VP, Product Security

2 weeks ago


Arizona City, United States NextGen Healthcare Full time
Job Description:
The VP, Product Security will lead a group of Product and Application Security professionals to build and maintain an effective Product Security Program and Secure Development Lifecycle at NextGen Healthcare. The ideal candidate will collaborate closely with Product and R&D teams to define and partner on appropriate security controls across NextGen products and platforms, including NextGen SaaS offerings and platforms. This team will work as trusted technical and process advisors in our areas of specialty to inform strategy and the future direction of Information Security inside NextGen, in various product and services offerings, and across NextGen customer related discussions. This team will also have responsibility for selection, acquisition, design, development and implementation of new tools, solutions, functionality, and frameworks that include people, process, and technology components.

  • Build and lead a high performing Product Security team and drive efforts to address internal, external, and emerging application security risks throughout the organization.
  • Develop key partnerships with executive leadership, engineering, and product teams to enhance the organization's security program, including customer MFA strategies.
  • Assess, design, implement, automate, and document security solutions and processes for K8s, and Cloud environments.
  • Leverage Agile methodologies to design, develop and deliver application security strategy, throughout the CI/CD lifecycle, including but not limited to the operating model, staffing and execution plans as needed.
  • Implement "security as code" using cloud services and CI/CD components and integrations.
  • Work with the Software Engineering teams to ensure that application security risks are effectively identified using market leading tools such as SAST, DAST, SCA etc., and appropriately with the right balance between security and operations, including security for Mobile applications.
  • Build and run a Security Champions program to integrate security culture into the software development operational cadence.
  • Be a product security evangelist who can translate security concepts into language that is meaningful to varying audiences, including business and technical leaders. Integrate new and existing security tools, standards, and processes into the development life cycle, including static analysis and runtime testing tools.
  • Conduct business level security architecture assessments to evaluate existing security program and cloud application architecture, identify weaknesses and make recommendations.
  • Ensure appropriate developer security awareness, culture, and mindset through a variety of outreach programs.
  • In partnership with Software Engineering and Product teams, design, implement, and maintain a Secure Development Lifecycle as part of the organization's SDLC.
  • Manage security assessments, penetration testing, and bug bounty programs to ensure the continuous security oversight of the NextGen Healthcare environment, platforms, and applications.
  • Lead the team in the development and evolution of security roadmaps, embodiment of strategic plans, understanding controls and process gaps, providing architectural vision, and enabling the larger information security team.
  • Working closely with business groups and the engineering manager, this role will enable the architects to define and deliver innovative architectures to support the continued maturity growth and efficiency of NextGen's information security services.
  • Ensure applications, networks, systems and Cloud services are planned, designed, developed, implemented, and monitored in accordance with security controls related to SOC 2, ISO 27001, HITRUST requirements and the NextGen Information Security Policy.
Other Key Management Responsibilities:
  • Hire, grow and retain team members to expand the team and its capabilities within the organization.
  • Perform assessments of security tools, vendors, and solutions to support information security roadmap initiatives
  • Act as an advocate for mentoring and technical career growth in the information security organization
  • Act as a liaison with other internal NextGen teams or driving new capabilities, product investments, and research to fill coverage gaps.
  • Provide assistance and guidance to Sales and Support teams across various customer engagements.
  • Regularly provide key performance and risk indicator metrics for management visibility into the status, health, and maturity of the Information Security Program at NextGen.
  • Perform other duties that support the overall objective of the position.
Education:
  • Bachelor's degree.
  • Or, any combination of education and experience which would provide the required qualifications for the position
Required Experience/Skills:
  • Extensive background in Product Security management and implementation in an Agile and CI/CD environment leveraging Cloud architecture and technologies (AWS primarily but including Azure).
  • Technical experience with design and implementation of security containers, including Kubernetes.
  • Minimum of 8 years progressive experience in an information security management role, with an emphasis in one or more of the following areas:Security Architecture, Security Engineering, Security Product Management, Software Engineering.
  • Demonstrated understanding of Software Engineering and Development technologies, methodologies, and implementations.
  • Minimum of 7 year's management experience leading high visibility/impact functions, including the management of senior technologists and architects.
  • Strong background in ensuring secure application development, from front-end sites, API layers, and data management layers.
  • Technical experience with various authentication schemes, SAML integrations, federation of trusts, etc.
  • Strong background in securing SaaS platforms, and other multi-tenant, Cloud-architected environments.
  • Extensive background in information security services and operations and the people, process, and technology components that make them successful.
  • Significant experience in fulfilling business needs through the development of solutions through well-organized processes.
  • Experience in client-facing discussions with new and existing customers to discuss security controls and implementations.
  • Significant Service Management and or vendor management experience.
  • Must be able to communicate at a technical and business level and be a bridge between the two.
  • Appropriate certifications a plus.


