Position Purpose
The Software Developer works directly alongside the executive team to design, develop, enhance, modify, deploy, and maintain software applications that support Pacific Health Group’s clinical, operational, administrative, and growth initiatives. The role combines modern software development with AI-assisted “vibe coding” to move rapidly from business concept to functional prototype and from prototype to secure, maintainable production software.
A core responsibility is taking applications created or accelerated through platforms such as Lovable and other AI-assisted development environments, auditing and refining the generated code, connecting the codebase to company-controlled repositories, migrating it to production infrastructure, and completing the configuration, security hardening, integration, and code modifications required for dependable operation. The Developer also develops APIs and third-party integrations, supports PHI/HIPAA-sensitive systems, and ensures that speed of development does not compromise security, reliability, maintainability, or data integrity.
KEY RESPONSIBILITIES
1. AI-Assisted / Vibe Coding and Application Development
Builds and evolves software by combining rapid AI-assisted prototyping with professional software development practices and full ownership of the resulting codebase.
Activities:
• Partner with executive leadership to translate ideas, operational pain points, workflows, and product concepts into functional software requirements and technical solutions.
• Use AI-assisted and vibe-coding platforms such as Lovable and comparable tools to rapidly build proofs of concept, internal applications, portals, dashboards, workflow tools, and production features.
• Review, debug, refactor, and strengthen AI-generated code rather than treating generated output as production-ready by default.
• Develop and modify front-end, back-end, database, authentication, business-logic, and integration components as required by the application.
• Maintain source code in company-approved version control, using clear branching, commits, pull requests, code review, and release practices.
• Identify technical debt, duplicated logic, unsupported dependencies, fragile components, and architectural issues introduced during rapid prototyping and correct them before or during production deployment.
• Document significant third-party libraries, AI-assisted code sources, dependencies, and repository components to support maintainability, security review, and traceability.
Outputs:
• Rapidly developed applications that transition from concept to stable, maintainable, production-ready software with clear source-code ownership and documentation.
2. Production Deployment, Server Migration, and Infrastructure
Owns the technical transition from development environments and AI application builders into secure, controlled production infrastructure.
Activities:
• Export, migrate, and adapt application code from AI-assisted platforms into GitHub or other company-approved repositories and deployment environments.
• Configure production and staging environments, including Linux/server settings, runtime dependencies, environment variables, databases, storage, domains, DNS, reverse proxies, and application services.
• Configure, renew, and troubleshoot SSL/TLS certificates and enforce encrypted connections for production applications and APIs.
• Implement repeatable deployment practices using CI/CD, containerization, infrastructure scripts, or other appropriate release mechanisms.
• Establish logging, monitoring, alerting, backups, rollback procedures, and recovery practices appropriate to each application.
• Troubleshoot deployment failures, server-side errors, performance issues, dependency conflicts, and environment-specific defects.
• Support capacity planning, performance tuning, and architecture changes as internal applications grow in users, data volume, or complexity.
Outputs:
• Stable staging and production environments with documented configurations, secure deployment practices, reliable rollback paths, and operational visibility.
3. API Development, Integrations, and Data Interoperability
Connects Pacific Health Group applications and business platforms through secure, reliable application programming interfaces and integration patterns.
Activities:
• Design, build, document, test, and maintain RESTful APIs, webhooks, middleware, background jobs, and integration services.
• Integrate third-party applications and internal systems including CRM, EMR/EHR, billing, communications, Google Workspace, workflow platforms, analytics tools, and other enterprise applications.
• Implement authentication and authorization patterns such as OAuth, API keys, service accounts, role-based access, and token-based access where appropriate.
• Create data mappings, transformations, validation rules, retry logic, rate-limit handling, error handling, and reconciliation processes for multi-system data exchanges.
• Diagnose and resolve integration conflicts involving vendor APIs, native platform limitations, version changes, payload structures, permissions, or data synchronization.
• Work with the Business Systems Analyst to convert process maps, functional requirements, field mappings, and business rules into reliable technical implementations.
• Maintain technical documentation for endpoints, credentials handling, dependencies, data flows, integration logic, and support procedures.
Outputs:
• Reliable, documented system integrations that reduce manual work, maintain data integrity, and support scalable operations across departments.
4. Security, HIPAA / PHI Safeguards, and Code Governance
Builds healthcare applications with security and privacy controls embedded into design, development, deployment, and maintenance.
Activities:
• Apply secure coding practices to applications that create, receive, maintain, or transmit Protected Health Information (PHI) or other sensitive company data.
• Implement appropriate access controls, least-privilege permissions, secure authentication, session controls, audit logging, encryption in transit, encryption at rest where applicable, and secure secrets management.
