Mach7 Technologies
Remote Jobs
3 Jobs
Role Description We're looking for a Senior Security Engineer to lead application security efforts across our product portfolio, spanning web applications, APIs, mobile, embedded software, and shipped product deliverables. You'll be embedded in the engineering organization, partnering with product and platform teams to bake security into every phase of the software development lifecycle, not bolt it on at the end. A critical part of this role is developing and maintaining a deep understanding of our product attack surface, how components interact, what's exposed, and where real risk lives. That understanding is what transforms security tooling output into prioritized, meaningful action across threat modeling, vulnerability management, and supply chain risk. This is a high-impact role for someone who is equally comfortable reading source code, threat modeling a new microservice, and coaching a developer through a secure code review. What You'll Do - Application Security & Secure SDLC - Own and evolve the AppSec program across the entire SDLC — from design reviews to post-deployment monitoring — for web, API, mobile, and shipped product deliverables. - Build and maintain a living model of the product attack surface — mapping trust boundaries, data flows, exposed interfaces, and high-value targets — and use it to drive prioritization across all security workstreams. - Conduct threat modeling and architecture security reviews for new features, services, and product releases across all delivery channels. - Perform manual and automated secure code reviews across multiple languages (e.g. Python, Go, TypeScript, C/C++). - Integrate and tune SAST, DAST, and SCA tooling within CI/CD pipelines (GitHub Actions, Jenkins, or equivalent). - Triage and drive remediation of vulnerabilities surfaced through scanning, bug bounty, and pen tests. - Develop and maintain a library of security standards, patterns, and guardrails applicable across product types. - Third-Party & Supply Chain Security - Own the Software Bill of Materials (SBOM) program — define generation, storage, and consumption processes across all product lines. - Establish and maintain policies for evaluating, onboarding, and continuously monitoring third-party dependencies and open-source components. - Triage and prioritize CVEs and license risks surfaced through SCA tooling, driving timely remediation with engineering teams. - Define processes for responding to upstream supply chain incidents (e.g. compromised packages, malicious dependencies). - Collaborate with procurement and legal to assess security risk of third-party vendors and integrations. - Contribute to industry frameworks and internal standards around software supply chain security (SLSA, NIST SSDF, or equivalent). - Act as a trusted security advisor embedded within product engineering squads. - Lead security training, lunch-and-learns, and developer education initiatives. - Collaborate with the Platform team on secrets management, identity, and access controls. - Work with the GRC function to translate compliance requirements (SOC 2, ISO 27001) into engineering controls. - Incident & Vulnerability Management - Participate in the security on-call rotation and lead security incident response investigations. - Drive root cause analysis and communicate findings clearly to engineering leadership. - Build and maintain metrics and dashboards to track the health of the AppSec program. - Participate as a member of the Cybersecurity council, representing development in the organization. Report weekly on new threat intelligence as it relates to product security, and any actions that are being taken to remediate new findings. Qualifications - 5+ years of experience in security engineering, with a strong AppSec focus. - Hands-on experience with threat modeling frameworks (STRIDE, PASTA, or similar). - Proficiency with common AppSec tooling: Semgrep, Snyk, Burp Suite, OWASP ZAP, or equivalents. - Deep understanding of web application vulnerabilities (OWASP Top 10, API security, auth/authz flaws). - Ability to read and reason about code in at least two languages; prior development experience a plus. - Experience with software supply chain security — SBOM generation and analysis (CycloneDX, SPDX), SCA tooling, and dependency risk management. - Strong written and verbal communication skills — you can explain risk to both engineers and executives. Requirements - Experience with cloud-native environments (AWS, GCP, or Azure) and container/Kubernetes security. - Familiarity with software supply chain frameworks such as SLSA, NIST SSDF, or OpenSSF Scorecards. - Contributions to open-source security tooling or security research. - Relevant certifications: OSCP, CSSLP, GWEB, or similar. Who You Are - Experienced security professional with a strong background in application security and secure software development. - Skilled at threat modeling, secure code reviews, and identifying real-world risks across complex systems. - Knowledgeable in web, API, mobile, and software supply chain security best practices. - Comfortable working with developers to embed security throughout the SDLC. - Proficient with security testing and vulnerability management tools, including SAST, DAST, and SCA solutions. - Strong communicator who can translate technical risks into actionable recommendations. - Collaborative, proactive, and driven to improve both product security and engineering security culture. - Passionate about continuous learning, emerging threats, and helping teams build secure products at scale.
Role Description We are seeking a Senior Database Administrator (DBA) to take ownership of performance, reliability, and evolution of mission-critical healthcare data platforms. This is not a traditional DBA role. You will operate at the intersection of customer environments and product engineering, spending approximately: - 60% working directly with healthcare customers - 40% partnering with R&D and engineering teams You will work across SQL Server and PostgreSQL environments deployed in hybrid architectures (on-prem + cloud), ensuring healthcare providers have fast, reliable, and secure access to critical patient data. An AI-first mindset is required—you will be expected to leverage AI tools to automate operations, accelerate troubleshooting, and improve system intelligence. Qualifications - 5+ years of hands-on DBA experience in production environments - Strong expertise in Microsoft SQL Server and PostgreSQL - Proven experience managing hybrid environments (on-prem + cloud) - Experience in customer-facing or production support roles - Deep knowledge of performance tuning, high availability/disaster recovery, and backup/recovery strategies - Ability to operate effectively in 24/7, mission-critical environments Requirements - Proactively use AI tools to accelerate root cause analysis - Automate repetitive operational tasks - Improve system monitoring and predictive insights - Continuously replace manual DBA workflows with intelligent automation - Contribute to building an AI-driven operations model Preferred Qualifications - Experience in healthcare IT environments - Familiarity with DICOM, HL7, or FHIR - Experience with clinical imaging systems (VNA, PACS) - Experience with large-scale data systems (TB-scale and beyond) - Exposure to cloud-native architectures and containerization/Kubernetes - Experience with database migration and modernization initiatives
Role Description Help us break things before customers do. We’re looking for a hands-on QA Team Lead for our Vendor Neutral Archive (VNA) platform. This is a role for someone who can lead people, think technically, and stay close to the work. You will help shape test strategy, improve release confidence, and chase down the kinds of bugs that hide in workflows, integrations, data movement, and storage. - Lead QA efforts for the VNA product across functional, integration, regression, upgrade, and release testing. - Coach and support QA engineers while staying hands-on with complex technical issues. - Build practical test strategies for workflows spanning application, database, and cloud storage layers. - Partner with Engineering, Product, and Support to make quality a shared responsibility. - Drive root cause thinking, defect triage, and release readiness decisions. - Improve test coverage, test environments, and automation over time. Qualifications - Experience leading QA or test efforts for complex software systems. - Strong background in both manual and automated testing. - Experience testing across UI, API, database, integration, and end-to-end workflows. - Solid hands-on experience with Microsoft SQL Server for data validation, troubleshooting, and backend verification. - Familiarity with test planning tools (Azure DevOps, Jira), defect tracking, traceability, and release coordination. - Experience validating systems that use cloud object storage such as Amazon S3. - Ability to investigate failures using logs, traces, SQL analysis, and system behavior. - Strong judgment around release risk, regression strategy, and defect management. - Ability to mentor others and raise the technical bar of the QA team. Requirements - Experience with VNA, PACS, enterprise imaging, or healthcare software. - Familiarity with DICOM, HL7, IHE, or interoperability-heavy workflows. - Experience with upgrade testing, migration testing, and backward compatibility. - Exposure to performance, reliability, and large-volume data validation. - Experience working in a regulated medical software environment. Benefits - Know your way around SQL Server and are not afraid to dig into the data. - Can use ADO without turning everything into process theater. - Understand that testing a VNA is not just clicking through a UI. - Like chasing down tricky bugs across services, storage, integrations, and workflows. - Can lead people and still jump into the weeds when needed.