Are you interested in harnessing technology and AI to transform healthcare?
At XiFin, we believe a healthier, more efficient healthcare system starts with strong financial and operational foundations. Our innovative technologies help diagnostic providers, laboratories, and healthcare systems manage complexity, drive better outcomes, and stay focused on what matters most: patient care.
We’re on a mission to simplify the business side of healthcare—and we know that mission takes people from all backgrounds and experiences. Whether you’re early in your career or bringing years of expertise, we welcome your perspective, your curiosity, and your passion. We value individuals who ask questions, challenge the status quo, and want to grow while making a real difference.
About the Role
XiFin has a deep commitment to shifting left and empowering our engineering and DevOps teams to control their development process while designing security and ensuring compliance with our security requirements. This high-level position is our application security evangelist: You will be the guide for our product, engineering and DevOps team to build security into all of their activities and manage the security processes relating to our development and product activities.
This position will be located at our offices in San Diego, CA.
Must be willing to travel 25% domestically.
How you will make an impact:
In this role, you’ll:
- Serve as a key security partner for product, engineering, and DevOps teams to embed security requirements into design, development, and release activities, supporting secure by design and secure by default outcomes across the SDLC.
- Serve as the application security subject matter expert in formal change and release review processes, ensuring security requirements are defined, reviewed, and enforced prior to production deployment.
- Drive proactive risk identification and mitigation by leading threat modeling workshops and architectural risk assessments to inform secure design decisions and reduce systemic vulnerabilities.
- Contribute to and influence the evolution of application security strategy, standards, and metrics to support continuous maturity improvement and measurable outcomes within the secure development program.
- Own the operational effectiveness and continuous improvement of automated application security tooling and CI/CD pipeline integrations (e.g., SAST, DAST, SCA, security checks) to enable scalable, repeatable secure software development practices.
- Lead and coordinate internal and third-party penetration testing and dynamic security assessments, ensuring vulnerabilities are identified, validated, prioritized, and communicated to support remediation and risk reduction.
- Lead the development and delivery of application security policies, standards, training, and developer mentoring to strengthen secure coding practices and organizational security awareness.
- Ensure application security requirements are validated against recognized frameworks and standards (e.g., OWASP ASVS, NIST guidance, CWE), including documented security impact analysis for architectural and design changes.
- Perform security focused code reviews and third-party software assessments to identify vulnerabilities, insecure patterns, and supply chain risks in accordance with secure acquisition and reuse practices.
- Communicate application security risks, vulnerabilities, and remediation status to technical and business stakeholders in a clear, timely, and actionable manner to support informed risk based decision making.
What you will bring to the team:
We’re looking for someone with a growth mindset and a passion for learning. You might be a great fit if you:
- Has effective communication and collaboration skills to influence product and engineering teams, lead training, and be the application security subject matter expert.
- Approach work with curiosity and ownership, proactively identifying opportunities to improve processes.
- Enjoy building trusted relationships and partnering cross-functionally to solve complex problems.
- Demonstrate strong attention to detail while balancing multiple priorities.
- Adapt well in a fast-paced, evolving healthcare environment.
Skills and experience you have:
You don’t need to check every box. We will consider a combination of education and experience, including:
- Bachelor’s degree in Computer Science or a relevant field. Advanced degree a plus
- Deep experience with secure SDLC practices, integrating security into design, development, and release processes.
- Practical threat modeling skills, including running or contributing to design reviews and identifying architectural risks in complex systems.
- Proficiency in security-focused code review across at least one major stack (for example Java, .NET, JavaScript/TypeScript, Python) and ability to spot insecure patterns.
- Hands-on experience with application security testing tools and techniques, including SAST, DAST, and manual web/API testing.
Why XiFin?
We’re more than just a healthcare technology company—we’re a team that cares about people.
Here’s a glimpse at what we offer:
- Comprehensive health benefits including medical, dental, vision, and telehealth
- 401(k) with company match and personalized financial coaching to support your financial future
- Health Savings Account (HSA) with company contributions
- Wellness incentives that reward your preventative healthcare activities
- Tuition assistance to support your education and growth
- Flexible time off and company-paid holidays
- Social and fun events to build community at our locations!
Pay Transparency
At XiFin, we believe in pay transparency and fairness. The expected annual salary range for this role is: $180,000-$205,000
Depending on your qualifications, you may be considered for either an Associate Specialist or Specialist title. Final compensation will be determined during the selection process and may vary based on experience, skills, and geographic location.
Accessibility & Accommodations
We’re committed to providing an inclusive and accessible experience for all applicants. If you need a reasonable accommodation during the application process, please contact us at 858-436-2901.
Equal Opportunity Employer
XiFin is proud to be an equal opportunity employer. We value diverse voices and do not discriminate on the basis of race, color, religion, national origin, gender, gender identity, sexual orientation, disability, age, veteran status or any other basis protected by law.
Ready to apply?
We’d love to hear from you—even if you’re not sure you meet every qualification. If you're excited about the role and believe you can contribute to our team, please apply. Let's build something meaningful together.