> Markdown version of [/jobs/ext/2172582-software-engineer](https://www.wearedevelopers.com/jobs/ext/2172582-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer - **Company:** NEXHEALTH, INC. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $165,000.0 - $230,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, User Authentication, Software as a Service, Cloud Computing, Code Review, Cyber Security, Computer Programming, Continuous Delivery, Continuous Integration, Customer Data Management, Python (Programming Language), OAuth, Open Web Application Security, Role-Based Access Control, JSON Web Token, Secure Coding, Software Engineering, Systems Architecture, Systems Integration, Trusted Systems, Scripting, Google Cloud, Cloud Platform System, Software Security, Electronic Medical Records, Backend, Juniper, Build Management, Information Technology, Software Coding, Multiplatform, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** August 21, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-software-engineer-security-san-francisco-ca--d3972fe4-85fa-4a2e-a708-d10e2f8e23c0 ## About the Role * 5+ years of software engineering experience, with 1-3+ years focused on application or product security * Experience building and securing backend systems in Python, Go, Java, or similar languages * Solid understanding of common vulnerabilities and mitigations (OWASP Top 10 and beyond) * Hands-on experience securing APIs and implementing authentication/authorization systems (OAuth 2.0, JWT, RBAC) * Experience working in cloud environments - we run on AWS and Google Cloud * Familiarity with security tooling: SAST, DAST, dependency scanning * Bachelor's degree in Computer Science, Engineering, or equivalent practical experience, Access Authorization, Access Control, Amazon Web Services (AWS), Application Programming Interface (API), Applications Security, Authentication, Cloud Computing, Code Reviews, Coding Standards, Computer Programming, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Customer/Client Research, Diversity, Diving, Documentation, Ecosystems, Embedded Systems, Food Delivery, Funding, Go Programming Language (Golang), HIPAA (Health Insurance Portability and Accountability Act), Healthcare, Identify Issues, Java, Juniper Networks M-Series, Leadership, Machine Tool, Medical Record System, Multiplatform/Cross-Platform, OAuth, Product Engineering, Python Programming/Scripting Language, Secure Coding, Security Architecture, Security Design, Software Engineering, Software as a Service (SaaS), System Architecture, Threat Modeling ## Description We're hiring a Senior Software Engineer, Security to own application security across our product platform - APIs, integrations, payments infrastructure, and the developer ecosystem built on top of our Synchronizer. This is a hands-on engineering role, not a compliance or audit function. You'll write code, design secure systems, review architecture, and embed security into the way we build - working directly alongside product engineering teams from the earliest stages of design. Data is at the center of everything we do, which means the security bar here is high and the work is meaningful. Moreover as a health tech company, we have the highest levels of responsibility towards safeguarding patient and customer data across all the facilities and services NexHealth provides. You'll report to engineering leadership and work closely with both product and platform teams. What You'll Do * Design and build secure systems across our APIs, EHR integrations, payments infrastructure, and SaaS products * Lead threat modeling and security design reviews for new features - embedded in the development process, not bolted on at the end * Identify and remediate vulnerabilities in application code, dependencies, and infrastructure * Improve authentication, authorization, and access control systems across our platform (OAuth, RBAC, service-to-service auth) * Integrate and maintain security tooling in our CI/CD pipelines - SAST, DAST, dependency scanning * Contribute to secure coding standards, internal libraries, and developer-facing security frameworks * Support HIPAA and SOC 2 compliance through strong system design and documentation * Help raise the security bar across the engineering org through code reviews, education, and pairing with developers ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers)