Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Company Overview: One of the global MedTech organization having their Indian HQ at Mumbai.
Job Overview
Looking for an experienced Backend Developer to own, evolve, and support the backend of the digital health platform. This platform is a large, production Symfony application used by Android and iOS mobile apps via REST APIs. The backend is the system of record for patient data, medical questionnaires, risk algorithms, eligibility, insurer configuration, telehealth, documents, notifications, and billing integrations. It handles sensitive health and personal information and must remain secure, reliable, and available.
The individual will work closely with mobile developers, QA, infrastructure/cloud, security, and clinical/operations stakeholders. The role covers both new feature development and live production support.
Job Responsibilities
Product & API development:
Design, develop, maintain, and enhance backend services and REST APIs consumed by Android and iOS applications, as well as the internal web admin.
Work with mobile developers to define API contracts, versioning, payloads, error handling, and request/response behaviour.
Implement and maintain application logic around authentication, authorization, questionnaires, medical data, services, documents, notifications, and third-party integrations.
Build and extend the EasyAdmin / Twig-based administration portal used by clinical and operations staff.
Write and maintain Doctrine entities, repositories, migrations, validators, voters, event listeners, and Symfony console commands.
Implement and maintain asynchronous processing using Symfony Messenger (emails, notifications, algorithm recalculation, file scanning, exports/imports, recordings, and similar background jobs).
Maintain API documentation (OpenAPI / Nelmio) and internal technical documentation covering APIs, integrations, data model, configuration, and deployment.
Data, performance & reliability:
Own database interactions: schema design, query optimisation, migrations, and troubleshooting on MySQL.
Optimise API response times, N+1 queries, caching (Redis), and overall backend performance.
Implement robust logging, exception handling, monitoring, and alerting (including Bugsnag).
Support development, UAT/staging, and production environments.
Security & sensitive data:
Maintain JWT authentication, refresh tokens, role-based access control, and two-factor authentication flows.
Apply secure coding practices for APIs, file uploads, webhooks, and admin surfaces.
Protect sensitive patient, medical, and insurance data in transit and at rest.
Support vulnerability remediation and findings from security reviews or penetration tests.
Work with file-scanning and malware-protection flows (uploaded medical documents are scanned before they are trusted).
Partner APIs (telemedicine, insurer/eligibility, geocoding, analytics).
Releases, DevOps & production support:
Participate in application releases and coordinate backend deployments with mobile app releases.
Work with DevOps/infrastructure on Dockerised deployments, CI/CD, Azure services, monitoring, backups, and disaster recovery.
Investigate production incidents involving APIs, databases, workers, integrations, authentication, and mobile-to-backend communication.
Perform root-cause analysis and implement permanent fixes, not only hotfixes.
Proactively identify recurring issues and improve stability, observability, and operability.
Ways of working:
Work in Agile/Scrum: sprint planning, backlog refinement, daily stand-ups, reviews, and retrospectives.
Manage development, enhancements, bugs, and production support through Jira.
Use Git and standard SDLC practices (branches, reviews, releases).
Communicate clearly with mobile, QA, infrastructure, security, and business/clinical stakeholders.
Job Requirements
4+ years of backend development experience, preferably in PHP/Symfony.
Hands-on experience supporting production applications.
Previous experience on backends that serve mobile applications is strongly preferred.
Experience in Agile/Scrum teams.
Comfortable collaborating with non-engineering stakeholders (clinical, operations, content, customer service).
Strong experience with PHP 8+ and Symfony (experience with Symfony 5/6/7 is ideal; this codebase is Symfony 7.2).
Strong experience designing and building REST APIs (JSON, HTTP/HTTPS, authentication, versioning, error handling).
Strong experience with Doctrine ORM (or equivalent ORM) and MySQL: schema design, relations, migrations, query optimisation, and troubleshooting.
Experience supporting backends consumed by Android and iOS applications, including mobile request/response flows, auth token handling, and push-notification backends.
Solid understanding of authentication and authorization: JWT, refresh tokens, role/permission models, and session-based web auth.
Experience with Docker and local/containerised development.
Experience with Git, code review, and a structured release process.
Experience with application logging, monitoring, and debugging in production.
Good working knowledge of Agile/Scrum and Jira.
Ability to work in a large existing codebase (many domains, entities, APIs, admin screens, and background jobs) rather than only greenfield services.
Experience with Microsoft Azure (app hosting, Azure Database for MySQL, Blob Storage, networking, SSL).
Experience with Symfony Messenger (or equivalent queue/worker systems) for asynchronous jobs.
Experience with Redis for caching.
Admin panel experience (EasyAdmin, Sonata, or similar CRUD/admin frameworks).
Experience with Twilio, Firebase, APNs, Stripe, or similar third-party API integrations.
Multi-language / i18n systems.
Nginx + PHP-FPM operational understanding.
Bugsnag, Mixpanel, Application Insights, Sentry, or similar observability/analytics tools.
Spreadsheet import/export (PhpSpreadsheet) and data migration/console commands.
Secure API development and least-privilege access control.
Authentication and authorization (JWT, refresh tokens, 2FA, role-based access; OAuth 2.0 / SSO familiarity is a plus).
Encryption in transit (TLS) and at rest.
Secure handling of passwords, tokens, files, and secrets.
Webhook signature verification and safe third-party callbacks.
File upload security and malware scanning.
Protection against common web/API vulnerabilities (OWASP API Security / OWASP Top 10), including injection, broken authentication, IDOR/BOLA, mass assignment, XSS, CSRF, open redirects, and rate limiting.
Audit logging of sensitive data changes.
Vulnerability remediation and working through penetration-test findings.
Secure coding practices in PHP/Symfony (input validation, output encoding, parameterized queries, session hardening).
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.