--- title: 'Cybersecurity Engineer – Engineering at Practice By Numbers' canonical: 'https://feeny.ai/job/cybersecurity-engineer-engineering-practice-by-numbers-gurugram-haryana-42dk2smrr1ya' type: 'job' last_seen: '2026-09-09' --- # Cybersecurity Engineer – Engineering at Practice By Numbers - **Company:** Practice By Numbers - **Location:** Gurugram Haryana, India - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-09-03 - **Last confirmed live:** 2026-09-09 - **Apply:** https://jobs.gem.com/practice-by-numbers/am9icG9zdDpfhlag3sbwhPwXOcEaJVnn ## Job description Cybersecurity Engineer – Engineering Experience: 6+ Years Location: Kolkata, India / Gurgaon, India (On-site) Reports to: Head of Engineering / Security Lead Employment Type: Full-time ## About Practice by Numbers Practice by Numbers (PbN) is a fast-growing SaaS platform helping healthcare organizations leverage data, automation, patient engagement, and operational intelligence to improve business performance and patient outcomes. We build highly scalable cloud-native products serving thousands of customers across North America. We handle protected health information at scale. Security is not a compliance checkbox for us — it is a product requirement. We are looking for a Cybersecurity Engineer who can secure a live, fast-moving cloud platform hands-on. ## Role Overview As a Cybersecurity Engineer, you will own the security posture of our AWS cloud infrastructure and our Python/Django, FastAPI, Node.js, and React applications. You will find real vulnerabilities, fix them or drive them to closure, and build the controls and automation that stop the same class of issue from recurring. This is a hands-on, technical role. You will read code, review architecture, run tests against our own systems, tune detections, respond to incidents, and carry the technical side of our HIPAA and SOC 2 obligations. You will work directly with engineering rather than filing findings over a wall. The ideal candidate has genuine application and cloud security depth, understands how software is actually built and deployed, and can tell a real risk from a scanner artifact. ## Key Responsibilities Application Security - Perform secure code reviews across Python/Django/FastAPI, Node.js, and React/TypeScript codebases. - Threat model new features and services; identify design-level risks before they ship. Own SAST, DAST, dependency, secret, and container scanning — including triage, false-positive reduction, and driving fixes to closure. - Run white-box (source-assisted), grey-box (authenticated, partial-knowledge), and black-box (external, zero-knowledge) security testing against our own applications and APIs. - Test authentication, authorization, multi-tenant isolation, and session handling; hunt for IDOR, privilege escalation, and tenant data leakage. - Review API security: input validation, rate limiting, authorization enforcement, and data exposure. Define and maintain secure coding standards; coach engineers through review rather than mandate. Cloud & Infrastructure Security - Harden AWS infrastructure — IAM least privilege, VPC and network segmentation, security groups, encryption at rest and in transit, S3 and RDS controls. - Review Terraform and infrastructure-as-code for security defects; add policy-as-code guardrails. Secure containerized workloads (Docker, ECS/Fargate or EKS) — image hygiene, runtime configuration, secrets handling. - Own secrets management practices (AWS Secrets Manager, SOPS, Vault) and key rotation. Continuously audit cloud configuration drift and remediate exposure. Security Operations & Incident Response - Build and tune detection and alerting across cloud, application, and access logs. Investigate security alerts; separate real signal from noise. - Lead incident response — containment, forensics, root cause, and blameless post-incident review. Maintain and exercise the incident response plan, including breach-notification readiness. Run vulnerability management end to end: discovery, risk-based prioritization, SLA tracking, verification. Compliance & Governance (Technical Ownership) - Own the engineering side of HIPAA and SOC 2 — implement controls, produce evidence, and support audits. - Maintain audit logging, access review, data retention, and encryption controls. Support security questionnaires, customer security reviews, and third-party/vendor assessments. Coordinate external penetration tests and drive remediation of findings. - Keep security policies and technical documentation accurate as systems change. Security Engineering & Automation - Embed security checks into CI/CD (GitHub Actions) so issues surface at pull-request time. Write Python and shell automation for evidence collection, configuration auditing, and remediation. - Build tooling and guardrails that make the secure path the easy path for engineers. Improve identity and access management across cloud, SaaS, and internal tooling. Collaboration & Enablement - Partner with engineering, DevOps, and product teams as an embedded security reviewer. Run practical security training and awareness for engineering. - Communicate risk clearly to both technical and non-technical audiences, with a recommendation attached. AI-Enabled Engineering - Use modern AI tools to accelerate code review, detection engineering, and analysis. - Apply AI-assisted practices while maintaining rigorous verification, data-handling, and review standards. - Assess and secure the organization’s own use of AI services, including data-exposure risk. Required Qualifications - Bachelor’s or Master’s degree in Computer Science, Information Security, or a related discipline. 