Jobs › Companies › eVisit › Software Engineer, Security Focus

Über diese Software Engineer, Security Focus Stelle bei eVisit

eVisit · Remote · Mesa, Arizona, United States

We are looking for a hands-on full-stack Software Engineer who will focus primarily on security remediation. Your first priority will be owning the remediation of vulnerabilities identified through penetration testing: not just reporting findings, but digging into the codebase, session traffic, and infrastructure to fix the underlying issues and prevent them from recurring. You will work closely with engineering and design teams to translate real-world security findings into concrete, testable requirements in our Technical Requirements Documents (TRDs), and you will personally implement or oversee the fixes.

This is an engineering role first. As the security backlog comes under control, you will have the flexibility to contribute to application development across our Ruby on Rails and React platform, bringing a security-minded perspective to the features you build.

Key Responsibilities

Security Remediation

  • Vulnerability Remediation: Own end-to-end remediation of vulnerabilities surfaced by penetration tests and other security assessments, from triage through verified fix.
  • Traffic and Session Analysis: Use browser-based code inspection tools to examine session traffic between the front end and back end, identify cases where excessive or sensitive information is being exposed, and translate those findings into concrete design and engineering requirements.
  • TRD Input: Feed vulnerability findings and remediation requirements directly into the Technical Requirements Document (TRD) process so fixes are captured as durable design requirements, not one-off patches.
  • Session Management: Review and harden session management practices across the application stack.
  • Full-Stack Remediation: Work within a Ruby on Rails and React codebase and across containerized services (AWS, Fargate) to implement fixes at both the application and infrastructure layers.
  • API and Real-Time Systems: Assess and secure real-time and API-driven features, including those built on Pusher and AnyCable, and RESTful APIs generally.
  • Documentation: Produce clear, thorough documentation of vulnerabilities, root causes, remediation steps, and verification results.
  • Compliance Support: Contribute security context and vocabulary to FedRAMP-related discussions and requirements, partnering with compliance and engineering stakeholders.

Application Development

  • Feature Development: Design, build, and ship features across the Ruby on Rails back end and React front end alongside the broader engineering team.
  • Secure by Design: Apply what you learn from remediation work to new development, helping the team avoid reintroducing known classes of vulnerabilities.
  • Code Quality: Participate in code reviews, testing, and technical design discussions, with an eye toward both security and maintainability.

Requirements

Engineering Experience

  • 5+ years of hands-on software engineering experience, with broad full-stack work across multiple applications and technology layers.
  • Working proficiency in Ruby on Rails and React.
  • Experience with containerized environments, AWS, and Fargate.
  • Solid API experience, including RESTful API design and security considerations.
  • Hands-on experience with Pusher and AnyCable, or comparable real-time messaging technologies.
  • Knowledge of Ruby data models and how schema and query design affect performance and scalability.

Security Experience

  • 5+ years of experience in a security engineering or closely related role.
  • Proven experience remediating vulnerabilities identified through penetration testing.
  • AWS Security certification(s) (e.g., AWS Certified Security – Specialty).
  • General familiarity with FedRAMP: enough understanding of the vocabulary and framework to contribute meaningfully to a FedRAMP-related project.

Analytical Skills

  • Comfortable using browser developer/code inspection tools to inspect network and session traffic.
  • Able to identify when too much information is being exposed between backend and frontend, and to explain the risk clearly to engineering and design stakeholders.
  • Able to translate security findings into actionable design requirements that feed directly into the TRD.

Coding and Technical Skills

  • Working proficiency in Ruby on Rails.
  • Experience with containerized environments, AWS, and Fargate.
  • Solid API experience, including RESTful API design and security considerations.
  • Solid understanding of session management principles and common pitfalls.
  • Hands-on experience with Pusher and AnyCable, or comparable real-time messaging technologies.
  • Broad, full-stack experience across multiple applications and technology layers.
  • Knowledge of Ruby data models and how schema and query design affect performance and scalability.

Documentation

  • Strong written communication skills, with the ability to document vulnerabilities, remediations, and technical requirements clearly for both engineering and non-engineering audiences.

Nice to Have

  • Experience with Pulumi for infrastructure as code.
  • Python experience.
  • SQL skills.
  • Active or eligible for security clearance.
Bereit, sich bei eVisit zu bewerben?
Bei eVisit bewerben

Über eVisit

eVisit is the leading digital care transformation partner for health systems and large, complex healthcare delivery organizations. Backed by Goldman Sachs Asset Management, Texas Health Resources, MedStar Health, and UPMC, eVisit partners with healthcare delivery systems to rearchitect the very nature of how care is delivered. We help our customers design care pathways that lower the total cost of care, increase access, and enhance both patient and provider experiences – all while strengthening clinical, operational and financial performance. eVisit is trusted by several of the Top 20 leading US health systems and currently support care delivery in all 50 states across more than 35,000 beds. eVisit is a two-time recipient of the prestigious Best in KLAS award (2024 and 2025) in the virtual care platform category. This award is the result of eVisit’s customers scoring the company across critical areas such as product capabilities, innovation, service, impact, value and others. Learn more at www.evisit.com

Alle Jobs bei eVisit ansehen →

Ähnliche Jobs

AX
CMM Programmer (Onsite)
Axon
⚡ Früh bewerben Mesa, Arizona, United States Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
Versaterm
Staff Software Engineer
Versaterm
⚡ Früh bewerben Mesa, Arizona, United States Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Wo.
SA
Software Engineer AMTS (Junior) - Keynote Demo
Salesforce
⚡ Früh bewerben Mexico - Mexico City Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 18 Min.
Redwood Materials
Software Engineer - ML/Computer Vision (Battery Sorting)
Redwood Materials
⚡ Früh bewerben McCarran, NV; San Francisco, C... Vor Ort $152,500–$200,000
● Neu 👁 Gesehen ✓ Beworben vor 31 Min.
Redwood Materials
Senior Software Engineer, Energy Storage
Redwood Materials
⚡ Früh bewerben San Francisco, California, Uni... Vor Ort $150,000–$237,500
● Neu 👁 Gesehen ✓ Beworben vor 32 Min.
Redwood Materials
Staff Software Engineer
Redwood Materials
⚡ Früh bewerben McCarran, NV; San Francisco, C... Hybrid $217,500–$287,500
● Neu 👁 Gesehen ✓ Beworben vor 32 Min.
SA
Senior Software Engineer, Identity
Scale AI
⚡ Früh bewerben San Francisco, CA; New York, N... Vor Ort $216,000–$270,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
Ensono
Senior Mainframe Systems Programmer - DB2
Ensono
⚡ Früh bewerben Hyderabad, India Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
TraceLink, Inc
Software Engineer, Principal
TraceLink, Inc
⚡ Früh bewerben US - MA - Wilmington Vor Ort $181,561–$225,648
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei eVisit

Alle Jobs bei eVisit ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos