# Senior Security Engineer

[Aidocmedical](https://gurify.com/jobs?q=Aidocmedical) · Tel Aviv-Yafo, Israel · Posted 4 weeks ago

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/aidocmedical/jobs/4920094101)

## Job description

### About Aidoc

Aidoc is the market leader in healthcare AI and has developed the world's largest clinical frontier model, supporting nearly 50 million patients each year.
Aidoc is deployed in more than 2,000 medical centers worldwide. Since our founding in 2016, Aidoc has raised over $500 million and achieved a record number of FDA-cleared solutions.

Medical diagnosis is hitting a breaking point, where the number of physicians hasn't kept up with the rapidly growing patient load. This leads to misdiagnosis and treatment delays that result in hundreds of thousands of deaths every year. Aidoc assists clinicians by precisely highlighting diseases directly on medical images, preventing misdiagnosis and ensuring that urgent patients receive the immediate attention they need.

### About this role

As a Senior Product Security Engineer, you will help ensure that security is built into the products, platforms, AI systems, and clinical workflows that support healthcare providers and patients at scale. This is a hands-on technical role focused on securing real systems in production, influencing architecture, and partnering closely with engineering, AI, DevOps, product, quality and regulatory.

You will work across cloud-native services, medical imaging workflows, healthcare integrations, AI/ML pipelines, APIs, data flows, and regulated product development processes. Your work will directly support Aidoc's ability to deliver secure, reliable, and trusted clinical AI solutions to healthcare organizations worldwide.

### What Makes This Role Unique at Aidoc

- Clinical AI with real-world patient impact - Aidoc operates in an environment where security is not only about protecting systems and data. Security decisions can affect clinical workflows, care-team coordination, customer trust, and patient safety.

- Highly sensitive healthcare data - You will help protect medical imaging data, clinical metadata, PHI/PII, customer environments, and AI-driven workflows that require strong privacy, access control, data protection, and auditability.

- Security for AI/ML and medical imaging systems - The role extends beyond traditional AppSec into AI/ML security, data pipeline protection, inference integrity, model-related risks, and misuse scenarios in clinical workflows.

- Complex healthcare integrations - Aidoc integrates with hospital systems and healthcare workflows that may include PACS, EHR, VNA, RIS/worklists, scheduling systems, and communication platforms. You will help secure the data flows, authentication models, APIs, and deployment patterns behind these integrations.

- Engineering-driven security in a regulated environment - This is not a checkbox compliance role. However, because Aidoc operates in healthcare and clinical AI, security must be practical, evidence-based, and aligned with regulatory, customer, and quality expectations.

- Cloud-native scale and production ownership - You will work with modern cloud infrastructure, Kubernetes, containers, CI/CD pipelines, identity and access management, observability, vulnerability management, and software supply-chain controls.

### Responsibilities

- Secure product and clinical workflows end-to-end - Work directly with engineering and product teams to identify, prioritize, and remediate security risks across services, APIs, medical imaging workflows, AI outputs, data flows, and customer-facing product features.

- Drive secure-by-design architecture - Provide practical security guidance on authentication, authorization, tenant/customer isolation, encryption, secrets management, service-to-service communication, audit logging, and secure data handling.

- Strengthen cloud-native security - Improve security across cloud environments, Kubernetes, containers, IAM, network segmentation, workload identity, infrastructure-as-code, logging, monitoring, and cloud security posture management.

- Embed security into the development lifecycle - Integrate, tune, and operationalize security tooling across CI/CD pipelines, including SAST, SCA, IaC scanning, container scanning, secrets detection and build/release integrity controls.

- Own vulnerability management as an engineering system - Prioritize vulnerabilities based on exploitability, product exposure, customer impact, clinical risk, and regulatory relevance. Drive remediation with engineering teams and reduce recurring issues through root-cause improvements.

- Secure AI/ML-driven features and data pipelines - Partner with AI, data, and platform teams to identify risks related to training and inference data, model inputs and outputs, model misuse, data leakage, access to sensitive datasets, pipeline integrity, and production monitoring.

- Improve software supply-chain security - Reduce risk across open-source dependencies, third-party components, third-party algorithms, container images, build systems, artifact repositories, release pipelines, and deployment processes.

- Mentor and enable engineers - Help developers understand security risks, make secure design decisions, and take ownership of security in their code, services, and infrastructure.

- Communicate risk clearly - Translate technical security findings into clear risk, impact, and trade-off language for engineering, product, leadership, quality, regulatory, and customer-facing stakeholders.

### Requirements

- 5+ years of experience in Product Security, Application Security, Cloud Security, or a similar hands-on security engineering role.

- Strong hands-on experience securing production systems, not only performing assessments or reviews.

- Strong understanding of secure design, threat modeling, and architecture risk analysis.

- Deep knowledge of application security, including OWASP Top 10, API security, authentication, authorization, access control, secure session handling, input validation, and modern attack vectors.

- Experience securing distributed systems, APIs, web applications, backend services, and cloud-native architectures.

- Strong experience with cloud environments, especially AWS and/or Azure, including IAM, network security, encryption, logging, monitoring, and workload security.

