Software Developer

Pacific Health Group
United States
3 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) PHP (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services ASC X12 Standards Application Integration Architecture Business Logic Software Applications Application Performance Management Application Services
+102 more
Audit Trail User Authentication Automation of Tests Unit Testing Microsoft Azure Backup Devices Bug Tracking Systems Software Bug Management Business Systems C Sharp (Programming Language) Software as a Service Cloud Computing Configuration Management Software Documentation Code Review Cyber Security Information Systems Databases Continuous Delivery Continuous Integration Corona (Software Development Kit) Custom Software Data Validation Data Integrity Data Security Data Synchronization Data Systems Relational Databases Cursor (Graphical User Interface Elements) Database Queries Software Debugging Linux Programming Tools Domain Name System (DNS) Middleware Github Design of User Interfaces Medical Software Human-Computer Interaction Systems Analysis Interoperability JSON Python (Programming Language) Key Management Microsoft Software Node.Js OAuth Performance Tuning Software Prototyping Rapid Prototyping Process Regression Testing Release Management Reliability Engineering E2e Testing Ruby Runbook Secure Coding Server Administration Software Deployment Software Engineering Software Requirements Analysis SQL Databases Data Streaming Systems Integration TypeScript Software Vulnerability Management Web Applications Web Hosting Services Workflow Management Systems Privacy Controls Data Logging Scripting Transport Layer Security Google Cloud Enterprise Software Applications Fast Healthcare Interoperability Resources Software Security Zapier Reliability of Systems Technical Debt Electronic Medical Records Backend Git Server Migration Containerization Integration Tests Kubernetes Information Technology Maintaining Code Health Level Seven International Integration Frameworks Nintex Tools for Reporting Gsuite Front End Software Development Api Design Restful APIs Code Restructuring Webhooks Software Version Control Docker Server Operating Systems & Platforms

Job description

The Software Developer works directly alongside the executive team to design, develop, enhance, modify, deploy, and maintain software applications that support Pacific Health Group’s clinical, operational, administrative, and growth initiatives. The role combines modern software development with AI-assisted “vibe coding” to move rapidly from business concept to functional prototype and from prototype to secure, maintainable production software.

A core responsibility is taking applications created or accelerated through platforms such as Lovable and other AI-assisted development environments, auditing and refining the generated code, connecting the codebase to company-controlled repositories, migrating it to production infrastructure, and completing the configuration, security hardening, integration, and code modifications required for dependable operation. The Developer also develops APIs and third-party integrations, supports PHI/HIPAA-sensitive systems, and ensures that speed of development does not compromise security, reliability, maintainability, or data integrity.

KEY RESPONSIBILITIES

  1. AI-Assisted / Vibe Coding and Application Development

Builds and evolves software by combining rapid AI-assisted prototyping with professional software development practices and full ownership of the resulting codebase.

Activities:

  • Partner with executive leadership to translate ideas, operational pain points, workflows, and product concepts into functional software requirements and technical solutions.

  • Use AI-assisted and vibe-coding platforms such as Lovable and comparable tools to rapidly build proofs of concept, internal applications, portals, dashboards, workflow tools, and production features.

  • Review, debug, refactor, and strengthen AI-generated code rather than treating generated output as production-ready by default.

  • Develop and modify front-end, back-end, database, authentication, business-logic, and integration components as required by the application.

  • Maintain source code in company-approved version control, using clear branching, commits, pull requests, code review, and release practices.

  • Identify technical debt, duplicated logic, unsupported dependencies, fragile components, and architectural issues introduced during rapid prototyping and correct them before or during production deployment.

  • Document significant third-party libraries, AI-assisted code sources, dependencies, and repository components to support maintainability, security review, and traceability.

Outputs:

  • Rapidly developed applications that transition from concept to stable, maintainable, production-ready software with clear source-code ownership and documentation.
  1. Production Deployment, Server Migration, and Infrastructure

Owns the technical transition from development environments and AI application builders into secure, controlled production infrastructure.

Activities:

  • Export, migrate, and adapt application code from AI-assisted platforms into GitHub or other company-approved repositories and deployment environments.

  • Configure production and staging environments, including Linux/server settings, runtime dependencies, environment variables, databases, storage, domains, DNS, reverse proxies, and application services.

  • Configure, renew, and troubleshoot SSL/TLS certificates and enforce encrypted connections for production applications and APIs.

  • Implement repeatable deployment practices using CI/CD, containerization, infrastructure scripts, or other appropriate release mechanisms.

  • Establish logging, monitoring, alerting, backups, rollback procedures, and recovery practices appropriate to each application.

  • Troubleshoot deployment failures, server-side errors, performance issues, dependency conflicts, and environment-specific defects.