The company has reviewed this job description to ensure that essential functions and basic duties have been included. It is intended to provide guidelines for job expectations and the employee's ability to perform the position described. It is not intended to be construed as an exhaustive list of all functions, responsibilities, skills and abilities. Additional functions and requirements may be assigned by supervisors as deemed appropriate. This document does not represent a contract of employment, and the company reserves the right to change this job description and/or assign tasks for the employee to perform, as the company may deem appropriate.

NextGen Healthcare is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
  • VP Product Security

    5 days ago


    Long Island City, United States Altice USA Full time

    Altice USA is a cutting-edge communications, media, and tech company. We connect people to what matters most to them; texting with friends, advertising that resonates, or binge watching their favorite show. Our differentiated approach centers around technologies that push the envelope and deliver the ultimate customer experience. We're building a workforce...

  • VP of Product

    2 weeks ago


    Arizona City, United States SnapDragon Associates LLC Full time

    About the Company: We are currently working with a well-established manufacturer of specialty window and door products. A fast-growing organization that is looking to break through into new markets while they look at expansion. They serve a diverse customer base including window and door manufacturers, as well as millwork wholesalers with door-hanging...


  • Redwood City, United States Zuora Full time

    Company Overview At Zuora, we do Modern Business. We're helping people subscribe to new ways of doing business that are better for people, companies and ultimately the planet. It's an approach resulting from the shift to the Subscription Economy that puts customers first by building recurring relationships instead of one-time product sales and focuses on...


  • Foster City, United States Standard Fiber LLC. Full time

    VP of Business Development Company: Standard Fiber LLC. Location: Foster City, CA Position Type: Full Time Experience: 2 years Education: Unspecified VP of Business Development Plan, direct, and coordinate the distribution of imported home textiles, ensuring products are efficiently moved from suppliers to customers; develop, implement, and manage sales...

  • VP Product

    6 days ago


    Jersey City, United States Morpheus Talent Solutions Full time

    Vice President of Product (LLM) - Senior Leader Tri-State Area or Eastern Time Zone, Canada $180k - $220k basic + bonus Morpheus are currently partnered with a leader in the Gen AI consulting space in the U.S. We are looking for a talented and experienced Vice President of Product (LLM) to drive the development of AI-driven products and solutions tailored to...

  • VP Product

    2 weeks ago


    Jersey City, United States Morpheus Talent Solutions Full time

    Vice President of Product (LLM) - Senior LeaderTri-State Area or Eastern Time Zone, Canada$180k - $220k basic + bonus Morpheus are currently partnered with a leader in the Gen AI consulting space in the U.S. We are looking for a talented and experienced Vice President of Product (LLM) to drive the development of AI-driven products and solutions tailored to...


  • Arizona City, United States Verra Mobility Full time

    Who we are… Verra Mobility is a global leader in smart mobility. We develop technology-enabled solutions that help the world move safely and easily. We are fostering the development of safe cities, working with police departments and municipalities to install over 4,000 red-light, speed, and school bus stop arm safety cameras across North America. We are...


  • Arizona City, United States Verra Mobility Full time

    Who we are Verra Mobility is a global leader in smart mobility. We develop technology-enabled solutions that help the world move safely and easily. We are fostering the development of safe cities, working with police departments and municipalities to install over 4,000 red-light, speed, and school bus stop arm safety cameras across North America. We are also...

