Doctronic
via Ashby
Information Security Engineer
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 20h ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 221d ago
The date the source published, not the day we noticed it (2026-02-06). Last seen at its source just now.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
New York City
The description states no restriction of its own. This is the source's own tag.
Pay
$180k–240k/yr
Read out of the job description by us, not from a structured field. Shown in the posting's own currency and period; we never convert.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
ashby employer's own board first seen 11d ago · last seen just now
The listing
Where Medicine Meets Intelligence
Doctronic is the first AI legally authorized to practice medicine. We're processing millions of consultations monthly with 99%+ treatment plan accuracy validated by board-certified clinicians.
About the Role
We're looking for an Information Security Engineer to own our security posture. We're HIPAA-compliant and SOC 2 Type II certified—you'll maintain and strengthen that foundation as we scale to serve millions of patients and enterprise partners.
This role is critical to our mission. When you're protecting healthcare data, security isn't just best practice—it's a sacred responsibility. You'll combine hands-on technical work with strategic security leadership, ensuring Doctronic remains the most trusted AI diagnostic platform in healthcare.
What You'll Do
Maintain SOC 2 Type II compliance and manage ongoing audits with external assessors
Implement and monitor HIPAA technical safeguards across our infrastructure and applications
Conduct and coordinate regular penetration testing, vulnerability assessments, and security reviews
Complete vendor security reviews and respond to enterprise security questionnaires from health systems and payers
Implement and enforce security policies across engineering, operations, and business teams
Respond to security incidents with urgency and thoroughness, conducting post-incident analysis
Build security automation and monitoring to scale protection as the company grows
Collaborate with engineering teams to embed security best practices into the development lifecycle
Stay current on emerging threats, vulnerabilities, and regulatory requirements in healthcare technology
Who You Are
7+ years of information security experience in production environments
Healthcare or fintech background required—you understand regulated industry security requirements
Hands-on technical ability, not just policy and paperwork—you can read code, configure systems, and investigate incidents
Deep experience with SOC 2, HIPAA, or equivalent compliance frameworks
Familiarity with AWS security controls, IAM, encryption, and cloud security best practices
Strong communicator who can translate security requirements for technical and non-technical audiences
Proactive problem-solver who anticipates risks before they materialize
Collaborative partner who enables teams to move fast while staying secure
Nice to Have
CISSP, CISM, CISA, or equivalent security certification
Experience with health information exchanges, TEFCA, QHIN, or interoperability standards
Startup security experience—building security programs from scratch vs. maintaining established ones
Familiarity with AI/ML security considerations and model protection
Experience with mobile app security (iOS/Android)
Knowledge of medical device security standards or FDA digital health guidance
Background in application security, secure SDLC, or DevSecOps
Compensation & Benefits
Base Salary: $180K-$240K + Equity
New York City | On-site
Join our NYC team and work directly with engineering and product teams to build security into everything we do.
Equity Opportunities
Share in Doctronic's growth as we transform healthcare with AI.
Parental Leave
12 weeks fully paid parental leave for all parents, regardless of gender or path to parenthood — no distinction between birthing and non-birthing parent
Building AI That Matters
Join Doctronic and work with cutting-edge AI that's transforming healthcare and helping people make faster, smarter decisions.
Reports To
Director of Engineering