About The Role
In this role, you will contribute to improving the security and reliability of a healthcare product by analyzing security requirements and addressing vulnerabilities within a large legacy C++ codebase. Working closely with the client’s developers and architects, you will implement security fixes, maintain memory- and threading-sensitive components, and assess technical and regression risks. You will also contribute to code reviews, testing, debugging, and continuous integration, helping ensure the product remains secure, stable, and reliable.
Responsibilities
- Analyze assigned security requirements and security findings
- Implement security-related changes in the healthcare product
- Remediate vulnerabilities such as unsafe input and length handling, buffer-overflow or memory-corruption risks, and SQL injection
- Work safely with a large legacy C++ codebase, including pointer-based and memory-sensitive logic
- Maintain and improve existing threading components
- Identify technical impact and regression risks before modifying existing functionality
- Participate in code reviews, testing, debugging, and troubleshooting
- Continuously integrate changes into the existing product and collaborate closely with the client’s developers and architects
Requirements
- Strong commercial experience with C++, including mature or legacy C++ codebases
- Strong knowledge of low-level programming, pointers and pointer arithmetic, manual memory management, bounds checking, and memory safety
- Experience preventing or remediating buffer overflows, memory corruption, unsafe input handling, and similar native-code vulnerabilities
- Experience with threading/multithreading; the product is mostly single-threaded but contains threaded components
- Good understanding of object-oriented programming concepts
- Strong debugging and problem-solving skills
- Proficiency in close collaboration with architects, QA engineers, security experts, and existing product developers
- Experience with Qt or similar desktop GUI frameworks is an advantage
- Experience with Windows / Windows Server-based desktop or on-premises products is an advantage
- Good SQL knowledge and understanding of secure database access; Oracle Database experience is an advantage
- Experience with ISAM or other legacy data-storage technologies is an advantage
- Experience with secure software development and remediation of documented security findings is strongly preferred