Head of CyberSecurity at AIOS — Remote, $150-250k/yr inc equity
Aios · Remote · 2026-08-03
About this role
ABOUT AIOS
AIOS is building the world’s first full-stack AI doctor.
We’re at $350M ARR, growing from $10M/yr 12 months ago. We’re the world’s fastest growing AI doctor.
We’re faithfully serving >150k/mo patients via Bolt Pharmacy, our main UK brand. We’re profitable.
Our strategy exists at the intersection of two strong theses:
1. The AI doctor that wins will get to escape velocity using GLP-1s, the fastest growing consumer product in history.
2. The $2T European healthcare market is overlooked by the most talented builders.
Our master plan:
- Step 0 → $100M/yr by end of 2025: We went from $10M to $100M in 6 months serving the UK GLP-1 market.
- Step 1 → $1B ARR by end of 2026: Over the last 12 months we've grown from 3k to 150k UK active GLP-1 patients. We’ll continue this growth curve to hit $1B ARR.
- Step 2 → $10B ARR by end of 2028: Blitzscale Europe. We’ll be Europe’s largest GLP-1 provider.
- Step 3 → $100B/yr by end of 2031: Get regulatory approval across Europe for our Full Autonomous Prescribing (FAP) system. Win contracts at scale with European payers to mass replace human labor. We’ll be the dominant full-stack AI doctor in Europe.
- Step 4 → $1T/yr by end of 2035: With one line of code and zero human time, you can use AIOS to treat any patient globally with any medication.
In so doing, we’ll become the world’s first trillion-dollar healthcare company.
We’re a young, founder-led company. This is still Day 1 and all our work is ahead of us.
You can read more about working with us here: Working at AIOS https://app.notion.com/p/Working-at-AIOS-5b5c0a584af44de78ac7fb9b2cf8d993?pvs=21
BEING A HEAD OF CYBERSECURITY AT AIOS
We are building a world-class team.
As Head of CyberSecurity at AIOS, your fundamental role is to build the secure foundation that allows us to scale globally without compromising patient trust, operational resilience, or speed.
You’ll own cybersecurity and internal systems across the AIOS group, spanning our healthcare businesses, technology platforms, pharmacy infrastructure, and more. This includes security strategy, identity and access management, endpoint security, incident response, architecture, tooling and overall security compliance.
You’ll turn that strategy into a consistent, scalable operating model across our entities and geographies. You’ll set clear standards, strengthen controls, establish ownership across teams, and ensuring risks are identified, prioritized, and actually resolved as the business grows.
This is both a strategic and hands-on role. You’ll advise leadership on material risks while also diving in to investigate issues, improve controls, review architecture, implement tooling, and drive remediation across the business.
Great performance in this role means we can move faster because our systems are secure, resilient, and scalable; teams understand their responsibilities; leadership has clear visibility into risk; and patients, employees, partners, and regulators can trust how we protect their data .
This is a full-time, fully remote role, and you’ll work async in the timezone of your choice — as long as you’re around until midday Pacific Time for calls as needed.
You’ll report directly to Joey Gracek https://www.linkedin.com/in/josephgracek/, Head of Business Operations.
You’ll also work most closely with:
- Gzim Helshani https://www.linkedin.com/in/ghels/ (VP Engineering)
- Jordan Pellikan https://www.linkedin.com/in/jordan-pellikan-847023201/ (Chief of Staff)
KEY RESPONSIBILITIES
- Security ownership: You own the cybersecurity strategy, roadmap, and operating model across all Aios entities and geographies.
- Security operations and incident response: You establish the systems and processes needed to detect, investigate, contain, and recover from security incidents. You lead the response when issues arise and ensure lessons are translated into stronger controls.
- Identity, access, and endpoint security: You ensure the right people have the right access to the right systems. You build scalable processes for authentication, permissions, employee onboarding and offboarding, device management, and overall access.
- Application and infrastructure security: You partner closely with engineering to strengthen the security of our applications, APIs, cloud infrastructure, development processes, and sensitive data. You review architecture, identify vulnerabilities, and drive remediation without unnecessarily slowing product development.
- Risk and compliance: You translate healthcare, privacy, and security requirements into practical controls across the business. You lead security risk assessments, audits, diligence requests, policy development, and readiness for frameworks such as HIPAA, GDPR, SOC 2, and ISO 27001.
- Business continuity and resilience: You ensure Aios can continue operating through system failures, security incidents, and other disruptions. You strengthen backups, recovery procedures, incident plans, and the resilience of business-critical systems.
- Third-party security: You assess and manage the risks created by vendors, partners, contractors, acquisitions, and new market launches. You ensure third parties meet appropriate security standards and that identified risks are actively resolved.
- Security leadership and culture: You make security a clear and practical responsibility across Aios. You advise leadership on material risks, establish ownership across teams, train employees, and build the internal team and external partner network required as the company scales.
NEED TO HAVE
- Experience: 5+ years experience leading cybersecurity, information security, or security engineering in a complex, fast-growing organization and have owned outcomes.
- Technical depth: You can operate credibly across identity and access management, endpoint security, cloud infrastructure, application security, incident response, vulnerability management, and corporate systems.
-…
Skills asked for
- cybersecurity
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.