HimalayasHimalayas logo
TherapyNotes.comTH

GRC Engineer

TherapyNotes, LLC offers a comprehensive online practice management system tailored for mental health practitioners, featuring robust notes, scheduling, billing, and telehealth capabilities.

TherapyNotes.com

Employee count: 201-500

Salary: 100k-140k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

About Us

TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.

We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!

About The Position

TherapyNotes is seeking a GRC Engineer who combines strong foundational GRC expertise with the ability to design and implement scalable, automated solutions. This role is responsible for both executing core GRC functions (e.g., risk assessments, policy management, third-party risk) and transforming those processes through engineering and automation.

The ideal candidate understands how GRC work is performed today—and has the technical skills to improve, scale, and modernize it.

What You'll Do

Core GRC Operations (Hands-On Execution)

  • Conduct third-party risk assessments (TPRM), including vendor reviews, security questionnaires, and risk evaluations
  • Maintain and update security policies, standards, and procedures
  • Support compliance initiatives across frameworks (SOC 2, ISO 27001, HIPAA, NIST, etc.)
  • Perform internal risk assessments, control testing, and gap analyses

GRC Engineering & Automation

  • Identify manual, repetitive GRC processes and design automated solutions
  • Build and maintain automated evidence collection (via APIs, scripts, and integrations)
  • Implement continuous control monitoring (CCM) to replace point-in-time audits
  • Translate compliance requirements into technical controls and system configurations
  • Validate control effectiveness through automated testing and monitoring
  • Enable real-time or near-real-time risk visibility through dashboards and reporting systems
  • Work with Security Engineering to continuously audit configurations and remediate drift programmatically
  • Build scalable workflows for vendor risk assessments, re-assessments and tracking
  • Integrate vendor data into centralized risk systems
  • Automate intake, review, and monitoring processes for third-party security posture
  • Develop self-service audit evidence systems and dashboards
  • Partner with auditors to provide API-driven or system-generated evidence

What We're Looking For

  • Bachelor’s degree in Computer Science, Engineering, or related field (or equivalent experience)
  • 3–6+ years in security engineering, GRC, GRC engineering, or cloud security roles
  • Strong experience with scripting/programming (Python, Go, or similar)
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP)
  • Familiarity with Infrastructure as Code (Terraform, CloudFormation, etc.)
  • Deep understanding of security controls and how they map to compliance frameworks
  • Experience integrating APIs and building automation pipelines

Bonus Points

  • Experience with policy-as-code tools
  • Experience with GRC automation platforms
  • Familiarity with SIEM, SOAR, and security telemetry systems
  • Experience building internal tools or platforms for compliance and risk management
  • Certifications such as CISSP, CISM, CRISC, or cloud security certifications

What We Offer

  • Competitive salary - $100,000-$140,000
  • Employer sponsored health, dental, vision, life, and disability insurance
  • Retirement plan with company contribution
  • Annual company profit sharing
  • Personal development/training budget
  • Open, collaborative work environment
  • Extensive 2-week onboarding plan
  • Comprehensive mentorship program

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 100k-140k USD

Education

Bachelor degree

Experience

3 years minimum

Experience accepted in place of education

Location requirements

Hiring timezones

United States +/- 0 hours

About TherapyNotes.com

Learn more about TherapyNotes.com and their company culture.

View company profile

TherapyNotes® is at the forefront of revolutionizing practice management for behavioral health professionals. Through groundbreaking technology, the company provides a comprehensive, secure, and intuitive online system designed to streamline the complex administrative and clinical workflows of mental health practitioners. TherapyNotes® was born out of a collaboration between Dr. Debra Pliner, a clinical psychologist, and Brad Pliner, a web technologies expert. They identified a critical need for an electronic health record (EHR) and practice management solution specifically tailored to the unique demands of the mental health field. Launched in 2010, TherapyNotes® has rapidly evolved into a market leader, empowering thousands of psychologists, therapists, counselors, social workers, and psychiatrists across the nation to manage their practices with greater efficiency and focus more on client care. The platform's innovative approach centers around a robust, form-filled notes system, a significant advancement over generic free-form text areas often found in other systems. This design greatly accelerates data entry and note-writing, ensuring compliance and accuracy.

The technological innovation at TherapyNotes® extends beyond note-taking. The platform integrates patient scheduling, medical records, billing, and electronic claims into a seamless software-as-a-service (SaaS) solution. This holistic approach addresses the multifaceted needs of modern behavioral health practices, from solo practitioners to large group practices and institutions. TherapyNotes® continually invests in enhancing its offerings, regularly launching new features such as secure messaging, telehealth capabilities, patient portals, and outcome measures. The system's powerful to-do list automatically guides clinicians on necessary actions, such as pending notes, follow-ups, and treatment plan updates, ensuring that critical tasks are not overlooked. Security and HIPAA compliance are paramount, with data encrypted, secured, and regularly backed up. By leveraging technologies like React and Erlang, TherapyNotes® demonstrates a commitment to utilizing modern, scalable, and reliable technological foundations to support the vital work of mental health professionals, ultimately contributing to improved patient outcomes and practice sustainability.

Claim this profileTherapyNotes.com logoTH

TherapyNotes.com

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

3 remote jobs at TherapyNotes.com

Explore the variety of open remote roles at TherapyNotes.com, offering flexible work options across multiple disciplines and skill levels.

View all jobs at TherapyNotes.com

Remote companies like TherapyNotes.com

Find your next opportunity by exploring profiles of companies that are similar to TherapyNotes.com. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan