Summary
Pacific Health Group is a healthcare organization seeking a Software Developer to build and maintain software supporting clinical, operational, administrative, and growth initiatives. The role focuses on AI-assisted application development, production deployment, API and third-party integrations, HIPAA/PHI safeguards, testing, technical support, and cross-functional solution development.
Responsibilities
- Partner with executive leadership to translate ideas, operational pain points, workflows, and product concepts into functional software requirements and technical solutions
- Use AI-assisted and vibe-coding platforms such as Lovable and comparable tools to rapidly build proofs of concept, internal applications, portals, dashboards, workflow tools, and production features
- Review, debug, refactor, and strengthen AI-generated code rather than treating generated output as production-ready by default
- Develop and modify front-end, back-end, database, authentication, business-logic, and integration components as required by the application
- Maintain source code in company-approved version control, using clear branching, commits, pull requests, code review, and release practices
- Identify technical debt, duplicated logic, unsupported dependencies, fragile components, and architectural issues introduced during rapid prototyping and correct them before or during production deployment
- Document significant third-party libraries, AI-assisted code sources, dependencies, and repository components to support maintainability, security review, and traceability
- Export, migrate, and adapt application code from AI-assisted platforms into GitHub or other company-approved repositories and deployment environments
- Configure production and staging environments, including Linux/server settings, runtime dependencies, environment variables, databases, storage, domains, DNS, reverse proxies, and application services
- Configure, renew, and troubleshoot SSL/TLS certificates and enforce encrypted connections for production applications and APIs
- Implement repeatable deployment practices using CI/CD, containerization, infrastructure scripts, or other appropriate release mechanisms
- Establish logging, monitoring, alerting, backups, rollback procedures, and recovery practices appropriate to each application
- Troubleshoot deployment failures, server-side errors, performance issues, dependency conflicts, and environment-specific defects
- Support capacity planning, performance tuning, and architecture changes as internal applications grow in users, data volume, or complexity
- Design, build, document, test, and maintain RESTful APIs, webhooks, middleware, background jobs, and integration services
- Integrate third-party applications and internal systems including CRM, EMR/EHR, billing, communications, Google Workspace, workflow platforms, analytics tools, and other enterprise applications
- Implement authentication and authorization patterns such as OAuth, API keys, service accounts, role-based access, and token-based access where appropriate
- Create data mappings, transformations, validation rules, retry logic, rate-limit handling, error handling, and reconciliation processes for multi-system data exchanges
- Diagnose and resolve integration conflicts involving vendor APIs, native platform limitations, version changes, payload structures, permissions, or data synchronization
- Work with the Business Systems Analyst to convert process maps, functional requirements, field mappings, and business rules into reliable technical implementations
- Maintain technical documentation for endpoints, credentials handling, dependencies, data flows, integration logic, and support procedures
- Apply secure coding practices to applications that create, receive, maintain, or transmit Protected Health Information (PHI) or other sensitive company data
- Implement appropriate access controls, least-privilege permissions, secure authentication, session controls, audit logging, encryption in transit, encryption at rest where applicable, and secure secrets management
- Prevent hardcoded credentials, exposed API keys, insecure storage, excessive permissions, vulnerable dependencies, and unprotected administrative functions
- Perform code and dependency reviews for security weaknesses, outdated packages, known vulnerabilities, unsafe configurations, and inappropriate data exposure
- Collaborate with Compliance, IT, vendors, and leadership to support HIPAA-related technical safeguards, internal security reviews, remediation plans, and audit-readiness documentation
- Separate development, testing, and production environments and ensure PHI is not introduced into non-approved environments or tools
- Maintain traceability for major code, configuration, integration, and infrastructure changes affecting regulated or sensitive systems
- Create and execute unit, integration, regression, API, security, and end-to-end tests appropriate to each application
- Support user acceptance testing (UAT), reproduce reported defects, identify root causes, and implement durable fixes
- Validate edge cases, error states, permission scenarios, data quality, integration failures, and recovery behavior rather than testing only the primary workflow
- Review application performance, database queries, API latency, page load time, background processes, and resource usage and optimize as needed
- Implement application observability through logs, alerts, health checks, and actionable monitoring
- Respond to production defects and incidents, document root cause, and implement preventive changes where recurring problems are identified
- Maintain technical runbooks, architecture notes, deployment documentation, and support instructions for critical systems
- Work closely with the executive team to evaluate feasibility, technical tradeoffs, implementation paths, risks, timelines, and build-versus-buy decisions
- Collaborate with the Business Systems Analyst to review process pain points, solution maps, automation opportunities, and system requirements before development begins
- Provide technical options when a requested approach is not secure, maintainable, cost-effective, or feasible and recommend practical alternatives
- Participate in discovery sessions with operational teams to understand real-world workflows, exceptions, user roles, and system dependencies
- Coordinate with software vendors and third-party technical teams when integrations, migrations, or platform limitations require joint troubleshooting
- Communicate technical issues in clear business language and maintain transparency on risks, blockers, dependencies, and production readiness
- Continuously evaluate emerging AI development tools, frameworks, infrastructure approaches, and integration technologies that can improve delivery speed or system quality
- Clarify the business problem, users, workflows, permissions, data requirements, integrations, exceptions, and expected outcomes
- Build or refine a rapid proof of concept using AI-assisted/vibe-coding tools where appropriate
- Identify systems of record, PHI exposure, vendor dependencies, technical constraints, and integration requirements
- Establish acceptance criteria and define what is required before the application can move beyond prototype status
- Move the codebase into company-controlled version control and establish a maintainable project structure
- Review AI-generated code, dependencies, data models, authentication, business logic, and error handling
- Refactor fragile or duplicated code and remove unsafe shortcuts, exposed secrets, insecure defaults, and unsupported dependencies
- Define deployment architecture, environments, release strategy, rollback path, and monitoring requirements
- Develop required APIs, middleware, webhooks, data mappings, and third-party integrations
- Implement authentication, authorization, audit logging, encryption, secrets management, validation, and other required security controls
- Configure staging and production infrastructure, databases, domains, DNS, certificates, backups, and environment-specific settings
- Validate that PHI and sensitive data are handled only through approved systems and approved technical paths
- Complete functional, integration, regression, permission, performance, error-state, and security testing
- Support UAT with business owners and resolve blocking defects prior to production launch
- Deploy through a documented release process with backup, rollback, monitoring, and post-release validation
- Confirm production certificates, environment variables, integrations, logging, alerts, and access controls are operating as intended
- Monitor application health, logs, integration failures, performance, certificate status, and security findings
- Prioritize defects, enhancement requests, technical debt, dependency updates, and security remediation
- Conduct root cause analysis for recurring incidents and improve code, architecture, or workflows to prevent recurrence
- Continue using AI-assisted development to accelerate enhancements while maintaining code review, testing, security, and documentation standards
Skills
- 3+ years of professional software development, full-stack development, application development, or comparable hands-on experience
- Demonstrated ability to build and maintain production web applications using modern front-end and back-end technologies
- Strong working knowledge of JavaScript/TypeScript and at least one back-end language or runtime such as Node.js, Python, PHP, Ruby, Java, C#, or comparable technology
- Experience with relational databases, SQL, data modeling, schema changes, migrations, and application-level data validation
- Hands-on experience designing or consuming REST APIs, webhooks, JSON payloads, authentication flows, and third-party integrations
