About the role
500M+ downloads. 80M+ monthly users. A decade of building – and we’re still accelerating.Flo is the world’s #1 health & fitness app worldwide on a mission to build a better future for female health. Backed by a $200M investment led by General Atlantic, we became the first product of our kind to reach a $1B valuation in 2024 – and we’re not slowing down.With 7M paid subscribers and the highest-rated experience in the App Store’s health category, we’ve spent 10 years earning trust at scale. Now, we’re building the next generation of digital health – AI-powered, privacy-first, clinically backed – to help our users know their body better.The jobAs a key member of Flo’s Security Architecture team, you will lead the design and operation of our US Healthcare security controls. You'll work directly with Product and Engineering teams to translate HIPAA and SOC 2 requirements into technical security controls across Flo's AWS multi-account environment - including EKS, Lambda, RDS, S3, VPC networking, IAM, and KMS.You'll own the roadmap for HIPAA compliance and SOC 2 Type II certification, working closely with external auditors and professional services partners, and partnering with Engineering and Legal to build a secure, compliant platform for millions of users.Your ExperienceMust have:7+ years in security, compliance, or risk management (3+ in a leadership capacity), with a Bachelor's degree in a related field or equivalent experience.Deep expertise in SOC 2 and HIPAA frameworks within the AWS environment.Familiarity with PHI handling, GRC and compliance automation platforms, and exposure to enterprise architecture frameworks such as TOGAF.Strong ability to manage multiple concurrent audit and certification workstreams.Excellent written and verbal communication, with the ability to translate complex compliance requirements into clear actions for engineering and business teams.Nice to have:CISA, CISM, or CISSP certificationsExperience with NIST 800-53, Cloud Security Alliance (CSA), and Center for Internet Security (CIS) frameworksExperience in healthcare or another regulated industry; HITRUST experience a plusExperience building compliance roadmaps in early-stage startupsExposure to containerization (Docker/Kubernetes), serverless, and big data platformsExposure to DevSecOps and sprint-based Agile developmentVendor management experienceWhat you'll be doingYou'll be responsible for:Compliance Leadership: Lead annual SOC 2 and HIPAA certifications, managing interfaces with external auditors and professional services.Technical Control Design: Partner with Engineering to harden AWS workloads (EKS, EC2, data pipelines, and more) to meet HIPAA and SOC 2 controls; perform technical security design reviews and architectural risk assessments for services handling PHI.Policy & Risk: Define and maintain security policies and standards; embed risk assessment activities within engineering processes, and evolve Flo's security risk management framework.Vendor Risk Management: Support vendor risk activities including contract reviews and security posture assessments.Operational Excellence: Partner with control owners to automate evidence gathering and ensure controls reduce friction rather than creating it.Stakeholder Management: Serve as the primary Security POC for US regulators and partners; support the wider Security team with ISO 27001/27701 alignment; report risk status to security leadership.Tooling: Manage and integrate GRC and compliance automation platforms to streamline monitoring and reporting.#LI-AJ1 #LI-HybridHow we workWe’re a mission-led, product-driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience, and the drive to keep going when things get tough. Because better health outcomes are worth it. What you'll getWe support impact with meaningful reward. Here’s what that looks like:Competitive salary and annual reviewsOpportunity to participate in Flo’s performance incentive schemePaid holiday, sick leave, and female health leaveEnhanced parental leave and pay for maternity, paternity, same-sex and adoptive parentsAccelerated professional growth through world-changing work and learning supportIn-person collaboration and work in a hybrid model, with 3 days per week spent in the office5-week fully paid sabbatical at 5-year FloversaryFlo Premium for friends & family, plus more health, pension and wellbeing perksDiversity, equity and inclusionOur strength is in our differences. At Flo, hiring is based on merit, skill and what you bring to the role – nothing else. We’re proud to be an equal opportunity employer, and we welcome applicants from all backgrounds, communities and identities. Read our privacy notice for job applicants.
About this listing
Screened by Joboru
This role passed our automated spam and quality filters and was active in our feed when last checked. Joboru is an aggregator — here is how we screen listings. If anything looks off, tell us.
Similar jobs you may like
Senior Cyber Security Engineer (EDR)
2 days agoSanderson Government and Defence
Senior Security Engineer
2 days agoOcho
Senior AWS Security Engineer
2 days agoOcho
Senior Security Architect TLNT1_NI
2 days agoOcho
Senior Security Engineer (WFH)
2 days agoOcho
Senior Security Engineer(Hybrid)
2 days agoOcho
Lead Security Engineer TLNT1_NI
2 days agoOcho
Senior Security Engineer TLNT1_NI
2 days agoOcho
Fire & Security Engineer's Required
2 days agoNorthtech Fire & Security