
About Flo Health
Empowering women's health with AI-driven insights
Key Highlights
- Over 70 million monthly users worldwide
- Most downloaded female health app globally
- $276.4 million raised in Series B funding
- Headquartered in London, UK with 501-1000 employees
Flo is an AI-powered period tracking app headquartered in St Katharine's & Wapping, London, UK, with over 70 million monthly users globally. The app provides personalized health insights by allowing users to log symptoms and cycle dates, making it the most downloaded female health app worldwide. Flo...
🎁 Benefits
Flo offers 6 months of fully paid maternity leave and 1 month of fully paid paternity leave, along with a $5000 bonus upon return. Employees enjoy 25 ...
🌟 Culture
Flo fosters a culture of innovation and user-centric design, leveraging AI to enhance the health tracking experience. The company prioritizes flexibil...
Skills & Technologies
Overview
Flo Health is seeking a Lead Security Specialist to oversee HIPAA compliance and SOC 2 certification. You'll collaborate with Engineering and Legal to ensure a secure platform for millions of users. This role requires expertise in security policies and risk management.
Job Description
Who you are
You have extensive experience in security compliance, particularly with HIPAA and SOC 2 certifications — you've successfully led compliance initiatives and managed relationships with external auditors. Your background includes defining and maintaining security policies, ensuring they align with engineering processes and vendor management. You understand the importance of operational excellence and have a track record of automating evidence gathering to streamline compliance efforts. You are a strong communicator and can effectively serve as the primary point of contact for US regulators and partners, ensuring that security practices meet regulatory requirements. Your experience with ISO 27001 and 27701 alignment is a plus, as you work to integrate these standards into the security framework. You are committed to fostering a culture of security awareness within the organization and are passionate about building a secure, compliant platform for users.
What you'll do
In this role, you will lead the design and operation of security controls specifically tailored for the US healthcare sector. You will own the roadmap for HIPAA compliance and SOC 2 Type II certification, working closely with cross-functional teams to ensure that security measures are effectively implemented. You will define and maintain security policies, embedding risk assessment activities within engineering processes and vendor management to mitigate potential risks. Your responsibilities will include managing interfaces with external auditors and professional services to facilitate annual SOC 2 and HIPAA certifications. You will partner with control owners to automate evidence gathering, ensuring that security controls reduce friction rather than create it. As the primary Security point of contact for US regulators and partners, you will support the wider Security team in aligning with ISO 27001 and 27701 standards. Your role will be crucial in shaping the security architecture of Flo Health as it continues to innovate in the digital health space.
What we offer
Flo Health offers a dynamic work environment where you can make a significant impact on the future of female health. We provide a competitive salary and benefits package, including health, pension, and wellbeing perks. Our commitment to diversity, equity, and inclusion means that we value the unique perspectives and experiences of all our employees. Join us in our mission to build a better future for female health and be part of a team that is dedicated to innovation and excellence.
Interested in this role?
Apply now or save it for later. Get alerts for similar jobs at Flo Health.
Similar Jobs You Might Like
Based on your interests and this role

Compliance Manager
Flo Health is seeking a HIPAA Lead Security Specialist to lead the design and operation of healthcare security controls. You'll manage HIPAA compliance and SOC 2 Type II certification while collaborating with Engineering and Legal teams. This role requires expertise in HIPAA and risk management.

Application Security Lead
Wayve is hiring an Application Security Lead to define and lead their application security program. You'll be responsible for building security measures to protect their advanced AI technology. This role requires strong leadership and expertise in application security.

Security Engineer
Teya is seeking a Security Engineering Lead to build and lead a security engineering team in a high-velocity fintech environment. You'll partner closely with engineering teams to embed security into the software delivery lifecycle. This role requires strong leadership and security engineering expertise.

Security Engineer
Anyscale is hiring a Lead Security Engineer to architect and build secure products for mission-critical applications. You'll collaborate with product and engineering teams to establish security best practices. This role requires expertise in security protocols and practices.

Security Engineer
HubSpot is hiring a Lead Security Analyst to oversee and enhance their global physical security program. You'll manage physical security systems and coordinate with various teams to ensure safety and efficiency. This role requires strong technical skills in security systems administration.