- Experience with Kubernetes, containers, infrastructure-as-code, CI/CD pipelines, and modern DevOps workflows.

- Practical experience with security tooling such as SAST, SCA, IaC scanning, container scanning, secrets detection, SBOM tools, vulnerability scanners, and cloud security tools.

- Experience with vulnerability management, risk prioritization, remediation planning, and working with engineering teams to fix issues at scale.

- Strong understanding of software supply-chain security, including dependency risk, build/release integrity, artifact security, and third-party component governance.

- Experience working with modern development stacks such as Python, Java, JavaScript/TypeScript, React, microservices, APIs, and cloud-native services.

- Ability to influence engineers through technical credibility, practical guidance, and strong collaboration.

- Strong communication skills and the ability to explain security risks to technical and non-technical stakeholders.

### Working at Aidoc

### Our Perks:

- Be part of something big - using cutting-edge technologies to transform the Healthcare industry (while saving patients’ lives)

- We work in a hybrid model, with our new offices located at 34 HaMasger Street in Tel Aviv and parking for employees.

- Amazing and healthy breakfasts and lunches prepared daily by our personal chef!

- Stocked up kitchen & meal card

- Wellness: Aidoc employees-only gym, plus Pilates, Yoga, and functional workouts classes.

- Amazing culture - collaborative, transparent & fun!

- Attractive compensation package & benefits

Aidoc is deeply committed to creating an inclusive workplace, and to the principle of equal opportunity for all individuals. We prohibit discrimination and harassment based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other status protected by law.

