Doctronic Logo

Doctronic

Information Security Engineer

Posted One Month Ago
In-Office or Remote
Hiring Remotely in New York City, NY, USA
180K-240K Annually
Senior level
In-Office or Remote
Hiring Remotely in New York City, NY, USA
180K-240K Annually
Senior level
Own and strengthen Doctronic's security posture for a HIPAA-compliant, SOC 2 Type II environment. Maintain compliance, run audits, perform penetration testing and vulnerability assessments, handle incident response, vendor security reviews, build security automation and monitoring, and partner with engineering to embed security across the SDLC.
The summary above was generated by AI
Information Security Engineer

Where Medicine Meets Intelligence

Doctronic is the first AI legally authorized to practice medicine. We're processing millions of consultations monthly with 99%+ treatment plan accuracy validated by board-certified clinicians.

About the Role

We're looking for an Information Security Engineer to own our security posture. We're HIPAA-compliant and SOC 2 Type II certified—you'll maintain and strengthen that foundation as we scale to serve millions of patients and enterprise partners.

This role is critical to our mission. When you're protecting healthcare data, security isn't just best practice—it's a sacred responsibility. You'll combine hands-on technical work with strategic security leadership, ensuring Doctronic remains the most trusted AI diagnostic platform in healthcare.

What You'll Do
  • Maintain SOC 2 Type II compliance and manage ongoing audits with external assessors

  • Implement and monitor HIPAA technical safeguards across our infrastructure and applications

  • Conduct and coordinate regular penetration testing, vulnerability assessments, and security reviews

  • Complete vendor security reviews and respond to enterprise security questionnaires from health systems and payers

  • Implement and enforce security policies across engineering, operations, and business teams

  • Respond to security incidents with urgency and thoroughness, conducting post-incident analysis

  • Build security automation and monitoring to scale protection as the company grows

  • Collaborate with engineering teams to embed security best practices into the development lifecycle

  • Stay current on emerging threats, vulnerabilities, and regulatory requirements in healthcare technology

Who You Are
  • 7+ years of information security experience in production environments

  • Healthcare or fintech background required—you understand regulated industry security requirements

  • Hands-on technical ability, not just policy and paperwork—you can read code, configure systems, and investigate incidents

  • Deep experience with SOC 2, HIPAA, or equivalent compliance frameworks

  • Familiarity with AWS security controls, IAM, encryption, and cloud security best practices

  • Strong communicator who can translate security requirements for technical and non-technical audiences

  • Proactive problem-solver who anticipates risks before they materialize

  • Collaborative partner who enables teams to move fast while staying secure

Nice to Have
  • CISSP, CISM, CISA, or equivalent security certification

  • Experience with health information exchanges, TEFCA, QHIN, or interoperability standards

  • Startup security experience—building security programs from scratch vs. maintaining established ones

  • Familiarity with AI/ML security considerations and model protection

  • Experience with mobile app security (iOS/Android)

  • Knowledge of medical device security standards or FDA digital health guidance

  • Background in application security, secure SDLC, or DevSecOps

Compensation & Benefits

Base Salary: $180K-$240K + Equity

New York City | On-site
Join our NYC team and work directly with engineering and product teams to build security into everything we do.

Equity Opportunities
Share in Doctronic's growth as we transform healthcare with AI.

Parental Leave
12 weeks fully paid parental leave for all parents, regardless of gender or path to parenthood — no distinction between birthing and non-birthing parent

Building AI That Matters
Join Doctronic and work with cutting-edge AI that's transforming healthcare and helping people make faster, smarter decisions.

Reports To

Director of Engineering

HQ

Doctronic New York, New York, USA Office

110 E 25th St, New York, NY, United States, 10010

Similar Jobs

23 Days Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
134K-168K Annually
Senior level
134K-168K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Protect corporate data through DLP implementation, tuning, alert review, false-positive reduction, and control optimization across web, endpoint, email, cloud, and SaaS environments. The engineer will review data protection programs, improve monitoring and blocking controls, collaborate with business partners, and use automation and emerging AI tools to strengthen security operations.
Top Skills: Ai ToolsCloud Data StoresData Loss Prevention (Dlp)SaaSZscaler DspmZscaler Zero Trust ExchangeZscaler Zia
Yesterday
Remote
USA
Senior level
Senior level
Information Technology • Professional Services
Designs and integrates secure information systems, cloud, and defense architectures; leads federal NIST RMF and ATO processes; implements security controls; performs vulnerability, threat, and risk assessments; advises engineering and program teams; and manages continuous monitoring, compliance, audit, and patch-management activities.
Top Skills: AcasAws GovcloudBashCnss 1253Cross Domain SolutionsCryptographyDlpFips 199Fips 200FirewallsHbssIcd 503Ids/IpsLinuxAzureNist Risk Management FrameworkNist Sp 800-37Nist Sp 800-53PowershellPythonRoutingSIEMTcp/IpWindows
Yesterday
Remote
United States
114K-154K Annually
Senior level
114K-154K Annually
Senior level
Aerospace • Information Technology • Professional Services • Security • Software
The Information Systems Security Engineer will secure a USPS information system modernization project by implementing federal security controls, conducting vulnerability assessments and penetration testing, integrating security into CI/CD pipelines, maintaining SSP, RMP, and POA&M documentation, monitoring cloud security tools, supporting incident response, and delivering security training. The role requires collaboration with development, operations, and federal security stakeholders while ensuring compliance with FISMA, NIST RMF, and FedRAMP standards.
Top Skills: Access ControlsAWSAws Security HubCi/CdCloudwatchDevsecopsEncryptionFedrampFismaGithub CopilotGuarddutyNessusNist RmfPenetration TestingSonarqubeSplunk

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account