- Proficiency with Git/GitHub or comparable version-control workflows, including branching, code review, merge management, and release discipline
- Experience deploying and supporting applications in cloud or server environments, including Linux/SSH, DNS, environment configuration, SSL/TLS certificates, and production troubleshooting
- Strong debugging and problem-solving skills with the ability to audit, refactor, and stabilize AI-generated or rapidly prototyped code
- Working knowledge of application security, access control, secrets management, logging, encryption concepts, and secure handling of sensitive data
- Ability to communicate effectively with executives, non-technical stakeholders, analysts, vendors, and other technical contributors
- Experience developing technology in healthcare, managed care, care coordination, clinical operations, revenue cycle, or other PHI-sensitive environments
- Hands-on experience with Lovable, Claude Code, Cursor, Replit, Bolt, or other AI-assisted/vibe-coding environments
- Experience with Docker, CI/CD pipelines, GitHub Actions, reverse proxies, cloud platforms such as AWS/Azure/GCP, or modern application hosting platforms
- Experience integrating EMR/EHR, CRM, billing, communications, workflow, and analytics systems
- Familiarity with healthcare interoperability concepts such as FHIR, HL7, X12, or healthcare data exchange patterns
- Experience with automation/orchestration platforms such as n8n, Zapier, Make, or comparable tools
- Experience with infrastructure-as-code, automated testing, vulnerability management, or production observability platforms
- Bachelor's degree in Computer Science, Information Systems, or a related technical field; equivalent professional experience may substitute
Qualifications
Must Haves
- 3+ years of professional software development, full-stack development, application development, or comparable hands-on experience
- Demonstrated ability to build and maintain production web applications using modern front-end and back-end technologies
- Strong working knowledge of JavaScript/TypeScript and at least one back-end language or runtime such as Node.js, Python, PHP, Ruby, Java, C#, or comparable technology
- Experience with relational databases, SQL, data modeling, schema changes, migrations, and application-level data validation
- Hands-on experience designing or consuming REST APIs, webhooks, JSON payloads, authentication flows, and third-party integrations
- Proficiency with Git/GitHub or comparable version-control workflows, including branching, code review, merge management, and release discipline
- Experience deploying and supporting applications in cloud or server environments, including Linux/SSH, DNS, environment configuration, SSL/TLS certificates, and production troubleshooting
- Strong debugging and problem-solving skills with the ability to audit, refactor, and stabilize AI-generated or rapidly prototyped code
- Working knowledge of application security, access control, secrets management, logging, encryption concepts, and secure handling of sensitive data
- Ability to communicate effectively with executives, non-technical stakeholders, analysts, vendors, and other technical contributors
Nice to Haves
- Experience developing technology in healthcare, managed care, care coordination, clinical operations, revenue cycle, or other PHI-sensitive environments
- Hands-on experience with Lovable, Claude Code, Cursor, Replit, Bolt, or other AI-assisted/vibe-coding environments
- Experience with Docker, CI/CD pipelines, GitHub Actions, reverse proxies, cloud platforms such as AWS/Azure/GCP, or modern application hosting platforms
- Experience integrating EMR/EHR, CRM, billing, communications, workflow, and analytics systems
- Familiarity with healthcare interoperability concepts such as FHIR, HL7, X12, or healthcare data exchange patterns
- Experience with automation/orchestration platforms such as n8n, Zapier, Make, or comparable tools
- Experience with infrastructure-as-code, automated testing, vulnerability management, or production observability platforms
- Bachelor's degree in Computer Science, Information Systems, or a related technical field; equivalent professional experience may substitute
Benefits
- Paid Time Off (PTO)
- 12 Paid Holidays per year, including your birthday and one floating holiday after 1 year of employment
- 4 Paid Volunteer Hours per Month to support causes you care about
- Bereavement Leave, including Fur Baby Bereavement
- 90% Employer-paid Employee-Only Medical Benefits
- Dental and Vision Insurance
- FSA | Dependent Care Account
- 401(k) with Company Match
- Monthly Stipend
- Short-Term & Long-Term Disability | AD&D
- Employee Assistance Program (EAP)
- Employee Discounts via Great Work Perks and Perks at Work
- Quarterly In-Person Events
- Fully remote work within California
- Opportunities for professional development and internal growth