Doctify is the global platform built by doctors for doctors, on a mission to build the largest, most trusted global network of validated healthcare providers and experts. We connect patients with the right doctors, and doctors with respected peers, to ensure better care worldwide. Through verified patient reviews and professional skill endorsements, Doctify creates unmatched credibility for providers and empowers patients to choose care with confidence.
Founded in 2015 and backed by $30m+ in funding, Doctify operates across 7 countries. We are uniting the global healthcare community, one trusted connection at a time.
We do things differently here at Doctify, we are boldly leading a digital revolution in healthcare and are confident in our mission.
This is a builder's role.
You will be the only dedicated security person at Doctify, and you will be in the AWS environment, the device fleet, and the tooling: configuring, hardening, and shaping our security posture day to day. This is the right opportunity for someone with genuine hands-on experience who is ready to step into a more senior, ownership-level role while remaining close to the technical work itself, rather than moving away from it.
This role will suit someone who thrives on personal ownership of the technical work at this stage, with the ambition to grow the function over time. Building a team is a genuine possibility as we grow, and it is very much part of the trajectory.
What we are offering in return is rare: full ownership of security at a company that matters, the autonomy to set direction and then deliver it your way, and a credible path to a CISO seat as Doctify scales, and the function is built.
You will report to the VP Engineering and work closely with the COO, Trust, and Legal.
Doctify has grown organically for over a decade, and security has become a key priority for the organisation as we work towards the next level of maturity in how we protect our platform, our people, and the patients and clinicians who rely on us.
You would be the person who defines what good looks like here and builds it yourself, with real autonomy and direct partnership with engineering leadership.
This is a rare opportunity for someone with strong hands-on experience who is ready for a more senior role, one where seniority means greater ownership and influence rather than distance from the work, to build something with their own hands and see it through.
You own the whole security programme, and personally execute it.
Cloud and platform security: Assess, re-architect, and continuously harden our AWS and Google Workspace environments yourself. This starts with a real piece of work: reviewing how our AWS Organizations and accounts are structured today, moving what should not be in the root account, and applying least privilege, sound IAM, and org-level guardrails against CIS benchmarks and NIST. This is the core of the role and where you'll begin.
Endpoint security and device management: Roll out and run enterprise-grade endpoint protection across a distributed device fleet, including EDR, MDM, patch management, and device-trust controls, for staff and contractors across multiple countries and personal and company hardware.
Security operations and visibility: Stand up our security operations capability: centralise event logging, integrate SIEM, set up alerting and an active review process, and decide pragmatically where an internal function ends and a managed SOC partner begins, then hold that partner to account.
Identity and access management: Strengthen IAM across the business and our patient and clinician-facing products: SSO centralisation, access controls, and privileged access management.
Application and data security architecture: Partner with the VP Engineering and the engineering team to embed security into the SDLC, from threat modelling and code-review standards to secure data-handling practices, and get developers owning their security responsibilities.
Incident response and business continuity: Own our incident response capability end to end: clear playbooks, tested procedures, and the ability to detect, contain, and recover, with appropriate communication protocols and the 72-hour GDPR breach clock understood and planned for.
Governance, risk, and compliance: Mature our governance framework, maintain Cyber Essentials, formalise risk methodology, own the risk register, and drive us towards ISO 27001 or equivalent, in proportion to the risk.
Patient and clinician data protection: Own our obligations around healthcare data, working with Trust and Legal on GDPR and multi-jurisdiction data handling, including our UAE and Saudi footprint and the data-residency questions that come with it.
Vendor and third-party security: Define and apply security requirements across supplier relationships, manage third-party risk, and oversee any outsourced security functions.
Security awareness and culture: Build genuine security awareness across the business through training, phishing simulations, and plain-language communication, so security is shared ownership rather than your problem alone.
Strategy, roadmap, and reporting: Translate Doctify's risk profile into a clear, prioritised roadmap, deliver it yourself, and report progress in plain language to the executive team and Board. You set the direction and then you do the work.
Essential and non-negotiable: recent, hands-on AWS. You must have demonstrable, recent experience personally configuring and hardening a production AWS environment, ideally multi-account or AWS Organisations.
We will ask you to walk us through the last thing you built or hardened in AWS yourself, and when. If AWS has been something you advised on, oversaw, or hold a certification in rather than worked in directly and recently, this role is not for you.
This is a team-of-one role, so we are not expecting the deepest specialist in every area. We need you genuinely hands-on in the core below, competent and able to execute across the middle, and able to apply the frameworks in practice. The tiers tell you honestly where the bar sits.
Core: deep and hands-on (you'll use these most weeks)
AWS security engineering: IAM (roles, policies, permission boundaries), Organizations and Service Control Policies, multi-account architecture, KMS and secrets management, VPC and network security groups, CloudTrail and org-wide logging, GuardDuty and Security Hub, S3 controls including public-access blocks, and infrastructure as code (Terraform or CloudFormation).
Endpoint and device security: EDR or XDR, MDM across macOS and Windows, patch management, and device-trust controls for a distributed fleet spanning personal and company hardware. Our endpoint rollout is live and immediate.
Google Workspace security: Admin console hardening, context-aware access, OAuth app governance, super-admin minimisation, and audit-log export. This is our corporate control plane, not just email, and we need it treated that way.
Strong and able to execute (deep where needed, competent throughout)
Security operations and visibility: SIEM integration, centralised logging, alerting, and the judgement to run an internal function or hold a managed SOC to account.
Identity beyond AWS: SSO and federation (SAML, OIDC), privileged access management, and joiner-mover-leaver governance.
Secure SDLC and application security: OWASP Top 10, threat modelling, code-review standards, and embedding SAST, DAST, SCA, and secrets scanning into CI/CD. This matters more as we move towards AI-native development.
Incident response: Playbooks, detect-contain-recover, and planning around the 72-hour GDPR breach clock.
Vulnerability management: Prioritising by real exploitability rather than raw CVSS score.
Frameworks, applied rather than theoretical
Cyber Essentials, ISO 27001, CIS benchmarks, NIST CSF, UK GDPR, and DPIAs, used to harden real systems and drive risk decisions, not as knowledge on a slide.
You’ll also bring
A strong track record in senior security roles, ideally at a SaaS, healthtech, or data-intensive scale-up, and the appetite to own security end to end as a team of one.
Exceptional communication: you can translate nuanced security risk into clear language and a clear decision for a non-technical executive team and Board.
Pragmatism at pace: you make sound, proportionate calls with incomplete information in a scale-up where priorities shift and resources are tight, and you know what to deprioritise.
You are based in the UK and able to work in London, hybrid.
Advantageous
Experience in a regulated environment handling sensitive healthcare or personal health data.
Experience across multiple data-protection jurisdictions, including the Middle East.
DevSecOps fluency and hands-on AI security: LLM governance, prompt-injection awareness, and securing agentic workflows. Relevant to our roadmap, but it does not substitute for the core above.
The ambition and ability to build and lead a small security function later, as the business scales, while staying personally close to the work. This is a future prospect, not a day-one requirement, and it does not replace the need to be hands-on now.
At Doctify, we shape careers with purpose. Our benefits are designed to fuel your growth, flexibility, and wellbeing.
28 days annual leave (25 + 3 between Christmas and New Year), earning up to 30 days leave with tenure
2 weeks of remote working annually (within 3-hour time zone of HQ)
Hybrid working model
Enhanced Parental Leave
Medicash health cash plan
Competitive, benchmarked compensation
3-month immersive onboarding experience
Ongoing learning through expert-led sessions, leadership insights, and soft-skill development
Clear internal mobility pathways to accelerate your career
Daily team huddles to connect, share wins and spark ideas
Regional Lunch Clubs & team socials powered by our Fun Police
Quarterly Doctifier nominated Impact Awards
Employee referral bonus: £700 (or local equivalent) per hire
Diversity, equity, inclusion and belonging aren’t just values. They’re at the core of what makes us Uniquely Doctify. These principles shape how we work, how we work, how we build our teams, how we design our policies, and how we bring our mission to life.
As a global team, we know that diverse perspectives drive innovation and lead to better outcomes for patients, providers and each other. We’re committed to creating a fair, inclusive environment where everyone is heard, respected and empowered to thrive.
We want to ensure that everyone has an equitable and comfortable experience throughout our hiring process. If you require any adjustments, we’re happy to discuss how we can support you. You can contact us at [email protected].