VP, Product Security

2 weeks ago


Phoenix, United States NextGen Healthcare Full time

Job Description:

The VP, Product Security will lead a group of Product and Application Security professionals to build and maintain an effective Product Security Program and Secure Development Lifecycle at NextGen Healthcare. The ideal candidate will collaborate closely with Product and R&D teams to define and partner on appropriate security controls across NextGen products and platforms, including NextGen SaaS offerings and platforms. This team will work as trusted technical and process advisors in our areas of specialty to inform strategy and the future direction of Information Security inside NextGen, in various product and services offerings, and across NextGen customer related discussions. This team will also have responsibility for selection, acquisition, design, development and implementation of new tools, solutions, functionality, and frameworks that include people, process, and technology components.
  • Build and lead a high performing Product Security team and drive efforts to address internal, external, and emerging application security risks throughout the organization.
  • Develop key partnerships with executive leadership, engineering, and product teams to enhance the organization's security program, including customer MFA strategies.
  • Assess, design, implement, automate, and document security solutions and processes for K8s, and Cloud environments.
  • Leverage Agile methodologies to design, develop and deliver application security strategy, throughout the CI/CD lifecycle, including but not limited to the operating model, staffing and execution plans as needed.
  • Implement "security as code" using cloud services and CI/CD components and integrations.
  • Work with the Software Engineering teams to ensure that application security risks are effectively identified using market leading tools such as SAST, DAST, SCA etc., and appropriately with the right balance between security and operations, including security for Mobile applications.
  • Build and run a Security Champions program to integrate security culture into the software development operational cadence.
  • Be a product security evangelist who can translate security concepts into language that is meaningful to varying audiences, including business and technical leaders. Integrate new and existing security tools, standards, and processes into the development life cycle, including static analysis and runtime testing tools.
  • Conduct business level security architecture assessments to evaluate existing security program and cloud application architecture, identify weaknesses and make recommendations.
  • Ensure appropriate developer security awareness, culture, and mindset through a variety of outreach programs.
  • In partnership with Software Engineering and Product teams, design, implement, and maintain a Secure Development Lifecycle as part of the organization's SDLC.
  • Manage security assessments, penetration testing, and bug bounty programs to ensure the continuous security oversight of the NextGen Healthcare environment, platforms, and applications.
  • Lead the team in the development and evolution of security roadmaps, embodiment of strategic plans, understanding controls and process gaps, providing architectural vision, and enabling the larger information security team.
  • Working closely with business groups and the engineering manager, this role will enable the architects to define and deliver innovative architectures to support the continued maturity growth and efficiency of NextGen's information security services.
  • Ensure applications, networks, systems and Cloud services are planned, designed, developed, implemented, and monitored in accordance with security controls related to SOC 2, ISO 27001, HITRUST requirements and the NextGen Information Security Policy.

Other Key Management Responsibilities:

  • Hire, grow and retain team members to expand the team and its capabilities within the organization.
  • Perform assessments of security tools, vendors, and solutions to support information security roadmap initiatives
  • Act as an advocate for mentoring and technical career growth in the information security organization
  • Act as a liaison with other internal NextGen teams or driving new capabilities, product investments, and research to fill coverage gaps.
  • Provide assistance and guidance to Sales and Support teams across various customer engagements.
  • Regularly provide key performance and risk indicator metrics for management visibility into the status, health, and maturity of the Information Security Program at NextGen.
  • Perform other duties that support the overall objective of the position.

Education:

  • Bachelor's degree.
  • Or, any combination of education and experience which would provide the required qualifications for the position

Required Experience/Skills:

