> Markdown version of [/jobs/ext/2704192-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/2704192-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - **Company:** Doctronic Inc. - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $180,000.0 - $240,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing Security, Cyber Security, EHealth, Identity and Access Management, Interoperability, Mobile Application Software, Software Security, Devsecops, Vulnerability Analysis - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/information-security-engineer-doctronic-8121896 ## About the Role * 7+ years of information security experience in production environments * Healthcare or fintech background required-you understand regulated industry security requirements * Hands-on technical ability, not just policy and paperwork-you can read code, configure systems, and investigate incidents * Deep experience with SOC 2, HIPAA, or equivalent compliance frameworks * Familiarity with AWS security controls, IAM, encryption, and cloud security best practices * Strong communicator who can translate security requirements for technical and non-technical audiences * Proactive problem-solver who anticipates risks before they materialize * Collaborative partner who enables teams to move fast while staying secure Nice to Have * CISSP, CISM, CISA, or equivalent security certification * Experience with health information exchanges, TEFCA, QHIN, or interoperability standards * Startup security experience-building security programs from scratch vs. maintaining established ones * Familiarity with AI/ML security considerations and model protection * Experience with mobile app security (iOS/Android) * Knowledge of medical device security standards or FDA digital health guidance * Background in application security, secure SDLC, or DevSecOps ## Description We're looking for an Information Security Engineer to own our security posture. We're HIPAA-compliant and SOC 2 Type II certified-you'll maintain and strengthen that foundation as we scale to serve millions of patients and enterprise partners. This role is critical to our mission. When you're protecting healthcare data, security isn't just best practice-it's a sacred responsibility. You'll combine hands-on technical work with strategic security leadership, ensuring Doctronic remains the most trusted AI diagnostic platform in healthcare. What You'll Do * Maintain SOC 2 Type II compliance and manage ongoing audits with external assessors * Implement and monitor HIPAA technical safeguards across our infrastructure and applications * Conduct and coordinate regular penetration testing, vulnerability assessments, and security reviews * Complete vendor security reviews and respond to enterprise security questionnaires from health systems and payers * Implement and enforce security policies across engineering, operations, and business teams * Respond to security incidents with urgency and thoroughness, conducting post-incident analysis * Build security automation and monitoring to scale protection as the company grows * Collaborate with engineering teams to embed security best practices into the development lifecycle * Stay current on emerging threats, vulnerabilities, and regulatory requirements in healthcare technology ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)