6+ years in cybersecurity, with substantial application security or cloud security ownership. Strong AWS security experience — IAM, VPC networking, encryption, logging, and common misconfiguration patterns. - Ability to read and reason about production code; Python strongly preferred, plus JavaScript/TypeScript. - Hands-on web application and API security testing (OWASP Top 10, OWASP API Security Top 10) using black-box, grey-box, and white-box approaches. - Ability to write up findings with reproducible steps, impact, severity rationale, and a concrete remediation path. - Practical experience with SAST/DAST/SCA and container scanning tooling, including triage and remediation. - Working knowledge of Docker and container orchestration (ECS/Fargate or EKS). Experience with vulnerability management and incident response in production environments. Familiarity with HIPAA, SOC 2, or equivalent compliance frameworks. - Solid Linux fundamentals, networking, and cryptography basics. - Clear written and verbal English; ability to document findings and risk decisions precisely. Technical Expertise Application Security - Secure Code Review (Python / Django / FastAPI, Node.js, React / TypeScript) Threat Modeling (STRIDE or equivalent) - OWASP Top 10 / OWASP API Security Top 10 - Authentication, Authorization, Multi-Tenant Isolation - Black-Box / Grey-Box / White-Box Penetration Testing - Manual Exploitation and Proof-of-Concept Development - SAST / DAST / SCA, Secret and Dependency Scanning - Burp Suite, OWASP ZAP, Semgrep, Trivy, and similar tooling Cloud & Infrastructure Security - AWS IAM, VPC, Security Groups, KMS, GuardDuty, Security Hub, CloudTrail, Config ECS / Fargate / EKS Workload Security - Terraform Security Review, Policy as Code (OPA, Checkov, tfsec) - Secrets Management (AWS Secrets Manager, SOPS, Vault) - Network Segmentation and Perimeter Controls Security Operations - SIEM / Log Analytics and Detection Engineering - Incident Response and Digital Forensics - Vulnerability Management and Risk-Based Prioritization - Audit Logging, Access Review, Monitoring and Alerting Data Protection & Compliance - Encryption at Rest and in Transit, Key Management - PHI / PII Handling, Data Classification, Retention - HIPAA, SOC 2, HITRUST, NIST CSF, ISO 27001 - Vendor and Third-Party Risk Assessment Platform Context - PostgreSQL Security and Access Control - Kafka / Redpanda / Amazon MSK, Redis - GitHub Actions and CI/CD Security - Python and Shell Automation ## Preferred Qualifications - Security certifications — OSCP, CISSP, AWS Security Specialty, GIAC (GWAPT, GCIH, GCSA), or CEH. - Experience securing multi-tenant SaaS platforms and tenant-isolation models. Prior experience carrying a SOC 2 Type II audit or HIPAA program through to completion. Offensive security background — black-box penetration testing, red teaming, or bug bounty experience. - Experience scoping and managing third-party black-box or grey-box penetration tests. Kubernetes security. - Experience with event-driven architectures and message-broker security. - Detection-as-code and security automation at scale. - Exposure to healthcare technology or other regulated domains. - Experience securing AI/LLM-integrated applications. ## What We Look For - Genuine hands-on depth — you find real issues, not just scanner output. - Engineering mindset: you fix and automate rather than only report. - Sound risk judgment and the ability to prioritize what actually matters. - Strong collaboration; engineers should want your review, not dread it. - Precise written communication and clean documentation. - Integrity, discretion, and ownership when handling sensitive data. - Continuous learning as the threat landscape moves. ## Why This Role - Security ownership of a healthcare platform where the stakes are real. - Breadth across application, cloud, and operational security in one role. - Modern stack: AWS, Terraform, GitHub Actions, Docker, Python, React, PostgreSQL, Kafka compatible messaging. - Direct influence on architecture and engineering practice, not a downstream audit function. ## About Practice By Numbers ## Company Overview - **One-liner**: Practice by Numbers is an all-in-one software platform that streamlines dental practice operations, from analytics and patient communication to payments and scheduling. - **Entity Type**: Private (no disclosed funding rounds – assumed bootstrapped or privately funded) - **Headquarters**: Redmond, Washington, United States - **Founded**: 