Staff Product Security Engineer in London

Staff Product Security Engineer in London

London Full-Time 63000 - 77000 £ / year (est.) Working from home possible
D

At a Glance

  • Tasks: Lead security initiatives and ensure our telemedicine platform is safe and compliant.
  • Company: Join doxy.me, the world's most loved telemedicine solution, on a mission to revolutionise healthcare.
  • Benefits: Enjoy unlimited PTO, private healthcare, and a flexible remote work environment.
  • Other info: Be part of a diverse team of innovators and enjoy excellent career growth opportunities.
  • Why this job: Make a real impact in healthcare security while working with cutting-edge technology.
  • Qualifications: Bachelor's degree or equivalent experience in computer science or related fields.

The predicted salary is between 63000 - 77000 £ per year.

Staff Product Security Engineer

Who we are

We’re doxy. me (doc-see-me), the world's most loved telemedicine solution, and we're on a mission to connect the world to the future of healthcare.

We believe that cost and complexity should never be a barrier to telemedicine.

That’s why we created a simple, free, and secure telemedicine platform.

Since 2013, we’ve grown to more than 1 million healthcare providers from 180+ countries who have clocked over 8 billion minutes of telemedicine sessions to date.

Our goal is to deliver the future of healthcare to every patient and healthcare professional on earth. Help us get there by joining our team of innovators, dreamers, and doers.

We’re a remote-first company with regional hubs for in-person collaboration (Austin, TX, Boston, MA, Charleston, SC, Salt Lake City, UT & London, UK).

Who you are

We’re seeking a Staff Product Security Engineer who thrives on making an impact by being part of a team that ensures that Doxy. me is safe, secure, and compliant over time with industry standards for security, secure SDLC, and secure operating principles.

As an early member of Doxy. me’s Application Security team you will build the technical foundation of the security and privacy of our products long into the future.

  • What you’ll do
  • Provide security leadership and guidance within our product engineering teams through developer-led threat modeling and education on security and privacy best practices that prevent the authoring of vulnerabilities.
  • Coordinate security requirements and standards throughout the product life cycle by working closely with product engineering to manage the vulnerabilities, cryptography, security monitoring, and risk management controls within our application-based products.
  • Participate in the development of Doxy. me’s Dev Sec Ops security strategy and posture by designing, advocating and helping build secure-by-default CI/CD pipelines and processes
  • Develop engineering reference implementations on topics of security patterns and security guardrails and how to implement these into software frameworks and the technology stack.

Support and implement security technology and security control design proof of concepts and implementations

  • Be a pioneering member of the Doxy. me Information Security Team; liaise with Product and Engineering teams to ensure all product business cases include functional security specs to ensure compliance with information security standards
  • Track trends against various metrics that capture the risks, threats, and vulnerabilities within the product environment then prioritise and implement remediation activities for application flaws.
  • Your skills and experience
  • A Bachelor's degree in computer science, programming, or related field and or equivalent job experience in lieu of a degree.
  • Experience working with remote, globally distributed teams
  • Experience working in organisations that develop software and/or operate managed infrastructure and technology services for their own customers
  • AWS platforms or services (also consider equivalent experience in Azure or GCP)
  • Kubernetes and container infrastructure
  • Secure development and application of IAC solutions (Terraform, Helm)
  • Experience with Dev Ops tools and processes, such as continuous integration and continuous deployment (CI/CD)
  • Experience with security testing tools, such as static Code analysis and dynamic Application security testing (DAST)
  • Strong understanding of OWASP Top 10, application security vulnerabilities and web security testing methodologies
  • Understanding of secure coding practices for compliance requirements within SOC2, ISO, HIPAA, HITRUST, etc.
  • Able to effectively give, receive, and respond to feedback
  • Ability to educate company employees about security measures.
  • What we can offer you

We have been evolving our benefits since launching in the UK in 2023; we’re continually seeking employee feedback to ensure they deliver real value to everyone and, as such, the below is not a finite, exhaustive list.

  • Alongside a competitive salary, we also offer;
  • Unlimited PTO
  • Private medical, optical and dental healthcare through AXA
  • 5% matched company pension
  • Remote working - we have recently secured a small flexible office workspace in London Liverpool Street (here).

Our current expectations are for teams to meet once per month in office; we would still anticipate a remote dominant environment going forward

  • Company equipment (inc. latest laptop) + £500 spending allowance on equipment you can keep
  • Interview process
  • 1st stage - Chat with our internal recruiter
  • 2nd stage - Hiring Manager interview
  • 3rd stage - Team Based interview
  • 4th stage - Technical interview/test
  • 5th stage - Meet with our VP of Engineering
  • Additional information
  • Doxy. me tech stack
  • Frontend: React, Type Script, Playwright, Web RTC, Next. js, Nx. dev
  • Backend: Nodejs, Type Script, Jest, Nest JS, Nx. dev
  • Cloud: AWS
  • 3rd party: Vonage, Segment, Twilio, Stripe
  • Our team: technologists, academics, researchers, and innovators from all over the world. English is the language used in all internal communication.
  • To ensure HIPAA compliance we perform background checks after extending a job offer
  • #J-18808-Ljbffr

Staff Product Security Engineer in London employer: Doxy.me Inc.

Doxy.me is an exceptional employer that champions a remote-first work culture, offering flexibility and a supportive environment for its employees. With a strong focus on professional growth, team members have access to continuous learning opportunities and the chance to innovate within the rapidly evolving field of telemedicine. Joining Doxy.me means being part of a mission-driven team dedicated to improving healthcare accessibility while enjoying the benefits of a collaborative and inclusive workplace.

D

Contact Details:

Doxy.me Inc. Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Staff Product Security Engineer in London

Join Local Tech Meetups

Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at Doxy.me Inc. or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!

Contribute to Open Source Projects

Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to Doxy.me Inc..

Tap into Online Developer Communities

Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like Doxy.me Inc..

Explore Job Boards Specifically for Tech Roles

Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like Doxy.me Inc. that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!

We think you need these skills to ace Staff Product Security Engineer in London

Security Leadership
Threat Modelling
Security Best Practices
Vulnerability Management
Cryptography
Risk Management
DevSecOps

Some tips for your application 🫡

Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.

Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at Doxy.me Inc..

Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at Doxy.me Inc. and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!

Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!

How to prepare for a job interview at Doxy.me Inc.

Brush Up on Your Coding Skills

For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.

Know Your Tools and Frameworks

Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If Doxy.me Inc. uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.

Showcase Your Projects

Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.

Prepare for Behavioural Questions

While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.