  • Support capacity planning, performance tuning, and architecture changes as internal applications grow in users, data volume, or complexity.

Outputs:

  • Stable staging and production environments with documented configurations, secure deployment practices, reliable rollback paths, and operational visibility.
  1. API Development, Integrations, and Data Interoperability

Connects Pacific Health Group applications and business platforms through secure, reliable application programming interfaces and integration patterns.

Activities:

  • Design, build, document, test, and maintain RESTful APIs, webhooks, middleware, background jobs, and integration services.

  • Integrate third-party applications and internal systems including CRM, EMR/EHR, billing, communications, Google Workspace, workflow platforms, analytics tools, and other enterprise applications.

  • Implement authentication and authorization patterns such as OAuth, API keys, service accounts, role-based access, and token-based access where appropriate.

  • Create data mappings, transformations, validation rules, retry logic, rate-limit handling, error handling, and reconciliation processes for multi-system data exchanges.

  • Diagnose and resolve integration conflicts involving vendor APIs, native platform limitations, version changes, payload structures, permissions, or data synchronization.

  • Work with the Business Systems Analyst to convert process maps, functional requirements, field mappings, and business rules into reliable technical implementations.

  • Maintain technical documentation for endpoints, credentials handling, dependencies, data flows, integration logic, and support procedures.

Outputs:

  • Reliable, documented system integrations that reduce manual work, maintain data integrity, and support scalable operations across departments.
  1. Security, HIPAA / PHI Safeguards, and Code Governance

Builds healthcare applications with security and privacy controls embedded into design, development, deployment, and maintenance.

Activities:

  • Apply secure coding practices to applications that create, receive, maintain, or transmit Protected Health Information (PHI) or other sensitive company data.

  • Implement appropriate access controls, least-privilege permissions, secure authentication, session controls, audit logging, encryption in transit, encryption at rest where applicable, and secure secrets management.

  • Prevent hardcoded credentials, exposed API keys, insecure storage, excessive permissions, vulnerable dependencies, and unprotected administrative functions.

  • Perform code and dependency reviews for security weaknesses, outdated packages, known vulnerabilities, unsafe configurations, and inappropriate data exposure.

  • Collaborate with Compliance, IT, vendors, and leadership to support HIPAA-related technical safeguards, internal security reviews, remediation plans, and audit-readiness documentation.

  • Separate development, testing, and production environments and ensure PHI is not introduced into non-approved environments or tools.

  • Maintain traceability for major code, configuration, integration, and infrastructure changes affecting regulated or sensitive systems.

Outputs:

  • Production applications and integrations that are security-conscious, audit-ready, appropriately access-controlled, and designed to protect PHI and confidential information.
  1. Testing, Quality, Reliability, and Technical Support

Ensures software works correctly across expected workflows and remains maintainable after launch.

Activities:

  • Create and execute unit, integration, regression, API, security, and end-to-end tests appropriate to each application.

  • Support user acceptance testing (UAT), reproduce reported defects, identify root causes, and implement durable fixes.

  • Validate edge cases, error states, permission scenarios, data quality, integration failures, and recovery behavior rather than testing only the primary workflow.

  • Review application performance, database queries, API latency, page load time, background processes, and resource usage and optimize as needed.

  • Implement application observability through logs, alerts, health checks, and actionable monitoring.

  • Respond to production defects and incidents, document root cause, and implement preventive changes where recurring problems are identified.

  • Maintain technical runbooks, architecture notes, deployment documentation, and support instructions for critical systems.

Outputs:

  • Lower defect rates, faster troubleshooting, improved software reliability, and repeatable technical support for business-critical applications.
  1. Executive and Cross-Functional Solution Development

Serves as a hands-on technical partner to leadership and departments when new capabilities, system improvements, or custom software are required.

Activities:

  • Work closely with the executive team to evaluate feasibility, technical tradeoffs, implementation paths, risks, timelines, and build-versus-buy decisions.

  • Collaborate with the Business Systems Analyst to review process pain points, solution maps, automation opportunities, and system requirements before development begins.

  • Provide technical options when a requested approach is not secure, maintainable, cost-effective, or feasible and recommend practical alternatives.

  • Participate in discovery sessions with operational teams to understand real-world workflows, exceptions, user roles, and system dependencies.

  • Coordinate with software vendors and third-party technical teams when integrations, migrations, or platform limitations require joint troubleshooting.

  • Communicate technical issues in clear business language and maintain transparency on risks, blockers, dependencies, and production readiness.

  • Continuously evaluate emerging AI development tools, frameworks, infrastructure approaches, and integration technologies that can improve delivery speed or system quality.

