Startups · AI

Information Security Engineer

Doctronic · New York City · Remote

← All jobs
About Doctronic

Doctronic is the world's most popular AI doctor. 100% Private. Get free, personalized, and immediate access to comprehensible health information with real-time issue exploration, symptom checkers, and action plans. We promote educated interactions between... Backed by Lightspeed and USV.

About the role

We're looking for an Information Security Engineer to own our security posture. We're HIPAA-compliant and SOC 2 Type II certified—you'll maintain and strengthen that foundation as we scale to serve millions of patients and enterprise partners.

What they're looking for

  • 7+ years of information security experience in production environments
  • Healthcare or fintech background required—you understand regulated industry security requirements
  • Hands-on technical ability, not just policy and paperwork—you can read code, configure systems, and investigate incidents
  • Deep experience with SOC 2, HIPAA, or equivalent compliance frameworks
  • Familiarity with AWS security controls, IAM, encryption, and cloud security best practices
  • Strong communicator who can translate security requirements for technical and non-technical audiences
More about this role

Doctronic is the first AI legally authorized to practice medicine. We're processing millions of consultations monthly with 99%+ treatment plan accuracy validated by board-certified clinicians.

We're looking for an Information Security Engineer to own our security posture. We're HIPAA-compliant and SOC 2 Type II certified—you'll maintain and strengthen that foundation as we scale to serve millions of patients and enterprise partners.

This role is critical to our mission. When you're protecting healthcare data, security isn't just best practice—it's a sacred responsibility. You'll combine hands-on technical work with strategic security leadership, ensuring Doctronic remains the most trusted AI diagnostic platform in healthcare.

Maintain SOC 2 Type II compliance and manage ongoing audits with external assessors

Implement and monitor HIPAA technical safeguards across our infrastructure and applications

Conduct and coordinate regular penetration testing, vulnerability assessments, and security reviews

Complete vendor security reviews and respond to enterprise security questionnaires from health systems and payers

Implement and enforce security policies across engineering, operations,...

Read the full posting on Doctronic's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.