• Prevent hardcoded credentials, exposed API keys, insecure storage, excessive permissions, vulnerable dependencies, and unprotected administrative functions.
• Perform code and dependency reviews for security weaknesses, outdated packages, known vulnerabilities, unsafe configurations, and inappropriate data exposure.
• Collaborate with Compliance, IT, vendors, and leadership to support HIPAA-related technical safeguards, internal security reviews, remediation plans, and audit-readiness documentation.
• Separate development, testing, and production environments and ensure PHI is not introduced into non-approved environments or tools.
• Maintain traceability for major code, configuration, integration, and infrastructure changes affecting regulated or sensitive systems.
Outputs:
• Production applications and integrations that are security-conscious, audit-ready, appropriately access-controlled, and designed to protect PHI and confidential information.
5. Testing, Quality, Reliability, and Technical Support
Ensures software works correctly across expected workflows and remains maintainable after launch.
Activities:
• Create and execute unit, integration, regression, API, security, and end-to-end tests appropriate to each application.
• Support user acceptance testing (UAT), reproduce reported defects, identify root causes, and implement durable fixes.
• Validate edge cases, error states, permission scenarios, data quality, integration failures, and recovery behavior rather than testing only the primary workflow.
• Review application performance, database queries, API latency, page load time, background processes, and resource usage and optimize as needed.
• Implement application observability through logs, alerts, health checks, and actionable monitoring.
• Respond to production defects and incidents, document root cause, and implement preventive changes where recurring problems are identified.
• Maintain technical runbooks, architecture notes, deployment documentation, and support instructions for critical systems.
Outputs:
• Lower defect rates, faster troubleshooting, improved software reliability, and repeatable technical support for business-critical applications.
6. Executive and Cross-Functional Solution Development
Serves as a hands-on technical partner to leadership and departments when new capabilities, system improvements, or custom software are required.
Activities:
• Work closely with the executive team to evaluate feasibility, technical tradeoffs, implementation paths, risks, timelines, and build-versus-buy decisions.
• Collaborate with the Business Systems Analyst to review process pain points, solution maps, automation opportunities, and system requirements before development begins.
• Provide technical options when a requested approach is not secure, maintainable, cost-effective, or feasible and recommend practical alternatives.
• Participate in discovery sessions with operational teams to understand real-world workflows, exceptions, user roles, and system dependencies.
• Coordinate with software vendors and third-party technical teams when integrations, migrations, or platform limitations require joint troubleshooting.
• Communicate technical issues in clear business language and maintain transparency on risks, blockers, dependencies, and production readiness.
• Continuously evaluate emerging AI development tools, frameworks, infrastructure approaches, and integration technologies that can improve delivery speed or system quality.
Outputs:
• Faster executive decision-making, stronger alignment between business requirements and technical implementation, and scalable solutions that address root operational problems.
REQUIRED QUALIFICATIONS
• 3+ years of professional software development, full-stack development, application development, or comparable hands-on experience.
• Demonstrated ability to build and maintain production web applications using modern front-end and back-end technologies.
• Strong working knowledge of JavaScript/TypeScript and at least one back-end language or runtime such as Node.js, Python, PHP, Ruby, Java, C#, or comparable technology.
• Experience with relational databases, SQL, data modeling, schema changes, migrations, and application-level data validation.
• Hands-on experience designing or consuming REST APIs, webhooks, JSON payloads, authentication flows, and third-party integrations.
• Proficiency with Git/GitHub or comparable version-control workflows, including branching, code review, merge management, and release discipline.
• Experience deploying and supporting applications in cloud or server environments, including Linux/SSH, DNS, environment configuration, SSL/TLS certificates, and production troubleshooting.
• Strong debugging and problem-solving skills with the ability to audit, refactor, and stabilize AI-generated or rapidly prototyped code.
• Working knowledge of application security, access control, secrets management, logging, encryption concepts, and secure handling of sensitive data.
• Ability to communicate effectively with executives, non-technical stakeholders, analysts, vendors, and other technical contributors.
PREFERRED QUALIFICATIONS
• Experience developing technology in healthcare, managed care, care coordination, clinical operations, revenue cycle, or other PHI-sensitive environments.
• Hands-on experience with Lovable, Claude Code, Cursor, Replit, Bolt, or other AI-assisted/vibe-coding environments.
• Experience with Docker, CI/CD pipelines, GitHub Actions, reverse proxies, cloud platforms such as AWS/Azure/GCP, or modern application hosting platforms.
• Experience integrating EMR/EHR, CRM, billing, communications, workflow, and analytics systems.
• Familiarity with healthcare interoperability concepts such as FHIR, HL7, X12, or healthcare data exchange patterns.
• Experience with automation/orchestration platforms such as n8n, Zapier, Make, or comparable tools.
