Head of Information Security & Systems
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Being a Head of InfoSec at AIOS
We are building a world-class team.
As Head of Information Security & Systems at AIOS, your fundamental role is to build the secure foundation that allows us to scale globally without compromising patient trust, operational resilience, or speed.
You’ll own cybersecurity and internal systems across the AIOS group, spanning our healthcare businesses, technology platforms, pharmacy infrastructure, and more. This includes security strategy, identity and access management, endpoint security, incident response, architecture, tooling and overall security compliance.
You’ll turn that strategy into a consistent, scalable operating model across our entities and geographies. You’ll set clear standards, strengthen controls, establish ownership across teams, and ensuring risks are identified, prioritized, and actually resolved as the business grows.
This is both a strategic and hands-on role. You’ll advise leadership on material risks while also diving in to investigate issues, improve controls, review architecture, implement tooling, and drive remediation across the business.
Great performance in this role means we can move faster because our systems are secure, resilient, and scalable; teams understand their responsibilities; leadership has clear visibility into risk; and patients, employees, partners, and regulators can trust how we protect their data.
This is a full-time, fully remote role, and you’ll work async in the timezone of your choice — as long as you’re around until midday Pacific Time for calls as needed.
You’ll report directly to Joey Gracek, Head of Business Operations.
You’ll also work most closely with:
- Gzim Helshani (VP Engineering)
- Jordan Pellikan (Chief of Staff)
Key responsibilities
Security ownership: You own the cybersecurity strategy, roadmap, and operating model across all Aios entities and geographies.Security operations and incident response: You establish the systems and processes needed to detect, investigate, contain, and recover from security incidents. You lead the response when issues arise and ensure lessons are translated into stronger controls.Identity, access, and endpoint security: You ensure the right people have the right access to the right systems. You build scalable processes for authentication, permissions, employee onboarding and offboarding, device management, and overall access.Application and infrastructure security: You partner closely with engineering to strengthen the security of our applications, APIs, cloud infrastructure, development processes, and sensitive data. You review architecture, identify vulnerabilities, and drive remediation without unnecessarily slowing product development.Risk and compliance: You translate healthcare, privacy, and security requirements into practical controls across the business. You lead security risk assessments, audits, diligence requests, policy development, and readiness for frameworks such as HIPAA, GDPR, SOC 2, and ISO 27001.Business continuity and resilience: You ensure Aios can continue operating through system failures, security incidents, and other disruptions. You strengthen backups, recovery procedures, incident plans, and the resilience of business-critical systems.Third-party security: You assess and manage the risks created by vendors, partners, contractors, acquisitions, and new market launches. You ensure third parties meet appropriate security standards and that identified risks are actively resolved.Security leadership and culture: You make security a clear and practical responsibility across Aios. You advise leadership on material risks, establish ownership across teams, train employees, and build the internal team and external partner network required as the company scales.
Need to have
Experience: 5+ years experience leading cybersecurity, information security, or security engineering in a complex, fast-growing organization and have owned outcomes.Technical depth: You can operate credibly across identity and access management, endpoint security, cloud infrastructure, application security, incident response, vulnerability management, and corporate systems.Builder: You have built or significantly improved a security program, including its roadmap, controls, policies, tooling, processes, and operating model.Autonomy: You are comfortable entering an environment that is still evolving, identifying what needs to be done, and driving it through to completion with limited structure.Judgement: You can identify the risks that genuinely matter, explain them clearly, and implement proportionate controls without creating unnecessary friction or slowing the business down.Incident leadership: You have managed security incidents or high-severity technical issues and can lead calmly through investigation, containment, communication, recovery, and remediation.Influence: You can work effectively with engineering, operations, legal, compliance, people, clinical, and executive teams, even when you do not directly manage the people responsible for implementation.Data Protection: You have worked in an environment handling highly sensitive customer, patient, financial, employee, or similarly regulated data.
Nice to have
Healthcare Experience: You have worked in digital health, telemedicine, pharmacy, clinical operations, health insurance, or another healthcare environment.International Experience: You have owned security across multiple countries, legal entities, or business units, particularly across the US, UK, and Europe.Compliance: You have supported or led programs involving HIPAA, GDPR, UK GDPR, SOC 2, ISO 27001, or similar security and privacy frameworks.IT Ownership: You have managed identity platforms, device management, endpoint protection, productivity systems, employee lifecycle processes, and internal support operations.Scaling: You have hired, developed, or managed security and systems professionals and know what capabilities should remain internal versus outsourced.