**Live in Aidocmedical’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- AI [Senior Security Engineer](https://gurify.com/job/senior-security-engineer-at-aidocmedical-5bd03c34f36a) Aidocmedical · Tel Aviv-Yafo, Israel · 4 weeks ago
- CR [Senior Application Security Engineer](https://gurify.com/job/senior-application-security-engineer-at-crossriver-600f9360b683) Crossriver · Jerusalem, Israel · last week
- CL [Senior Security Operations Engineer - Open Position](https://gurify.com/job/senior-security-operations-engineer-open-position-at-claroty-f77f7538461d) Claroty · Tel Aviv, Israel · last week
- OL [DevOps Engineer (U.S Citizen) - Oligo Security](https://gurify.com/job/devops-engineer-u-s-citizen-oligo-security-at-oligosecurity-2bf93bd623c4) Oligosecurity · Tel Aviv-Yafo, Israel · last week
- SO [Cloud Security Engineer](https://gurify.com/job/cloud-security-engineer-at-somekhchaikin-3a0311a8860b) Somekhchaikin · Tel Aviv-Yafo, Israel · 6 days ago
- ZE [AI Agent Security | Product Security Engineer](https://gurify.com/job/ai-agent-security-product-security-engineer-at-zenity-f5b9cf85b08a) Zenity · Tel Aviv-Jaffa, Israel · 6 days ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Security Engineer","description":"\u003Ch3\u003EAbout Aidoc\u003C/h3\u003E\u003Cp\u003EAidoc is the market leader in healthcare AI and has developed the world\u0026#39;s largest clinical frontier model, supporting nearly 50 million patients each year.\u003Cbr /\u003EAidoc is deployed in more than 2,000 medical centers worldwide. Since our founding in 2016, Aidoc has raised over $500 million and achieved a record number of FDA-cleared solutions.\u003C/p\u003E\u003Cp\u003EMedical diagnosis is hitting a breaking point, where the number of physicians hasn\u0026#39;t kept up with the rapidly growing patient load. This leads to misdiagnosis and treatment delays that result in hundreds of thousands of deaths every year. Aidoc assists clinicians by precisely highlighting diseases directly on medical images, preventing misdiagnosis and ensuring that urgent patients receive the immediate attention they need.\u003C/p\u003E\u003Ch3\u003EAbout this role\u003C/h3\u003E\u003Cp\u003EAs a Senior Product Security Engineer, you will help ensure that security is built into the products, platforms, AI systems, and clinical workflows that support healthcare providers and patients at scale. This is a hands-on technical role focused on securing real systems in production, influencing architecture, and partnering closely with engineering, AI, DevOps, product, quality and regulatory.\u003C/p\u003E\u003Cp\u003EYou will work across cloud-native services, medical imaging workflows, healthcare integrations, AI/ML pipelines, APIs, data flows, and regulated product development processes. Your work will directly support Aidoc\u0026#39;s ability to deliver secure, reliable, and trusted clinical AI solutions to healthcare organizations worldwide.\u003C/p\u003E\u003Ch3\u003EWhat Makes This Role Unique at Aidoc\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EClinical AI with real-world patient impact - Aidoc operates in an environment where security is not only about protecting systems and data. Security decisions can affect clinical workflows, care-team coordination, customer trust, and patient safety.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHighly sensitive healthcare data - You will help protect medical imaging data, clinical metadata, PHI/PII, customer environments, and AI-driven workflows that require strong privacy, access control, data protection, and auditability.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecurity for AI/ML and medical imaging systems - The role extends beyond traditional AppSec into AI/ML security, data pipeline protection, inference integrity, model-related risks, and misuse scenarios in clinical workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EComplex healthcare integrations - Aidoc integrates with hospital systems and healthcare workflows that may include PACS, EHR, VNA, RIS/worklists, scheduling systems, and communication platforms. You will help secure the data flows, authentication models, APIs, and deployment patterns behind these integrations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEngineering-driven security in a regulated environment - This is not a checkbox compliance role. However, because Aidoc operates in healthcare and clinical AI, security must be practical, evidence-based, and aligned with regulatory, customer, and quality expectations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECloud-native scale and production ownership - You will work with modern cloud infrastructure, Kubernetes, containers, CI/CD pipelines, identity and access management, observability, vulnerability management, and software supply-chain controls.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EResponsibilities\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ESecure product and clinical workflows end-to-end - Work directly with engineering and product teams to identify, prioritize, and remediate security risks across services, APIs, medical imaging workflows, AI outputs, data flows, and customer-facing product features.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDrive secure-by-design architecture - Provide practical security guidance on authentication, authorization, tenant/customer isolation, encryption, secrets management, service-to-service communication, audit logging, and secure data handling.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrengthen cloud-native security - Improve security across cloud environments, Kubernetes, containers, IAM, network segmentation, workload identity, infrastructure-as-code, logging, monitoring, and cloud security posture management.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEmbed security into the development lifecycle - Integrate, tune, and operationalize security tooling across CI/CD pipelines, including SAST, SCA, IaC scanning, container scanning, secrets detection and build/release integrity controls.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOwn vulnerability management as an engineering system - Prioritize vulnerabilities based on exploitability, product exposure, customer impact, clinical risk, and regulatory relevance. Drive remediation with engineering teams and reduce recurring issues through root-cause improvements.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESecure AI/ML-driven features and data pipelines - Partner with AI, data, and platform teams to identify risks related to training and inference data, model inputs and outputs, model misuse, data leakage, access to sensitive datasets, pipeline integrity, and production monitoring.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EImprove software supply-chain security - Reduce risk across open-source dependencies, third-party components, third-party algorithms, container images, build systems, artifact repositories, release pipelines, and deployment processes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMentor and enable engineers - Help developers understand security risks, make secure design decisions, and take ownership of security in their code, services, and infrastructure.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECommunicate risk clearly - Translate technical security findings into clear risk, impact, and trade-off language for engineering, product, leadership, quality, regulatory, and customer-facing stakeholders.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ERequirements\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E5\u002B years of experience in Product Security, Application Security, Cloud Security, or a similar hands-on security engineering role.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong hands-on experience securing production systems, not only performing assessments or reviews.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong understanding of secure design, threat modeling, and architecture risk analysis.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDeep knowledge of application security, including OWASP Top 10, API security, authentication, authorization, access control, secure session handling, input validation, and modern attack vectors.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience securing distributed systems, APIs, web applications, backend services, and cloud-native architectures.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong experience with cloud environments, especially AWS and/or Azure, including IAM, network security, encryption, logging, monitoring, and workload security.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with Kubernetes, containers, infrastructure-as-code, CI/CD pipelines, and modern DevOps workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPractical experience with security tooling such as SAST, SCA, IaC scanning, container scanning, secrets detection, SBOM tools, vulnerability scanners, and cloud security tools.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with vulnerability management, risk prioritization, remediation planning, and working with engineering teams to fix issues at scale.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong understanding of software supply-chain security, including dependency risk, build/release integrity, artifact security, and third-party component governance.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience working with modern development stacks such as Python, Java, JavaScript/TypeScript, React, microservices, APIs, and cloud-native services.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to influence engineers through technical credibility, practical guidance, and strong collaboration.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong communication skills and the ability to explain security risks to technical and non-technical stakeholders.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWorking at Aidoc\u003C/h3\u003E\u003Ch3\u003EOur Perks:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EBe part of something big - using cutting-edge technologies to transform the Healthcare industry (while saving patients\u2019 lives)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWe work in a hybrid model, with our new offices located at 34 HaMasger Street in Tel Aviv and parking for employees.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAmazing and healthy breakfasts and lunches prepared daily by our personal chef!\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStocked up kitchen \u0026amp; meal card\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWellness: Aidoc employees-only gym, plus Pilates, Yoga, and functional workouts classes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAmazing culture - collaborative, transparent \u0026amp; fun!\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAttractive compensation package \u0026amp; benefits\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EAidoc is deeply committed to creating an inclusive workplace, and to the principle of equal opportunity for all individuals. We prohibit discrimination and harassment based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other status protected by law.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-security-engineer-at-aidocmedical-d4749e23f716"},"url":"https://gurify.com/job/senior-security-engineer-at-aidocmedical-d4749e23f716","datePosted":"2026-07-06","validThrough":"2026-09-21T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Aidocmedical","sameAs":"https://job-boards.greenhouse.io/aidocmedical"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"IL","addressLocality":"Tel Aviv-Yafo"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Israel","item":"https://gurify.com/jobs/israel"},{"@type":"ListItem","position":3,"name":"Senior Security Engineer","item":"https://gurify.com/job/senior-security-engineer-at-aidocmedical-d4749e23f716"}]}
```