• Experience with infrastructure-as-code, automated testing, vulnerability management, or production observability platforms.
• Bachelor’s degree in Computer Science, Information Systems, or a related technical field; equivalent professional experience may substitute.
FULL SOFTWARE DEVELOPMENT & DEPLOYMENT FRAMEWORK
(To be used for application development, technical delivery expectations, production readiness, and ongoing software governance)
PHASE 1. Discovery, Requirements, and Rapid Prototype
• Clarify the business problem, users, workflows, permissions, data requirements, integrations, exceptions, and expected outcomes.
• Build or refine a rapid proof of concept using AI-assisted/vibe-coding tools where appropriate.
• Identify systems of record, PHI exposure, vendor dependencies, technical constraints, and integration requirements.
• Establish acceptance criteria and define what is required before the application can move beyond prototype status.
Deliverables:
• Functional prototype or technical concept
• Initial architecture and integration map
• Requirements and acceptance criteria
• Preliminary security and PHI considerations
PHASE 2. Code Audit, Architecture, and Production Hardening
• Move the codebase into company-controlled version control and establish a maintainable project structure.
• Review AI-generated code, dependencies, data models, authentication, business logic, and error handling.
• Refactor fragile or duplicated code and remove unsafe shortcuts, exposed secrets, insecure defaults, and unsupported dependencies.
• Define deployment architecture, environments, release strategy, rollback path, and monitoring requirements.
Deliverables:
• Reviewed and controlled code repository
• Production architecture and deployment plan
• Dependency and configuration inventory
• Technical remediation backlog
PHASE 3. Integration, Security, and Compliance Buildout
• Develop required APIs, middleware, webhooks, data mappings, and third-party integrations.
• Implement authentication, authorization, audit logging, encryption, secrets management, validation, and other required security controls.
• Configure staging and production infrastructure, databases, domains, DNS, certificates, backups, and environment-specific settings.
• Validate that PHI and sensitive data are handled only through approved systems and approved technical paths.
Deliverables:
• Integrated staging application
• Security and configuration checklist
• API/integration documentation
• HIPAA/PHI technical safeguard documentation as applicable
PHASE 4. Testing, Deployment, and Go-Live
• Complete functional, integration, regression, permission, performance, error-state, and security testing.
• Support UAT with business owners and resolve blocking defects prior to production launch.
• Deploy through a documented release process with backup, rollback, monitoring, and post-release validation.
• Confirm production certificates, environment variables, integrations, logging, alerts, and access controls are operating as intended.
Deliverables:
• UAT sign-off
• Production release
• Deployment and rollback record
• Runbook and support documentation
PHASE 5. Monitoring, Maintenance, and Continuous Improvement
• Monitor application health, logs, integration failures, performance, certificate status, and security findings.
• Prioritize defects, enhancement requests, technical debt, dependency updates, and security remediation.
• Conduct root cause analysis for recurring incidents and improve code, architecture, or workflows to prevent recurrence.
• Continue using AI-assisted development to accelerate enhancements while maintaining code review, testing, security, and documentation standards.
Deliverables:
• Maintenance backlog
• Incident/root-cause records
• Periodic security and dependency updates
• Continuous release and improvement roadmap
EXPECTATIONS FOR SUCCESS
• 100% of production application code maintained in company-approved version control with documented ownership and release history.
• Production applications use valid SSL/TLS, secured credentials/secrets, appropriate access controls, and documented environment configurations.
• AI-generated or rapidly prototyped code is reviewed, tested, and hardened before being treated as production-ready.
• APIs and integrations include documented mappings, authentication, error handling, monitoring, and support procedures.
• PHI-sensitive systems maintain appropriate technical safeguards, traceability, and audit-ready documentation.
• Measurable reduction in development cycle time without increasing unresolved defects, security exposure, or support burden.
• Clear technical communication with leadership regarding feasibility, risk, architecture, production readiness, and required remediation.
Benefits & Perks
Equal Opportunity Employer
Pacific Health Group is an Equal Opportunity Employer. We are committed to creating an inclusive and equitable workplace where all individuals are treated with dignity and respect. All qualified applicants will receive consideration for employment without regard to race, color, religion or creed, sex (including pregnancy, childbirth, breastfeeding, and related medical conditions), gender, gender identity or gender expression, sexual orientation, national origin or ancestry, citizenship status, physical or mental disability, medical condition (including cancer and genetic characteristics), age (40 and over), marital status, military or veteran status, genetic information, or status as a victim of domestic violence, assault, or stalking. We value diversity in all forms and encourage individuals from historically underrepresented communities to apply.
Pre-Employment Requirements
Employment is contingent upon the successful completion of a background check. Please DO NOT contact employer regarding your application status, thank you!
By continuing you agree to our Terms & Privacy Policy.