  • Extensive background in Product Security management and implementation in an Agile and CI/CD environment leveraging Cloud architecture and technologies (AWS primarily but including Azure).
  • Technical experience with design and implementation of security containers, including Kubernetes.
  • Minimum of 8 years progressive experience in an information security management role, with an emphasis in one or more of the following areas:Security Architecture, Security Engineering, Security Product Management, Software Engineering.
  • Demonstrated understanding of Software Engineering and Development technologies, methodologies, and implementations.
  • Minimum of 7 year's management experience leading high visibility/impact functions, including the management of senior technologists and architects.
  • Strong background in ensuring secure application development, from front-end sites, API layers, and data management layers.
  • Technical experience with various authentication schemes, SAML integrations, federation of trusts, etc.
  • Strong background in securing SaaS platforms, and other multi-tenant, Cloud-architected environments.
  • Extensive background in information security services and operations and the people, process, and technology components that make them successful.
  • Significant experience in fulfilling business needs through the development of solutions through well-organized processes.
  • Experience in client-facing discussions with new and existing customers to discuss security controls and implementations.
  • Significant Service Management and or vendor management experience.
  • Must be able to communicate at a technical and business level and be a bridge between the two.
  • Appropriate certifications a plus.

The company has reviewed this job description to ensure that essential functions and basic duties have been included. It is intended to provide guidelines for job expectations and the employee's ability to perform the position described. It is not intended to be construed as an exhaustive list of all functions, responsibilities, skills and abilities. Additional functions and requirements may be assigned by supervisors as deemed appropriate. This document does not represent a contract of employment, and the company reserves the right to change this job description and/or assign tasks for the employee to perform, as the company may deem appropriate.

NextGen Healthcare is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.



  • Phoenix, United States CareerBuilder Full time

    VP of Product Management About the Company Innovative internet security company offering Next Gen SIEM & XDR solutions Industry Internet Type Privately Held Founded 2017 Employees 51-200 Funding $76-$100 million Categories Computers Design Services Integration Services IT Management Technology Information Technology & Services Security About the Role The...


  • Phoenix, United States 1st United Door Technologies, Inc. Full time

    Job Description Job Description Job descriptionSummaryThe VP-Information Technology (VP/IT) will be a key member of the leadership team and will report to the CEO. This role collaborates closely with the Executive Leadership Team and other departments. The VP/IT is a strategic executive and will be responsible for the overall management and direction of the...


  • Phoenix, United States 1st United Door Technologies, Inc. Full time

    Job Description Job Description Job description Summary The VP-Information Technology (VP/IT) will be a key member of the leadership team and will report to the CEO. This role collaborates closely with the Executive Leadership Team and other departments. The VP/IT is a strategic executive and will be responsible for the overall management and direction of...


  • Phoenix, United States 1st United Door Technologies Full time

    Job DescriptionJob DescriptionJob descriptionSummaryThe VP-Information Technology (VP/IT) will be a key member of the leadership team and will report to the CEO. This role collaborates closely with the Executive Leadership Team and other departments. The VP/IT is a strategic executive and will be responsible for the overall management and direction of the...


  • Phoenix, United States 1st United Door Technologies Full time

    Job DescriptionJob DescriptionJob descriptionSummaryThe VP-Information Technology (VP/IT) will be a key member of the leadership team and will report to the CEO. This role collaborates closely with the Executive Leadership Team and other departments. The VP/IT is a strategic executive and will be responsible for the overall management and direction of the...


  • Phoenix, Arizona, United States Motion Recruitment Full time

    A healthcare client is looking to bring on a remote, contract-to-hire Cloud Security Architect to help build out their security infrastructure and strengthen their security posture for their new line of business going live at the start of 2025. This person will report into the VP/CISO and act as his "right-hand" while they work on building out a security...


  • Phoenix, United States Applied Business Communications (ABcom) Full time

    Job DescriptionJob DescriptionABcom, a prominent provider of design and build of business critical network infrastructures for data centers and all business types is adding an experienced Security Technician to its growing team!The Technician is responsible for successful project deployments and troubleshooting under the direction of project managers,...


  • Phoenix, United States CLevelCrossing Full time

    Job Information Humana Associate VP, Marketing - Home Segment in Phoenix Arizona Description Humana is a Fortune 50 market leader in integrated healthcare whose dream is to help people achieve lifelong well-being. As a company focused on the health and well-being of the people we serve, Humana starts from within, and is committed to providing progressive...

