×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

HIPAA Lead Security Specialist

Remote / Online - Candidates ideally in
New York, New York County, New York, 10261, USA
Listing for: School of UX
Contract, Remote/Work from Home position
Listed on 2026-01-14
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below
Position: HIPAA Lead Security Specialist (12 months contract) New New York
Location: New York

HIPAA Lead Security Specialist (12 months contract)

New York

500M+ downloads. 77M+ monthly users. A decade of building – and we’re still accelerating.

Flo is the world’s #1 health & fitness app worldwide on a mission to build a better future for female health. Backed by a $200M investment led by General Atlantic, we became the first product of our kind to reach a $1B valuation in 2024 – and we’re not slowing down.

With 6M paid subscribers and the highest‑rated experience in the App Store’s health category, we’ve spent 10 years earning trust , we’re building the next generation of digital health – AI‑powered, privacy‑first, clinically backed – to help our users know their body better.

The job

As a key member of Flo’s Security Architecture team, you will lead the design and operation of our US Healthcare security controls. You will own the roadmap for HIPAA compliance and SOC2 Type II certification
, partnering with Engineering and Legal to build a secure, compliant platform for millions of users.

Key Responsibilities
  • Compliance Leadership: Lead annual SOC 2 and HIPAA certifications, managing interfaces with external auditors and professional services.
  • Policy & Risk: Define and maintain security policies; embed risk assessment activities within engineering processes and vendor management.
  • Operational Excellence: Partner with control owners to automate evidence gathering and ensure controls reduce friction rather than creating it.
  • Stakeholder Management: Serve as the primary Security POC for US regulators and partners; support the wider Security team with ISO 27001/27701 alignment.
  • Tooling: Manage and integrate GRC platforms to streamline compliance monitoring and reporting.
Qualifications
  • Experience: 7+ years in security/compliance (3+ in leadership), with a Bachelor’s degree in a related field.
  • Core

    Skills:

    Deep expertise in SOC 2 and HIPAA frameworks within a Cloud‑based SaaS environment.
  • Technical Knowledge: Familiarity with PHI handling, GRC platforms, and compliance automation.
  • Soft Skills: Strong ability to translate complex compliance requirements into clear actions for engineering teams.
  • Preferred: CISA/CISSP certifications; experience with NIST, HiTrust, Docker/Kubernetes, and Dev Sec Ops .

This is a 12‑month contract, therefore not all listed benefits will be applicable.

How we work

We’re a mission‑led, product‑driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.

You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience, and the drive to keep going when things get tough. Because better health outcomes are worth it.

What you’ll get

We support impact with meaningful reward. Here’s what that looks like:

  • Competitive salary and annual reviews
  • Opportunity to participate in Flo’s performance incentive scheme
  • Paid holiday, sick leave, and female health leave
  • Enhanced parental leave and pay for maternity, paternity, same‑sex and adoptive parents
  • Accelerated professional growth through world‑changing work and learning support
  • Flexible office + home working, up to 2 months a year working abroad
  • 5‑week fully paid sabbatical at 5‑year Floversary
  • Flo Premium for friends & family, plus more health, pension and wellbeing perks
Diversity, equity and inclusion

Our strength is in our differences. At Flo, hiring is based on merit, skill and what you bring to the role – nothing else. We’re proud to be an equal‑opportunity employer, and we welcome applicants from all backgrounds, communities and identities. Read our privacy notice for job applicants.

Voluntary Self‑Identification

We ask candidates to respond to the below self‑identification survey. Completion is voluntary and will not be considered in the hiring process.

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary