Head of InfoSec at AIOS — Remote, $150-250k/yr inc equity
WFA Digital Insight
AIOS is at a pivotal moment, moving from a fast‑growing AI‑driven pharmacy into a broader European health platform. The Head of InfoSec isn’t just a compliance gatekeeper; the role is the architect of a security posture that must keep pace with rapid product expansion and massive patient data flows. Reporting to the head of business operations and working side‑by‑side with engineering and the chief of staff, the leader will translate high‑level risk appetite into day‑to‑day controls, incident‑response playbooks, and a unified identity framework across multiple subsidiaries. Candidates who can balance strategic road‑mapping with hands‑on investigation will enable AIOS to scale without sacrificing the trust essential to a medical‑grade AI service.
Job Description
ABOUT AIOS AIOS is building the world’s first full-stack AI doctor. We’re at $350M ARR, growing from $10M/yr 12 months ago. We’re the world’s fastest growing AI doctor. We’re faithfully serving >150k/mo patients via Bolt Pharmacy, our main UK brand. We’re profitable. Our strategy exists at the intersection of two strong theses: 1. The AI doctor that wins will get to escape velocity using GLP-1s, the fastest growing consumer product in history. 2. The $2T European healthcare market is overlooked by the most talented builders. Our master plan: - Step 0 → $100M/yr by end of 2025: We went from $10M to $100M in 6 months serving the UK GLP-1 market.
- Step 1 → $1B ARR by end of 2026: Over the last 12 months we've grown from 3k to 150k UK active GLP-1 patients.
- Step 2 → $10B ARR by end of 2028: Blitzscale Europe. We’ll be Europe’s largest GLP-1 provider.
- Step 3 → $100B/yr by end of 2031: Get regulatory approval across Europe for our Full Autonomous Prescribing (FAP) system. Win contracts at scale with European payers to mass replace human labor.
- Step 4 → $1T/yr by end of 2035: With one line of code and zero human time, you can use AIOS to treat any patient globally with any medication. In so doing, we’ll become the world’s first trillion-dollar healthcare company. We’re a young, founder-led company. This is still Day 1 and all our work is ahead of us.
- Security operations and incident response: You establish the systems and processes needed to detect, investigate, contain, and recover from security incidents.
- Identity, access, and endpoint security: You ensure the right people have the right access to the right systems. You build scalable processes for authentication, permissions, employee onboarding and offboarding, device management, and overall access.
- Application and infrastructure security: You partner closely with engineering to strengthen the security of our applications, APIs, cloud infrastructure, development processes, and sensitive data.
- Risk and compliance: You translate healthcare, privacy, and security requirements into practical controls across the business. You lead security risk assessments, audits, diligence requests, policy development, and readiness for frameworks such as HIPAA, GDPR, SOC 2, and ISO 27001.
- Business continuity and resilience: You ensure Aios can continue operating through system failures, security incidents, and other disruptions.
- Third-party security: You assess and manage the risks created by vendors, partners, contractors, acquisitions, and new market launches. You ensure third parties meet appropriate security standards and that identified risks are actively resolved.
- Security leadership and culture: You make security a clear and practical responsibility across Aios.
- Technical depth: You can operate credibly across identity and access management, endpoint security, cloud infrastructure, application security, incident response, vulnerability management, and corporate systems.
- Builder: You have built or significantly improved a security program, including its roadmap, controls, policies, tooling, processes, and operating model.
- Autonomy: You are comfortable entering an environment that is still evolving, identifying what needs to be done, and driving it through to completion with limited structure.
- Judgement: You can identify the risks that genuinely matter, explain them clearly, and implement proportionate controls without creating unnecessary friction or slowing the business down.
- Incident leadership: You have managed security incidents or high-severity technical issues and can lead calmly through investigation, containment, communication, recovery, and remediation.
- Influence: You can work effectively with engineering, operations, legal, compliance, people, clinical, and executive teams, even when you do not directly manage the people responsible for implementation.
- Data Protection: You have worked in an environment handling highly sensitive customer, patient, financial, employee, or similarly regulated data.
- International Experience: You have owned security across multiple countries, legal entities, or business units, particularly across the US, UK, and Europe.
- Compliance: You have supported or led programs involving HIPAA, GDPR, UK GDPR, SOC 2, ISO 27001, or similar security and privacy frameworks.
- IT Ownership: You have managed identity platforms, device management, endpoint protection, productivity systems, employee lifecycle processes, and internal support operations.
- Scaling: You have hired, developed, or managed security and systems professionals and know what capabilities should remain internal versus outsourced.
- A maniacal sense of urgency: We execute at an intensity that most people think is impossible. Speed is critical and we need things done yesterday. We all work very hard and in such a competitive world there really is no other way to win. 7. Enduring frugality: We are frugal. We hate being wasteful and we are anti-luxury.
- Keep your head down: We’re boring people doing exciting work. We don’t chase short-term status — we ignore short-term dopamine hits and focus on what matters. Outsiders will underestimate us and we revel in that. 10. The power of focus: We live in a world of power laws and we cannot overestimate the unimportance of practically everything.
- ## Compensation
- Healthcare: comprehensive medical insurance (if appropriate) - Vacation: PTO with a yearly minimum (≥2wks/yr + local national holidays) - Remote: our team is fully distributed across the world and functions fully remotely - Personal development: budget for books, courses, coaching ($1200/yr) - Personal wellness: budget for gym, health apps ($1200/yr) - Coaching: free biweekly health coaching - Equipment: Macbook & work-from-home equipment provided as needed - What are we missing?
How to Stand Out
- Highlight any experience securing health‑related data or working under regulatory frameworks in your resume and interview.
- Prepare concrete examples of incident response you led, focusing on detection, containment, and post‑mortem improvements.
- Demonstrate familiarity with cloud security tools (e.g., AWS GuardDuty, Azure Sentinel) and be ready to discuss architecture decisions.
- Include any certifications (CISSP, CISM, CISA) and relevant Excel‑based analytics projects in your portfolio.
- During interviews, ask about the current security tooling stack and how the team measures risk, showing your strategic mindset.
- When discussing compensation, emphasize equity interest and inquire about the vesting schedule and performance milestones.
- Watch for vague descriptions of reporting lines or unclear escalation processes; clarity here indicates mature security governance.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.