Outputs:

  • Faster executive decision-making, stronger alignment between business requirements and technical implementation, and scalable solutions that address root operational problems., (To be used for application development, technical delivery expectations, production readiness, and ongoing software governance)

PHASE 1. Discovery, Requirements, and Rapid Prototype

  • Clarify the business problem, users, workflows, permissions, data requirements, integrations, exceptions, and expected outcomes.

  • Build or refine a rapid proof of concept using AI-assisted/vibe-coding tools where appropriate.

  • Identify systems of record, PHI exposure, vendor dependencies, technical constraints, and integration requirements.

  • Establish acceptance criteria and define what is required before the application can move beyond prototype status.

Deliverables:

  • Functional prototype or technical concept

  • Initial architecture and integration map

  • Requirements and acceptance criteria

  • Preliminary security and PHI considerations

PHASE 2. Code Audit, Architecture, and Production Hardening

  • Move the codebase into company-controlled version control and establish a maintainable project structure.

  • Review AI-generated code, dependencies, data models, authentication, business logic, and error handling.

  • Refactor fragile or duplicated code and remove unsafe shortcuts, exposed secrets, insecure defaults, and unsupported dependencies.

  • Define deployment architecture, environments, release strategy, rollback path, and monitoring requirements.

Deliverables:

  • Reviewed and controlled code repository

  • Production architecture and deployment plan

  • Dependency and configuration inventory

  • Technical remediation backlog

PHASE 3. Integration, Security, and Compliance Buildout

  • Develop required APIs, middleware, webhooks, data mappings, and third-party integrations.

  • Implement authentication, authorization, audit logging, encryption, secrets management, validation, and other required security controls.

  • Configure staging and production infrastructure, databases, domains, DNS, certificates, backups, and environment-specific settings.

  • Validate that PHI and sensitive data are handled only through approved systems and approved technical paths.

Deliverables:

  • Integrated staging application

  • Security and configuration checklist

  • API/integration documentation

  • HIPAA/PHI technical safeguard documentation as applicable

PHASE 4. Testing, Deployment, and Go-Live

  • Complete functional, integration, regression, permission, performance, error-state, and security testing.

  • Support UAT with business owners and resolve blocking defects prior to production launch.

  • Deploy through a documented release process with backup, rollback, monitoring, and post-release validation.

  • Confirm production certificates, environment variables, integrations, logging, alerts, and access controls are operating as intended.

Deliverables:

  • UAT sign-off

  • Production release

  • Deployment and rollback record

  • Runbook and support documentation

PHASE 5. Monitoring, Maintenance, and Continuous Improvement

  • Monitor application health, logs, integration failures, performance, certificate status, and security findings.

  • Prioritize defects, enhancement requests, technical debt, dependency updates, and security remediation.

  • Conduct root cause analysis for recurring incidents and improve code, architecture, or workflows to prevent recurrence.

  • Continue using AI-assisted development to accelerate enhancements while maintaining code review, testing, security, and documentation standards.

Deliverables:

  • Maintenance backlog

  • Incident/root-cause records

  • Periodic security and dependency updates

  • Continuous release and improvement roadmap

EXPECTATIONS FOR SUCCESS

  • 100% of production application code maintained in company-approved version control with documented ownership and release history.

  • Production applications use valid SSL/TLS, secured credentials/secrets, appropriate access controls, and documented environment configurations.

  • AI-generated or rapidly prototyped code is reviewed, tested, and hardened before being treated as production-ready.

  • APIs and integrations include documented mappings, authentication, error handling, monitoring, and support procedures.

  • PHI-sensitive systems maintain appropriate technical safeguards, traceability, and audit-ready documentation.

  • Measurable reduction in development cycle time without increasing unresolved defects, security exposure, or support burden.

  • Clear technical communication with leadership regarding feasibility, risk, architecture, production readiness, and required remediation.

Requirements

  • 3+ years of professional software development, full-stack development, application development, or comparable hands-on experience.

  • Demonstrated ability to build and maintain production web applications using modern front-end and back-end technologies.

  • Strong working knowledge of JavaScript/TypeScript and at least one back-end language or runtime such as Node.js, Python, PHP, Ruby, Java, C#, or comparable technology.

  • Experience with relational databases, SQL, data modeling, schema changes, migrations, and application-level data validation.

  • Hands-on experience designing or consuming REST APIs, webhooks, JSON payloads, authentication flows, and third-party integrations.

  • Proficiency with Git/GitHub or comparable version-control workflows, including branching, code review, merge management, and release discipline.

  • Experience deploying and supporting applications in cloud or server environments, including Linux/SSH, DNS, environment configuration, SSL/TLS certificates, and production troubleshooting.

  • Strong debugging and problem-solving skills with the ability to audit, refactor, and stabilize AI-generated or rapidly prototyped code.

  • Working knowledge of application security, access control, secrets management, logging, encryption concepts, and secure handling of sensitive data.