  • Head of Security

    7 days ago


    Arizona, United States Rocket Lawyer Full time

    California / Arizona / North Carolina / Utah / ColoradoTechnology – Cloud & Data Engineering /Full-time /HybridAbout Rocket LawyerWe believe everyone deserves access to affordable and simple legal services.Founded in 2008, Rocket Lawyer is the largest and most widely used online legal service platform in the world. With offices in North America and Europe,...


  • Phoenix, Arizona, United States Applied Business Communications (ABcom) Full time

    ABcom, a prominent provider of design and build of business critical network infrastructures for data centers and all business types is adding an experienced Security Technician to its growing team! The Technician is responsible for successful project deployments and troubleshooting under the direction of project managers, department supervisors, foremen,...


  • Kansas City, MO, United States LHH Full time

    LHH has partnered with a large Kansas City based company to find their next Vice President of Finance. This is an Executive level position and will play a pivotal role in the direction of the company. Reporting to the CFO, the VP of Finance will lead the Financial Analysis and Planning team and will be a key strategic partner to the business. Qualified...


  • Oklahoma City, Oklahoma, United States Elevance Health Full time

    A proud member of the Elevance Health family of companies, Paragon Healthcare brings over 20 years in providing life-saving and life-giving infusible and injectable drug therapies through our specialty pharmacies, our infusion centers, and the home setting.Staff VP Manufacturer Relations & Trade (Paragon)Location: May be located within 50 miles of an...

  • VP of Engineering

    1 week ago


    Oklahoma City, United States Invitation Homes Full time

    Job Sum m ar y This is a Hybrid role located in Dallas, TX. If you are out of state and willing to relocate to Dallas, TX, please apply. Invitation Homes is pioneering a new industry and needs dedicated, innovative, and enthusiastic technologists to support our innovation and growth. As the nation’s premier home leasing company, we develop advanced...


  • Arizona City, United States Industry Analysts , Inc. Full time

    Position : IT Systems Analyst Company : Flex Technology Group Job Location : Mesa, AZ Flex Technology Group is a privately held corporation, headquartered in Mesa, Arizona with offices across the U.S. Since our founding in 2005, we have achieved unparalleled growth within the industry. Our primary services include managed print solutions, as well as offering...


  • Kanawha City, United States VP Management Full time

    Job DescriptionJob DescriptionFull Job DescriptionWe are looking for a thorough housekeeper with excellent cleanliness standards to attend all areas of our facilities. The goal is to enhance customer experience by keeping our facilities in clean and orderly condition.ResponsibilitiesClean and tidy all areas to the standard cleanliness within time...


  • Foster City, CA, United States Qualys Full time

    Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!As a Director of Product Management, you will own product execution for Enterprise TruRisk capability which will provide organizations to get a unified view of risk across their infrastructure integrating with various Qualys platform...


  • Salt Lake City, United States Remotely Full time

    This is a remote position. Sr. Product Marketing Manager - Endpoint Security (3-5 year experience, remote) Be part of our future! This job posting builds our talent pool for potential future openings. We'll compare your skills and experience against both current and future needs. If there's a match, we'll contact you directly. No guarantee of immediate...


  • Kansas City, MO, United States EquipmentShare Full time

    EquipmentShare is Hiring a Category Manager, Material Handling ProductsEquipmentShare is searching for a Category Manager responsible for sourcing Material Handling Products and related equipment for our rapidly growing rental fleet based out of our corporate office in Columbia, MO, to support our team as the department continues to grow.  Salary range:...


  • Jersey City, United States Resource Logistics Full time

    Skills - AppScan, Clienther, AWS Secrets Manager, Burpsuite, Cloud Security, CxSAST, Information Security & Cybersecurity, Metasploit, Nessus, Nmap, PaaS - Security, SAP GRC, ServiceNow GRC, Web Application Scanning (WAS), Wireshark Netskope Cloud Access Security Broker (CASB), SASE/SSE Network Engineering, Zscaler Security Service Edge Security Consulting:...


  • Texas City, United States Atechstar Full time

    Job descriptionKey Responsibilities 1. Cloud Security Implementation Architect/SME would be responsible for the build and integration primarily of AWS GuardDuty Security Hub CloudTrail CloudWatch Azure VNET Load balancer resource group 2. Responsible to perform security assessment having the knowledge and acumen of cloud risk management 3....