As an early member of the Application Security team, you will establish the technical foundation for Doxy.me’s security and privacy. You’ll lead threat modeling, architect secure-by-default CI/CD pipelines, and develop engineering reference implementations. This is a pivotal role ensuring a massive global healthcare platform remains safe, compliant, and resilient as it scales.
Staff Product Security Engineer at Doxy.me
Join Doxy.me, the world's leading telemedicine platform, as a Staff Product Security Engineer to build the technical foundation for security and privacy across a global network serving over 1 million healthcare providers. You will lead threat modeling, architect secure-by-default CI/CD pipelines, and drive DevSecOps strategy for a mission-driven company that has facilitated over 8 billion minutes of telemedicine sessions to date. This is a rare opportunity to own product security for a massive-scale healthcare innovator while enjoying a remote-first environment, private healthcare, and a culture dedicated to making healthcare barrier-free for everyone.
Want to apply for this role?
Jack finds you jobs at companies like Doxy. Talk to Jack to get considered for roles that fit what you're great at.
Location
London, United Kingdom
Compensation
Not Disclosed
Company
Doxy
Role overview
Doxy.me is a global leader in telemedicine, providing a secure and free platform used by over 1 million healthcare providers across 180 countries. Since 2013, they have facilitated 8 billion minutes of patient care, on a mission to make healthcare accessible and barrier-free for everyone on earth through simple, remote-first technology.
What you will do
- Provide security leadership through developer-led threat modeling and education on privacy best practices to prevent vulnerabilities at the source.
- Design and implement secure-by-default CI/CD pipelines, advocating for robust DevSecOps strategies across the entire product life cycle.
- Develop engineering reference implementations for security patterns and guardrails, supporting proof-of-concept designs for software frameworks and infrastructure.
Who this is a fit for
- Proven experience securing complex cloud environments, specifically using AWS, Kubernetes, and Infrastructure as Code tools like Terraform and Helm.
- Deep expertise in OWASP Top 10, web security testing methodologies (SAST/DAST), and implementing secure coding practices for HIPAA or SOC2 compliance.
- Strong background in DevOps processes with the ability to collaborate with globally distributed engineering teams and educate staff on security measures.
Why this role is remarkable
- Influence the security posture of a platform supporting over 1 million healthcare providers and 8 billion minutes of clinical sessions worldwide.
- Join as a pioneering member of the Information Security team, shaping the technical standards for a high-growth, remote-first healthtech leader.
- Work with a modern, cloud-native stack including AWS, Kubernetes, and Terraform while solving complex privacy and compliance challenges in the global healthcare space.
How Jack & Jill work together
Jack gets to know what you're great at and what you want next, then searches 15 million jobs daily and helps you discover roles at companies like this.
Meet Jack
What happens next?
Jack’s an AI agent for job searching and career coaching. He works for you.
Jill is the AI recruiter working for the company. She recruits from Jack’s network.
If your profile’s a match and Doxy wants to meet, Jill will make the intro. In the meantime, Jack will send you excellent alternatives.