Staff Product Security Engineer at Doxy.me

Company: Jack & Jill
Apply for the Staff Product Security Engineer at Doxy.me
Location: London
Job Description:

Job Title


Staff Product Security Engineer



Salary


Not Disclosed



Company Description


Doxy.me is a global leader in telemedicine, providing a secure and free platform used by over 1 million healthcare providers across 180 countries. Since 2013, they have facilitated 8 billion minutes of patient care, on a mission to make healthcare accessible and barrier-free for everyone on earth through simple, remote-first technology.



Job Description


As an early member of the Application Security team, you will establish the technical foundation for Doxy.me’s security and privacy. You’ll lead threat modeling, architect secure-by-default CI/CD pipelines, and develop engineering reference implementations. This is a pivotal role ensuring a massive global healthcare platform remains safe, compliant, and resilient as it scales.



Location


London, UK



Why this role is remarkable



  • Influence the security posture of a platform supporting over 1 million healthcare providers and 8 billion minutes of clinical sessions worldwide.

  • Join as a pioneering member of the Information Security team, shaping the technical standards for a high-growth, remote-first healthtech leader.

  • Work with a modern, cloud-native stack including AWS, Kubernetes, and Terraform while solving complex privacy and compliance challenges in the global healthcare space.



What You Will Do



  • Provide security leadership through developer-led threat modeling and education on privacy best practices to prevent vulnerabilities at the source.

  • Design and implement secure-by-default CI/CD pipelines, advocating for robust DevSecOps strategies across the entire product life cycle.

  • Develop engineering reference implementations for security patterns and guardrails, supporting proof-of-concept designs for software frameworks and infrastructure.



The ideal candidate



  • Proven experience securing complex cloud environments, specifically using AWS, Kubernetes, and Infrastructure as Code tools like Terraform and Helm.

  • Deep expertise in OWASP Top 10, web security testing methodologies (SAST/DAST), and implementing secure coding practices for HIPAA or SOC2 compliance.

  • Strong background in DevOps processes with the ability to collaborate with globally distributed engineering teams and educate staff on security measures.



We never post fake jobs


This isn’t a trick. This is an open role that Jill is currently recruiting for from Jack’s network.



Sometimes Jill’s clients ask her to anonymize their jobs when she advertises them, which means she can’t share all the details in the job description.



We appreciate this can make them look a bit suspect, but there isn’t much we can do about it.



Give Jack a spin! You could land this role. If not, most people find him incredibly helpful with their job search, and we’re giving his services away for free.

#J-18808-Ljbffr…

Posted: October 2nd, 2026