforms, with particular responsibility for Vanta and
Aikido Security.
2
- Manage Vanta control monitoring, automated tests, evidence collection, access reviews,
security findings, and audit-readiness activities.
- Manage Aikido Security capabilities including application security scanning, dependency
analysis, secrets detection, infrastructure-as-code scanning, container security, and cloud
security posture monitoring.
- Monitor and improve TMC's Microsoft Azure security posture, including identity and access
controls, resource configuration, logging, network protections, and cloud security controls.
- Configure and maintain applicable Microsoft security technologies such as Microsoft
Defender for Cloud, Microsoft Entra ID, Azure Key Vault, Azure Policy, Azure Monitor, and
Microsoft Sentinel.
- Review security findings and vulnerabilities, assess their severity and business risk,
prioritize remediation, and verify resolution.
- Coordinate security remediation with development, DevSecOps, infrastructure, and other
technology teams.
- Review identity and access controls to support least-privilege access, appropriate
authentication controls, privileged-access management, and secure application identities.
- Monitor security alerts and events, investigate suspicious activity, escalate significant
threats, and participate in incident containment, remediation, root-cause analysis, and
post-incident improvement.
- Support TMC's compliance with applicable security and healthcare standards, including
HIPAA, SOC 2, and HITRUST, by monitoring control effectiveness, identifying gaps, and
coordinating corrective actions.
- Support internal and external audits by maintaining security evidence, responding to
findings, and ensuring corrective actions are tracked to completion.
- Assist with third-party security reviews, vendor risk assessments, security questionnaires,
and other security-assurance activities as needed.
- Develop and maintain security dashboards, reports, procedures, runbooks, and technical
documentation.
- Automate repetitive security monitoring, reporting, evidence collection, and remediation
activities where appropriate using scripting, APIs, and platform integrations.
- Collaborate with development, DevSecOps, infrastructure, compliance, and business
stakeholders to implement practical security improvements while minimizing unnecessary
operational friction.
3
- Evaluate existing security controls and recommend improvements to technologies,
configurations, processes, and security practices.
- Stay current with cybersecurity threats, vulnerabilities, Azure security capabilities,
regulatory requirements, and industry best practices.
REQUIRED QUALIFICATIONS
Bachelor's degree or higher in Cybersecurity, Information Technology, Computer Science,
Information Systems, or a related field, or equivalent work experience.
- 3+ years of hands-on experience in cybersecurity, security operations, cloud security,
information security, or a related technical security role.
- Hands-on experience securing and monitoring Microsoft Azure environments.
- Working knowledge of Microsoft cloud security technologies and concepts including
Microsoft Entra ID, Defender for Cloud, RBAC, Multi-Factor Authentication, Conditional
Access, Key Vault, Azure networking, logging, and monitoring.
- Experience administering or supporting security compliance or GRC automation platforms
such as Vanta, or similar platforms. Direct Vanta experience is strongly preferred.
- Experience administering or supporting application and vulnerability security platforms
such as Aikido Security, Snyk, GitHub Advanced Security, or comparable tools. Direct Aikido
experience is strongly preferred.
- Practical experience with vulnerability management, including risk assessment,
prioritization, remediation coordination, and validation.
- Understanding of application and cloud security concepts including SAST, SCA, secrets
detection, dependency vulnerabilities, infrastructure-as-code security, container security,
and cloud misconfiguration.
- Working knowledge of identity and access management, least-privilege principles, zerotrust
concepts, and privileged-access management.
- Experience investigating security alerts and participating in cybersecurity incident
response.
- Understanding of security and compliance frameworks applicable to regulated
organizations, including HIPAA, SOC 2, HITRUST, ISO 42007, NIST, and CIS guidance.
- Understanding of networking fundamentals including firewalls, DNS, TCP/IP, VPNs, virtual
networks, network security groups, and private endpoints.
- Familiarity with SIEM technologies, security logging, threat detection, and log analysis.
4
- Ability to use scripting or automation technologies such as PowerShell, Bash, Python, APIs,
or Microsoft Graph to improve security operations.
- Strong analytical, troubleshooting, documentation, and communication skills.
- Ability to effectively collaborate across development, DevSecOps, infrastructure,
compliance, leadership, and business teams.
- Demonstrated ability to take ownership, work independently, and continuously improve
security processes.
- Relevant security certifications such as CompTIA Security+, Microsoft AZ-500, SC-200, SC-
300, CISSP, or CCSP are preferred.
- Organized, detail-oriented, and process- and improvement-minded
CULTURE FIT
The culture at TMC embraces those that demonstrate a deep passion for solving the problems of
healthcare with enthusiasm for building positive working relationships and winning as a team.
Creating a strong workplace culture has been one of our staples, which we believe encourages and
inspires employees to do their best. We also embrace an “All In” mindset and give back to our
communities through personal and company initiatives. Individuals in this role should embrace a
mindset of continuous improvement and be prepared to have some fun along the way!