logo[мetahunt]
> DOU

Solutions Architect

Riseapps
format:Remotecompany:Outsource
fhirhl7dicomawsazuregoogle cloudany one ofawsapievent-driven architectureeltetlany one ofeltsqlnosqldata warehousingoauth 2.0openid connectrbacthreat modelingpenetration testingllmrag
experience8+ years
domainHealthTech
> full description

Ми шукаємо, наразі, роль парттайм, з майбутньою можливістю перейти на фуллтайм.

We build software for healthcare organizations, from early-stage startups to established digital health vendors, providers and payers. We are looking for a hands-on solution architect who joins presale conversations and turns an ambiguous healthcare idea into a credible architecture, a scoped prototype and an estimate that our delivery team can stand behind. In this role, AI innovation and governance go together: every proposal should be fast to prototype and safe to put in front of a regulator, a compliance officer or a hospital security team.

What you will do:

  • Join discovery, RFP and technical pitch calls with founders, clinical leaders, operations and IT teams, and explain architecture decisions in plain language.
  • Design architectures for EHR/EMR integration, patient data exchange and healthcare workflows such as scheduling, eligibility verification, referrals, prior authorization, claims and revenue cycle management (RCM).
  • Build AI-assisted prototypes and demos on sandboxes and synthetic data, and state clearly what is real, what is simulated and what remains for production.
  • Define the AI governance approach for each proposal: data handling, model selection, human oversight, validation, monitoring and audit trail.
  • Separate a proof of concept from an MVP, choose the single use case that proves feasibility, and defend that choice.
  • Produce estimates (phases, stories, assumptions, risks) together with Delivery, and rebuild them when scope changes.
  • Review client-supplied architecture documents and AI-generated specs critically, keeping what is sound and challenging what is not.
  • Complete customer security questionnaires and due diligence, and prepare HIPAA, SOC 2 and HITRUST evidence for prospects.
  • Support partner conversations with integration platforms, clearinghouses and EHR vendors.
  • Hand over every won project to Delivery with a clean architecture, documented assumptions and open risks.

Healthcare domain expertise:

  • Systems and data: hands-on experience with EHR/EMR platforms (Epic, Cerner/Oracle Health, athenahealth, eClinicalWorks, NextGen or similar), practice management and patient portals.
  • Standards: FHIR R4, SMART on FHIR, CDS Hooks, Bulk FHIR, HL7 v2 (ADT, ORM, ORU), C-CDA/CCD, and DICOM basics.
  • Administrative and financial flows: X12 270/271 (eligibility), 278 (referrals and prior authorization), 837/835 (claims and remittance), clearinghouses, payer and provider connectivity, denial management and the RCM lifecycle.
  • Coding and terminology: ICD-10, CPT/HCPCS, SNOMED CT, LOINC, RxNorm, NPI, and the mapping and normalization problems between them.
  • Data governance: PHI and PII handling, minimum necessary access, de-identification (Safe Harbor and Expert Determination), consent management (including 42 CFR Part 2 where relevant), master patient index and patient matching, and audit logging.
  • Regulation and policy: HIPAA Privacy, Security and Breach Notification rules, 21st Century Cures Act and information blocking, ONC/ASTP certification (HTI rules), CMS interoperability and prior authorization rules, and TEFCA.
  • Quality and value-based care: HEDIS, eCQM, CQL, care gaps, risk adjustment and population health analytics.

AI governance in regulated environments:

  • Practical knowledge of frameworks and rules such as NIST AI RMF, ISO/IEC 42001, ONC decision support transparency requirements, FDA guidance on clinical decision support and software as a medical device, and the EU AI Act for clients operating in Europe.
  • Experience designing human-in-the-loop controls, escalation to clinical or operational staff, and clear boundaries on what an AI agent may and may not do.
  • Ability to handle PHI in LLM workflows: vendor BAAs, data residency, prompt and log redaction, no training on customer data, retention limits and access control.
  • Methods for validating and monitoring AI: evaluation sets, hallucination and bias testing, drift monitoring, versioning of models and prompts, and incident response.
  • Documentation habits that regulators and buyers expect: model cards, risk assessments, data lineage, decision logs and explainability for non-technical reviewers.

Technical requirements:

  • 8+ years in software engineering and solution architecture, including delivery of SaaS and mobile products at scale.
  • 3+ years in healthtech integration or digital health product work.
  • Cloud-native architecture on AWS, Azure, or GCP using HIPAA-eligible services, with encryption, key management, network isolation, and least-privilege access.
  • Integration engines and platforms (Mirth/NextGen Connect, Rhapsody, Redox, Health Gorilla, Medplum, Stedi or similar), including API design, event-driven patterns and reliable message handling.
  • Data engineering: ETL/ELT pipelines, SQL and NoSQL, data warehouses, streaming, analytics and BI.
  • Security practices: OAuth 2.0 and OIDC, RBAC, secrets management, secure SDLC, threat modeling and penetration test readiness.
  • Experience with SOC 2 or HITRUST programs, and with third-party risk questionnaires from health systems and payers.
  • Hands-on AI engineering: LLM APIs, agent orchestration, RAG, speech and messaging channels, cost and latency management, and prompt evaluation.
  • Rapid prototyping with AI coding tools, and the judgment to know when generated code must be rebuilt from a clean specification.
  • Reliability and observability for clinical and operational workflows: monitoring, auditability, disaster recovery and SLAs.
  • Mobile and web accessibility awareness (WCAG, Section 508) for patient-facing products.
  • Testing strategy for regulated software: validation evidence, traceability and change control.

Nice to have:

  • Experience at an EHR vendor, clearinghouse, payer, health system or healthtech startup.
  • Voice AI, SMS or omnichannel patient engagement experience.
  • Experience with ambient documentation, coding assistance or prior authorization automation.
  • Knowledge of medical device software standards (IEC 62304, ISO 14971).
  • Public speaking, writing or open-source contributions in healthcare IT.
Відгукнутись на вакансію