Head of InfoSec at AIOS — Remote, $150-250k/yr inc equity
About AIOS
AIOS is building the world’s first full-stack AI doctor. We’re at $350M ARR, growing from $10M/yr 12 months ago, making us the world’s fastest growing AI doctor. We faithfully serve over 150k patients monthly via Bolt Pharmacy, our main UK brand. We’re profitable and operate at the intersection of two strong theses: the AI doctor that wins will achieve escape velocity using GLP-1s, the fastest growing consumer product in history, and the $2T European healthcare market is overlooked by the most talented builders.
Our master plan:
- Step 0 → $100M/yr by end of 2025: We went from $10M to $100M in 6 months serving the UK GLP-1 market.
- Step 1 → $1B ARR by end of 2026: Over the last 12 months, we’ve grown from 3k to 150k UK active GLP-1 patients. We’ll continue this growth curve to hit $1B ARR.
- Step 2 → $10B ARR by end of 2028: Blitzscale Europe. We’ll be Europe’s largest GLP-1 provider.
- Step 3 → $100B/yr by end of 2031: Get regulatory approval across Europe for our Full Autonomous Prescribing (FAP) system. Win contracts at scale with European payers to mass replace human labor. We’ll be the dominant full-stack AI doctor in Europe.
- Step 4 → $1T/yr by end of 2035: With one line of code and zero human time, use AIOS to treat any patient globally with any medication. We’ll become the world’s first trillion-dollar healthcare company.
We’re a young, founder-led company. This is still Day 1, and all our work is ahead of us.
About the role
As Head of Information Security & Systems at AIOS, you’ll build the secure foundation that allows us to scale globally without compromising patient trust, operational resilience, or speed. You’ll own cybersecurity and internal systems across the AIOS group, spanning our healthcare businesses, technology platforms, pharmacy infrastructure, and more. This includes security strategy, identity and access management, endpoint security, incident response, architecture, tooling, and overall security compliance. You’ll turn strategy into a consistent, scalable operating model across our entities and geographies, setting clear standards, strengthening controls, and ensuring risks are identified, prioritized, and resolved as the business grows.
This is both a strategic and hands-on role. You’ll advise leadership on material risks while also diving in to investigate issues, improve controls, review architecture, implement tooling, and drive remediation across the business. You’ll report directly to Joey Gracek, Head of Business Operations, and work closely with Gzim Helshani (VP Engineering) and Jordan Pellikan (Chief of Staff).
This is a full-time, fully remote role. You’ll work async in the timezone of your choice, with availability until midday Pacific Time for calls as needed.
Responsibilities
- Security ownership: Own the cybersecurity strategy, roadmap, and operating model across all AIOS entities and geographies.
- Security operations and incident response: Establish systems and processes to detect, investigate, contain, and recover from security incidents. Lead response efforts and ensure lessons translate into stronger controls.
- Identity, access, and endpoint security: Ensure the right people have the right access to the right systems. Build scalable processes for authentication, permissions, employee onboarding/offboarding, device management, and access.
- Application and infrastructure security: Partner with engineering to strengthen the security of applications, APIs, cloud infrastructure, development processes, and sensitive data. Review architecture, identify vulnerabilities, and drive remediation without slowing product development.
- Risk and compliance: Translate healthcare, privacy, and security requirements into practical controls. Lead security risk assessments, audits, diligence requests, policy development, and readiness for frameworks such as HIPAA, GDPR, SOC 2, and ISO 27001.
- Business continuity and resilience: Ensure AIOS can continue operating through system failures, security incidents, and disruptions. Strengthen backups, recovery procedures, incident plans, and resilience of business-critical systems.
- Third-party security: Assess and manage risks from vendors, partners, contractors, acquisitions, and new market launches. Ensure third parties meet security standards and identified risks are actively resolved.
- Security leadership and culture: Make security a clear and practical responsibility across AIOS. Advise leadership on material risks, establish ownership across teams, train employees, and build the internal team and external partner network required as the company scales.
Requirements
- Experience: 5+ years leading cybersecurity, information security, or security engineering in a complex, fast-growing organization, with ownership of outcomes.
- Technical depth: Operate credibly across identity and access management, endpoint security, cloud infrastructure, application security, incident response, vulnerability management, and corporate systems.
- Builder: Have built or significantly improved a security program, including its roadmap, controls, policies, tooling, processes, and operating model.
- Autonomy: Comfortable entering an evolving environment, identifying what needs to be done, and driving it to completion with limited structure.
- Judgement: Identify risks that genuinely matter, explain them clearly, and implement proportionate controls without creating unnecessary friction or slowing the business.
- Incident leadership: Have managed security incidents or high-severity technical issues and can lead calmly through investigation, containment, communication, recovery, and remediation.
- Influence: Work effectively with engineering, operations, legal, compliance, people, clinical, and executive teams, even without direct management authority.
- Data Protection: Experience handling highly sensitive customer, patient, financial, employee, or similarly regulated data.
Nice to have
- Healthcare experience in digital health, telemedicine, pharmacy, clinical operations, health insurance, or similar environments.
- International experience owning security across multiple countries, legal entities, or business units, particularly in the US, UK, and Europe.
- Compliance experience with HIPAA, GDPR, UK GDPR, SOC 2, ISO 27001, or similar frameworks.
- IT ownership, including identity platforms, device management, endpoint protection, productivity systems, employee lifecycle processes, and internal support operations.
- Scaling experience hiring, developing, or managing security and systems professionals, with knowledge of what capabilities to keep internal versus outsourced.
Cultural standards
- Belief in the mission: We will serve 100 million patients by the end of 2035 and transform the lives of most patients who join. We are obsessed with our patients and dedicated to the mission.
- Unwavering integrity: We operate at the frontier with no trodden path, so we maintain impeccable ethics and unwavering integrity.
- Only the paranoid survive: Bad outcomes are inevitable. By joining us, you’re choosing to sail straight towards storms with unhesitating conviction. It’s still Day 1, and all our work is ahead of us.
- If we’re average we fail: We demand “insanely great” execution, a dedication to excellence, and reject incompetence.
- Commitment to candor: We value full transparency. We never say anything about someone that we wouldn’t say to them directly. Feedback is given with love, and we don’t protect people from fleeting discomfort.
- A maniacal sense of urgency: We execute at an intensity most people think is impossible. Speed is critical, and we need things done yesterday.
- Enduring frugality: We are frugal, hate waste, and are anti-luxury. A culture of cheapness keeps us young. We spend cash wisely and carefully.
- Bulldozing barriers: The world is malleable, and we shape it. We are relentlessly resourceful and at the mercy of no one but ourselves.
- Keep your head down: We’re boring people doing exciting work. We ignore short-term status and focus on what matters. Outsiders will underestimate us, and we revel in that.
- The power of focus: We live in a world of power laws. Know your One Thing, and nail it.
“You just build a f*ing amazing experience. Make each step amazing. Make every decision in the long-term interest of the customer. Give the customer massively more value than you take.”
Pay
$150–250k, including equity.
Benefits
- Healthcare: Comprehensive medical insurance (if appropriate).
- Vacation: PTO with a yearly minimum (≥2 weeks/yr + local national holidays).
- Remote: Fully distributed team across the world.
- Personal development: Budget for books, courses, coaching ($1200/yr).
- Personal wellness: Budget for gym, health apps ($1200/yr).
- Coaching: Free biweekly health coaching.
- Equipment: MacBook and work-from-home equipment provided as needed.