Senior Software Engineer, Security
Job description
About the Role
At Nex Health, we are actively deconstructing the analog foundations of healthcare to construct a modern, digital infrastructure. Our mission is to accelerate innovation in healthcare by connecting patients, providers, and developers through a unified platform. We are building the essential infrastructure layer that bridges thousands of fragmented, on-premise, and closed EHR systems into a single, cohesive ecosystem that powers software, APIs, payments, and patient experiences. As a health-tech company safeguarding sensitive patient data, we operate with the highest levels of responsibility and trust. The Senior Software Engineer, Security role is critical to this effort. You will not be a passive compliance officer; you will be a hands-on engineer owning application security across our core platforms, including APIs, integrations, payments infrastructure, and the developer ecosystem built on our Synchronizer. You will embed security into the DNA of how we build, working directly alongside product teams from the earliest design stages to ensure data protection is built-in, not bolted-on.
What You'll Do
Your primary responsibility is to design and build secure systems that protect patient data and enable trusted interactions across the healthcare ecosystem. You will own application security for our APIs, EHR integrations, payments infrastructure, and SaaS products. This is a production-focused role where you will write code, design resilient security architectures, and review critical designs before implementation. You will lead threat modeling and security design reviews for new features, ensuring risk is considered early and continuously integrated into the development lifecycle. You will actively identify and remediate vulnerabilities in application code, dependencies, and infrastructure across both production and pre-production environments. A key focus will be improving authentication, authorization, and access control systems, including OAuth flows, JWT implementation, and RBAC across our platform. You will also integrate and maintain security tooling within our CI/CD pipelines, such as SAST, DAST, and dependency scanning, to enable fast and safe deployments. Furthermore, you will contribute to the creation of secure coding standards, internal libraries, and developer-facing security frameworks that guide best practices across the entire organization. Finally, you will support HIPAA and SOC 2 compliance efforts through secure system design, rigorous documentation, and verifiable control implementations, while helping raise the security bar across the engineering organization through code reviews, education, and pairing with developers.
Requirements
To succeed in this role, you must bring a strong foundation in software engineering and application security. We require 5+ years of software engineering experience, with 1-3+ years specifically focused on application or product security within production systems. You should demonstrate hands-on experience building and securing backend systems using languages such as Python, Go, Java, or similar, operating effectively in cloud environments. A solid understanding of common web application vulnerabilities and their mitigations, aligned with the OWASP Top 10 and related industry guidance, is essential. You must have practical experience securing APIs and implementing authentication and authorization mechanisms like OAuth 2.0, JWT, and RBAC at scale. Experience operating within cloud platforms, specifically AWS and Google Cloud, and leveraging their security and compliance capabilities is required. Familiarity with security tooling and workflows - including SAST, DAST, interactive application security testing, and dependency scanning approaches - is necessary. A Bachelor's degree in Computer Science, Engineering, or equivalent practical experience that demonstrates deep technical competence is required. Above all, we seek a candidate who maintains a strong commitment to delivering secure software under tight constraints while balancing delivery speed and effective risk management.
Compensation
Nex Health offers a competitive compensation package. Actual salaries will vary depending on factors including but not limited to location, experience, and performance. The range listed represents the base salary component of Nex Health's total compensation package for employees in this role. Other benefits may include stock options, an unlimited paid time off policy, and up to 100% coverage on medical, vision, and dental insurance.