Our cultural standards
We aim to make this your life’s work. This should be the most challenging, most rewarding role of your life. Accordingly, these are the core cultural standards to which we hold ourselves & our team-members:
Belief in the mission: We will have served 100 million patients by the end of 2035 and we transform the life of most patients who join. We have a lot of work to do. We are obsessed with our patients and are dedicated to the mission.Unwavering integrity: We are at the frontier, so we often live in ambiguity with no trodden path. When we can’t look to others for guidance, we must maintain impeccable ethics and unwavering integrity.Only the paranoid survive: Bad sh*t is coming. By joining us, you’re choosing to sail straight towards the storms with unhesitating conviction. However much we’ve already done, however far we’ve already come — it’s still Day 1 and all our work is ahead of us.If we’re average we fail: We are only interested in “insanely great”, a focus on the quality of our execution that in everyday life would be considered pathological. We have a dedication to excellence and reject incompetence.Commitment to candor: That which can be destroyed by the truth should be. You get full transparency from the company and the company expects full transparency from you. We never say anything about someone that we wouldn’t say to them directly. We give feedback with love and do not need to protect people from fleeting physical sensations.A maniacal sense of urgency: We execute at an intensity that most people think is impossible. Speed is critical and we need things done yesterday. We all work very hard and in such a competitive world there really is no other way to win.Enduring frugality: We are frugal. We hate being wasteful and we are anti-luxury. A culture of cheapness keeps us young. We spend our cash wisely & carefully — in a way that would make our grandmas proud.Bulldozing barriers: The world is malleable and we shape it. We truly believe this and act accordingly. We are relentlessly resourceful and are at the mercy of no-one but ourselves. You’ll be shocked how capable you are and how much you can achieve.Keep your head down: We’re boring people doing exciting work. We don’t chase short-term status — we ignore short-term dopamine hits and focus on what matters. Outsiders will underestimate us and we revel in that.The power of focus: We live in a world of power laws and we cannot overestimate the unimportance of practically everything. Know your One Thing, and nail it.
🎯 “You just build a f*ing amazing experience. Make each step amazing. Make every decision in the long term interest of the customer. Give the customer massively more value than you take.”
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Fella Health
Explore Top Companies in this Space
Fella Health
View Company ProfileFella Health (operating under fellahealth.com, legally AIOS Inc.) is an enterprise-grade telehealth clinic, specialized men's metabolic health engine, and medical weight management platform engineered to dismantle the severe social stigma, clinical fragmentation, and lifestyle friction preventing busy men from accessing sustainable obesity treatments. Founded in 2021 by Cambridge University alumni Richie Cartwright and Luke Harries under the institutional incubation of Y Combinator, the corporation revolutionized the consumer digital health sector by building a personalized, science-backed care delivery network tailored specifically for men. Moving past historical weight-loss paradigms—which relied on inefficient, low-compliance "willpower-only" routines that fail long-term for roughly 90 percent of patients—Fella Health natively unifies board-certified clinical obesity evaluations, continuous medical oversight, direct-to-home deliveries of advanced GLP-1 and GIP metabolic medications (such as semaglutide and tirzepatide), and continuous 1:1 behavioral health coaching. Underpinning its hyper-scale distribution architecture is ClinicOS, the company's proprietary, AI-driven clinical operating system designed to automate administrative workflows, optimize patient-clinician triage, and enable consumer brands to launch direct-to-patient healthcare channels seamlessly at scale. Backed by marquee institutional venture capital firms including Y Combinator, BrandProject, and Global Founders Capital, alongside prominent angel backers behind tech giants like Indeed and Alan, the cash-flow positive enterprise has scaled its multi-brand footprint across the United States and the United Kingdom. Serving over 50,000 active members and generating upwards of $100 million in annualized revenue, the organization continues to pioneer scalable consumer biotech access. Headquartered in Austin, Texas, with additional offices in San Francisco, California, the company operates via a highly distributed, remote-first global workspace. What distinguishes Fella Health is its strict, no-nonsense integration of clinical precision and psychological re-conditioning; by connecting high-availability programmatic telemedicine infrastructure with advanced endocrine and metabolic pharmacology, the corporation remains a definitive vanguard in the global fight against chronic metabolic disease and modern longevity optimization.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.




