Jobs and Careers
NE
Principal Engineer, Product Security
NextGen HealthcareRemote GA, United StatesRemotefull_timeVerifiedPosted 31 Jul 2024
About the role
Job Description:
The Principal Engineer, Product Security will lead the design, implementation, and review of security features and controls across our product portfolio. This role will work closely with product managers, engineers, and other stakeholders to ensure that our products meet the highest standards of security and compliance.- Execute the product security strategy and roadmap, aligning with the business objectives and customer needs.
- Conduct threat modeling, risk assessment, and security testing of our products and services, and provide remediation guidance and support.
- Develop and maintain security policies, standards, and guidelines for product development and deployment.
- Review and approve security architectures, designs, and code, and provide feedback and recommendations for improvement.
- Participate in security incident response and investigations and communicate with internal and external stakeholders.
- Research and evaluate emerging security trends, technologies, and best practices, and incorporate them into our products and processes.
- Provide technical leadership and mentorship to other security engineers and foster a culture of security awareness and best practices within the organization.
- Perform other duties that support the overall objective of the position.
Education Required:
- Bachelor's degree in computer science, engineering, or related field.
- Or, any combination of education and experience which would provide the required qualifications for the position.
Experience Required:
- 10+ years of experience in product security engineering, with a focus on web, mobile, cloud, and IoT products.
- Experience with security technologies and platforms, such as encryption, authentication, and web application firewall.
- Experience with cloud platforms and services, such as AWS, Azure, or GCP, and their security features and configurations.
- Experience with DevSecOps practices and tools, such as CI/CD, automation, and orchestration.
Knowledge, Skills & Abilities:
- Knowledge of: Expert knowledge of security principles, standards, and frameworks, such as OWASP, NIST, ISO, and CIS.• Proficient in security testing tools and methodologies, such as static and dynamic analysis, penetration testing, and vulnerability scanning.
- Skill in: Advanced skills in programming languages, such as Java, Python, C#, or Go, and scripting languages, such as Bash, PowerShell, or Perl. Excellent communication, collaboration, problem-solving and analytical skills.
- Ability to: Stay current with evolving security trends and technologies. Identify, troubleshoot and resolve problems quickly using sound judgment, poise and diplomacy.
The company has reviewed this job description to ensure that essential functions and basic duties have been included. It is intended to provide guidelines for job expectations and the employee's ability to perform the position described. It is not intended to be construed as an exhaustive list of all functions, responsibilities, skills and abilities. Additional functions and requirements may be assigned by supervisors as deemed appropriate. This document does not represent a contract of employment, and the company reserves the right to change this job description and/or assign tasks for the employee to perform, as the company may deem appropriate.
NextGen Healthcare is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s