2015 - **Founders**: Dr. Aditi Agarwal, Rohit Garg, Chris Lau ## Core Business - **Primary industry**: Dental Practice Management Software (HealthTech) - **Target customers**: Dental practices, groups, and organizations (B2B, primarily SMB and mid-market) - **Mission statement**: “Transform dental practice management through integrated software solutions that streamline operations, enhance patient experiences, and optimize business performance.” ## Products & Services - **Practice Relationship Management (PRM) Platform**: A unified suite combining analytics, patient communication, reputation management, online scheduling, online payments, patient forms, insurance verification, and more – all in one system. - **Analytics & Business Intelligence**: Dashboards and reports that give dental teams insights into practice performance, patient trends, and revenue optimization. - **VoIP / SIP Backbone**: Integrated phone system for dental practices. - **AI-Powered Tools**: AI at the core of modern dentistry to simplify operations (e.g., automation, patient engagement). ## Market Standing - **Valuation**: Not publicly available - **Key Metric**: Over 5,000 dental professionals trust the platform (2024); 400% growth since the 2022 relaunch. - **Notable Investors/Partners**: Not disclosed – key partnerships likely include dental industry networks; talent sources include Henry Schein One, Lighthouse 360, etc. - **Growth Signals**: 70 employees (+9% YoY); active job postings for senior roles (VP Sales, SRE, Product Manager); expanding presence in India and US. ## Competitive Advantages - **All-in-one integration**: Combines analytics, CRM, payments, scheduling, and phone into a single platform, reducing the need for multiple vendors. - **Dental-specific focus**: Deep domain expertise from founders (clinical + business + tech) creates a product tailored to dental workflows. - **AI-first approach**: Infusing AI into core operations to automate and optimize practice management. ## Strategic Focus - **AI & Automation**: Putting AI at the center of product development to simplify dental practice operations. - **Platform expansion**: Continuously adding modules (online booking, patient intake, payments) to become the single operating system for dental practices. - **Scaling team**: Hiring across engineering, product, sales, and customer success to support 400% growth trajectory. ## Why Work Here - **Culture**: Described as “work hard, play hard” – high energy, collaborative, with genuine friendships and celebrations. Mission-driven environment focused on improving dental care. - **Work policy**: Hybrid/remote flexibility – Bellevue, WA office; employees work remotely with hybrid options (headquarters in Redmond, also office in Evansville, IN). Remote-friendly. - **Perks**: Competitive salary, flexible schedule, professional development (training, mentorship), health coverage, wellness perks. - **Engineering culture**: Building on a modern tech stack (VoIP/SIP, AI, full-stack payments); opportunities to work on complex system challenges in a growing startup. ## Sources 1. [practicenumbers.com/company/job-listings](https://practicenumbers.com/company/job-listings/) 2. [practicenumbers.com/company/careers](https://practicenumbers.com/company/careers/) 3. [practicenumbers.com/company/about-us](https://practicenumbers.com/company/about-us/) 4. [linkedin.com/company/practice-by-numbers](https://linkedin.com/company/practice-by-numbers) 5. [builtin.com/company/practice-by-numbers](https://builtin.com/company/practice-by-numbers) ## Other roles at Practice By Numbers - [DevOps / Site Reliability Engineer – Engineering](https://feeny.ai/job/devops-site-reliability-engineer-engineering-practice-by-numbers-kolkata-1v947x506fdc) — Kolkata, India - [UX Designer](https://feeny.ai/job/ux-designer-practice-by-numbers-gurugram-haryana-dpe3pzrzcpng) — Gurugram Haryana, India - [Senior Software Engineer, AI](https://feeny.ai/job/senior-software-engineer-ai-practice-by-numbers-gurugram-haryana-hyfj9tbka2za) — Gurugram Haryana, India - [Senior Network Engineer](https://feeny.ai/job/senior-network-engineer-practice-by-numbers-gurugram-haryana-8eq381yn8jc2) — Gurugram Haryana, India - [AI Software Engineer](https://feeny.ai/job/ai-software-engineer-practice-by-numbers-gurugram-haryana-q36f1xvssq0b) — Gurugram Haryana, India - [Technical Leader – Engineering/ Kolkata](https://feeny.ai/job/technical-leader-engineering-kolkata-practice-by-numbers-kolkata-xkqwcaj3fzmd) — Kolkata, India - [Senior Software Engineer](https://feeny.ai/job/senior-software-engineer-practice-by-numbers-kolkata-0kn51n6v19xx) — Kolkata, India - [Software Engineer](https://feeny.ai/job/software-engineer-practice-by-numbers-kolkata-3j37yep2pr1w) — Kolkata, India - [Sales Development Representative (SDR) (Copy)](https://feeny.ai/job/sales-development-representative-sdr-copy-practice-by-numbers-united-states-6zregqpzr6cn) — United States - [Sr. Account Executive](https://feeny.ai/job/sr-account-executive-practice-by-numbers-united-states-9daja750b9z1) — United States