HIPAA Security Engineer at Flo Health
on-site · full-time · Visa sponsorship
Apply for this role at Flo Health
Responsibilities:
- Own the HIPAA compliance roadmap and lead annual HIPAA and SOC 2 Type II certification activities.
- Design, operate, and improve US healthcare security controls across the platform.
- Define and maintain security policies, embed risk assessments into engineering and vendor processes.
- Automate evidence collection and partner with control owners to reduce audit friction.
- Manage GRC tooling, integrate compliance monitoring, and produce clear reports for stakeholders.
- Act as primary security point of contact for US regulators, external auditors, and partners; support ISO 27001/27701 alignment.
Requirements:
- 7+ years in security/compliance with at least ~3 years in a leadership or senior contributor role; bachelor’s degree in a related field preferred.
- Deep, hands-on experience with HIPAA and SOC 2 in cloud-based SaaS environments and practical PHI handling knowledge.
- Familiarity with GRC platforms, compliance automation, and evidence workflows.
- Strong ability to translate regulatory requirements into actionable engineering controls and testable evidence.
- Preferred: CISA/CISSP, experience with NIST/HiTrust frameworks, and familiarity with Docker/Kubernetes and DevSecOps practices.
- Willingness to relocate to London; visa sponsorship and relocation support available.