HIPAA Security Engineer

Flo Health, Inc.
California City, CA, United States
27 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Software as a Service Cyber Security Kubernetes RSA Archer Platform Devsecops Docker

Job description

We are seeking a HIPAA Security Engineer to join our team in London, UK. While this posting is open to candidates currently based in the United States, this position requires full-time relocation to London. We offer comprehensive visa sponsorship and a full relocation support package to ensure a smooth transition for the selected candidate.As a key member of Flo’s Security Architecture team, you will lead the design and operation of our US Healthcare security controls. You will own the roadmap for HIPAA compliance and SOC2 Type II certification, partnering with Engineering and Legal to build a secure, compliant platform for millions of users., * Compliance Leadership: Lead annual SOC 2 and HIPAA certifications, managing interfaces with external auditors and professional services.

  • Policy & Risk: Define and maintain security policies; embed risk assessment activities within engineering processes and vendor management.
  • Operational Excellence: Partner with control owners to automate evidence gathering and ensure controls reduce friction rather than creating it.
  • Stakeholder Management: Serve as the primary Security POC for US regulators and partners; support the wider Security team with ISO 27001/27701 alignment.
  • Tooling: Manage and integrate GRC platforms to streamline compliance monitoring and reporting.

Requirements

  • Experience: 7+ years in security/compliance (3+ in leadership), with a Bachelor’s degree in a related field.
  • Core Skills: Deep expertise in SOC 2 and HIPAA frameworks within a Cloud-based SaaS environment.
  • Technical Knowledge: Familiarity with PHI handling, GRC platforms, and compliance automation.
  • Soft Skills: Strong ability to translate complex compliance requirements into clear actions for engineering teams.

Preferred: CISA/CISSP certifications; experience with NIST, HiTrust, Docker/Kubernetes, and DevSecOps.

Benefits & conditions

Pulled from the full job description Parental leave Sabbatical Paid holidays, We’re a mission-led, product-driven team. We move fast, stay focused and take ownership - from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.

You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience, and the drive to keep going when things get tough. Because better health outcomes are worth it.

What you’ll get

We support impact with meaningful reward. Here’s what that looks like:

  • Competitive salary and annual reviews
  • Opportunity to participate in Flo’s performance incentive scheme
  • Paid holiday, sick leave, and female health leave
  • Enhanced parental leave and pay for maternity, paternity, same-sex and adoptive parents
  • Accelerated professional growth through world-changing work and learning support
  • In-person collaboration and work in a hybrid model, with 3 days per week spent in the office
  • 5-week fully paid sabbatical at 5-year Floversary
  • Flo Premium for friends & family, plus more health, pension and wellbeing perks

About the company

Flo is the world’s #1 health & fitness app worldwide on a mission to build a better future for female health. Backed by a $200M investment led by General Atlantic, we became the first product of our kind to reach a $1B valuation in 2024 - and we’re not slowing down.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

2:07 min

Leveraging cloud infrastructure for security and healthcare compliance

Leo Lindhorst · World Congress 2022

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

Videos

See all

Related articles

See all