  • Ability to communicate effectively with executives, non-technical stakeholders, analysts, vendors, and other technical contributors.

PREFERRED QUALIFICATIONS

  • Experience developing technology in healthcare, managed care, care coordination, clinical operations, revenue cycle, or other PHI-sensitive environments.

  • Hands-on experience with Lovable, Claude Code, Cursor, Replit, Bolt, or other AI-assisted/vibe-coding environments.

  • Experience with Docker, CI/CD pipelines, GitHub Actions, reverse proxies, cloud platforms such as AWS/Azure/GCP, or modern application hosting platforms.

  • Experience integrating EMR/EHR, CRM, billing, communications, workflow, and analytics systems.

  • Familiarity with healthcare interoperability concepts such as FHIR, HL7, X12, or healthcare data exchange patterns.

  • Experience with automation/orchestration platforms such as n8n, Zapier, Make, or comparable tools.

  • Experience with infrastructure-as-code, automated testing, vulnerability management, or production observability platforms.

  • Bachelor’s degree in Computer Science, Information Systems, or a related technical field; equivalent professional experience may substitute., Acceptance Testing, Access Control, Accidental Death and Dismemberment (AD&D), Administrative Skills, Amazon Web Services (AWS), Application Builders, Application Hosting, Application Integration, Application Programming Interface (API), Applications Security, Architectural Services, Artificial Intelligence (AI), Auditing, Authentication, Automation, Billing, Bug Tracking/Defect Management, Business Solutions, Business Support, Capacity and Performance Management, Cloud Applications, Cloud Computing, Code Reviews, Communication Skills, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Integration, Cross-Functional, Cryptography, Customer Relationship Management (CRM), DNS (Domain Name System), Data Modeling, Data Quality, Debugging Skills, Digital Certificates, Docker, Doctor of Nursing Science (DNS), Documentation, Documentation Standards, Electronic Medical Records, Embedded Systems, Employee Assistance Plan, Enterprise Applications, Error Handling, Feasibility Analysis, Functional Testing, GCP (Good Clinical Practices), Git, GitHub, HIPAA (Health Insurance Portability and Accountability Act), HL7 (Health Level 7), Healthcare, Healthcare Software, Identify Issues, Information Technology & Information Systems, Information/Data Security (InfoSec), Integration Testing, Internet Application, Interoperability, JSON, Java, JavaScript, Leadership, Linux Operating System, Managed Care, Medical Record System, Microsoft C# (C Sharp), Microsoft Windows Azure, Middleware, Node.js, OAuth, Operational Support, PHP Scripting Language (PHP Hypertext Preprocessor), Performance Tuning/Optimization, Privacy Controls, Problem Solving Skills, Process Analysis, Production Control, Production Systems, Programming Tools, Proof of Concept, Prototyping, Python Programming/Scripting Language, REST (Representational State Transfer), Rapid Prototyping, Reconciliation, Refactoring, Regression Testing, Relational Databases (RDBMS), Release Management/Engineering, Reliability Engineering, Reporting Dashboards, Risk, Root Cause Analysis, Ruby, SQL (Structured Query Language), SSH (Secure Shell), SSL-TLS (Secure Socket Layer - Transport Layer Security), Scripting (Scripting Languages), Secure Coding, Software Administration, Software Development, Software Prototyping, Source Code/Configuration Management (SCM), Support Documentation, System Integration (SI), Systems Analysis, Technical Delivery, Technical Support, Technical Writing, Test Automation, Test Plan/Schedule, Testing, Theater Production, Traceability, Traffic Shaping, Unit Test, User Documentation, User Interface/Experience (UI/UX), Vendor/Supplier Evaluation, Web Hosting, Web Production, Wheel/Front-End Loader, Work From Home

Benefits & conditions

Benefits & Perks

  • Paid Time Off (PTO)
  • 12 Paid Holidays per year, including your birthday and one floating holiday after 1 year of employment
  • 4 Paid Volunteer Hours per Month to support causes you care about
  • Bereavement Leave, including Fur Baby Bereavement
  • 90% Employer-paid Employee-Only Medical Benefits
  • Dental and Vision Insurance
  • FSA Dependent Care Account
  • 401(k) with Company Match
  • Monthly Stipend
  • Short-Term & Long-Term Disability AD&D
  • Employee Assistance Program (EAP)
  • Employee Discounts via Great Work Perks and Perks at Work
  • Quarterly In-Person Events
  • Fully remote work within California
  • Opportunities for professional development and internal growth

Equal Opportunity Employer

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:06 min

Developer experience and project variety at scale

Alexandra Petri · World Congress 2023

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:45 min

Prioritizing human collaboration and social skills over coding

Christian Heilmann Christian Heilmann · World Congress 2025

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all