  • Product Owner

    11 hours ago


    Phoenix, United States STIAOS Technologies Full time

    We are looking for Product Owner/Product Manager with following skills: *Product Owner/Manager *Secure File Transfer(SFT) *Managed File Transfer(MFT) Job Description: *Should have Technical Background *Should have experience with MFT/SFT Required Skills: Should have hands on experience with Agile Methodologies ,Scrum, Rally,JIRA,Roadmap, Strategy, Vision


  • Phoenix, Arizona, United States Applied Business Communications (ABcom) Full time

    ABcom, a prominent provider of design and build of business critical network infrastructures for data centers and all business types is adding an experienced Security Technician to its growing team! The Technician is responsible for successful project deployments and troubleshooting under the direction of project managers, department supervisors, foremen,...


  • Phoenix, United States CLevelCrossing Full time

    Job Information Humana AVP Enterprise Architecture Activation in Phoenix Arizona Description The Associate VP, Enterprise Architecture translates business needs into technical systems solutions and architectural roadmaps. The Associate VP, Enterprise Architecture requires a in-depth understanding of how organization capabilities interrelate across segments...

  • Production Worker

    2 weeks ago


    Phoenix, United States STSS Recycling Full time

    Job DescriptionJob DescriptionSTSS Recycling is looking for General Production Workers with the skill set's below and good attitudes-Hand Tool Expierence-General Mechanical Ability-Reliable transportation a must-2 Valid forms of ID-Shift hours 5:00 a.m.-1:45 p.m. (these are summer hours, normal hours 6am-2:45pm)  Company DescriptionSTSS Recycling is...


  • Phoenix, United States DEEM, LLC Full time

    Overview Our mission is simple. We make business travel less complicated for travelers, less costly for employers and more profitable for service providers. Using our industry-leading software solutions, employees book travel and car service and report those expenses faster and more easily than ever before. Corporations control costs more effectively. Travel...


  • Phoenix, United States Forhyre Full time

    Job DescriptionJob DescriptionWe are looking for a Lead Information Security Architect who will be responsible for developing and maintaining a comprehensive information security architecture program and representing information security requirements for all technology solutions and business processes covering multiple technical disciplines, such as systems...


  • Phoenix, Arizona, United States BAE Systems Full time

    Job Description The Phoenix, Arizona site is an industry leader in design, development and support of crashworthy armored and unarmored seating solutions for aviation and blast seating for ground vehicles. Since the site was established in 1973, it has been the primary provider of US Military helicopter seats. We are currently looking for a Material and...


  • Phoenix, United States Mfused Full time

    SUMMARY OF ROLE: Are you ready to be at the forefront of a rapidly evolving and dynamic industry? Join MFUSED, a leading Cannabis company, in our quest to redefine the boundaries of innovation and quality. We are seeking a visionary VP of Finance to play a pivotal role in our ambitious expansion plans, both in the United States and globally. If you're a...


  • Phoenix, United States Concentrix Full time

    Expert Technology Consultant (Evaluations) Job DescriptionCustomer/Partner-facing roles able to drive sales opportunities based on a 300/400-level knowledge of products, including Microsoft 365, Security, and Azure, as well as Block 64 technology.Job DescriptionSecure customer wins for Cloud: Maximize up-sell and cross-sell opportunities collaborating with...


  • Phoenix, United States Diverse Lynx Full time

    Cyber Security Engineer Day 1 Onsite: 18850 N 56th Street, Phoenix, AZ 85054 Cyber Security Engineer with Threat modelling experience, Responsible for designing and implementation of threat models. Analyse the Network security and suggest remediations for issues. Must HAVE's: Should have experience doing Security assessments. Should have security background....


  • Phoenix, United States CareerBuilder Full time

    Job summary AI Data security for PII and proprietary information, usage policies, definitions Establish auditing and compliance mechanism Align Gen AI security needs with enterprise security framework Experience in design, build and maintain security frameworks for an enterprise with relevant tools set A. App & Cyber Security Engineer with Info sec Analyst...


  • Phoenix, United States Diverse Lynx Full time

    Job summary AI Data security for PII and proprietary information, usage policies, definitions Establish auditing and compliance mechanism Align Gen AI security needs with enterprise security framework Experience in design, build and maintain security frameworks for an enterprise with relevant tools set A. App & Cyber Security Engineer with Info sec...