Overview
In this role you drive the design and operation of Flo’s US healthcare security controls, owning HIPAA and SOC 2 Type II readiness. You’ll partner with Engineering and Legal to build a secure, compliant platform used by millions. You’ll lead governance, policy, and risk programs while enabling automated evidence gathering to reduce friction. This is a mission-led environment that balances rigorous compliance with fast, impactful delivery.
Pay / Benefits
- Competitive salary
- Performance incentive scheme
- Paid holidays and parental leave
- Hybrid work model with office in 3 days/week
- Sabbatical at 5-year anniversary
- Flo Premium for friends and family
Responsibilities
- Lead annual SOC 2 and HIPAA certifications, coordinating with auditors and services
- Define and maintain security policies and embed risk assessment in engineering and vendor processes
- Collaborate with control owners to automate evidence gathering and streamline controls
- Act as primary Security point of contact for US regulators and partners; align with ISO 27001/27701
- Manage and integrate GRC platforms to streamline monitoring and reporting
Key requirements
- 7+ years in security/compliance (3+ in leadership)
- Bachelor’s degree in a related field
- Deep expertise in SOC 2 and HIPAA within a Cloud-based SaaS environment
- Familiarity with PHI handling, GRC platforms, and compliance automation
- Strong ability to translate complex requirements for engineering teams
- Effective communication with cross-functional teams
- Leadership and stakeholder management
- Analytical thinking and risk-based decision making
- SOC 2 and HIPAA frameworks
- GRC platforms
- Compliance automation
…
