Location
London
Hours
Full Time
Salary
Negotiable
About the Role
Flo Health is the world’s #1 health & fitness app worldwide, with over 500 million downloads and 80 million monthly users. Backed by a $200M investment and recently achieving a $1B valuation, Flo is on a mission to build the next generation of digital health—AI-powered, privacy-first, and clinically backed—to help users better understand their bodies. As a key member of Flo’s Security Architecture team, you will lead the design and operation of US Healthcare security controls. You will collaborate directly with Product and Engineering teams to translate HIPAA and SOC 2 requirements into technical security controls across Flo's AWS multi-account environment, including EKS, Lambda, RDS, S3, VPC networking, IAM, and KMS. You will own the roadmap for HIPAA compliance and SOC 2 Type II certification, working closely with external auditors, professional services partners, and internal teams to build a secure, compliant platform for millions of users.
What you'll be doing
- Lead annual SOC 2 and HIPAA certifications, managing relationships with external auditors and professional services
- Partner with Engineering to harden AWS workloads (EKS, EC2, data pipelines, etc.) to meet HIPAA and SOC 2 controls
- Perform technical security design reviews and architectural risk assessments for services handling PHI
- Define and maintain security policies and standards, embed risk assessment activities within engineering processes, and evolve Flo's security risk management framework
- Support vendor risk management including contract reviews and security posture assessments
- Collaborate with control owners to automate evidence gathering and ensure controls reduce friction
- Serve as the primary Security point of contact for US regulators and partners; support ISO 27001/27701 alignment
- Manage and integrate GRC and compliance automation platforms to streamline monitoring and reporting
How we work
We are a mission-led, product-driven team that moves fast, stays focused, and takes ownership from concept to impact. We encourage debate, share decisions, and care deeply about craftsmanship. Our culture values commitment, resilience, and the drive to improve health outcomes for millions.
What you'll get
Competitive salary with annual reviews
Opportunity to participate in Flo’s performance incentive scheme
Paid holiday, sick leave, and female health leave
Enhanced parental leave and pay for maternity, paternity, same-sex, and adoptive parents
Accelerated professional growth through impactful work and learning support
Hybrid working model with 3 days per week in the office
5-week fully paid sabbatical at 5-year anniversary
Flo Premium for friends & family plus additional health, pension, and wellbeing perks
Diversity, equity and inclusion
Flo values diversity and is proud to be an equal opportunity employer. Hiring is based on merit, skill, and what you bring to the role. We welcome applicants from all backgrounds, communities, and identities.
Experience
- 7+ years in security, compliance, or risk management, including 3+ years in leadership roles
- Deep expertise in SOC 2 and HIPAA frameworks within AWS environments
- Familiarity with PHI handling, GRC and compliance automation platforms
- Exposure to enterprise architecture frameworks such as TOGAF
- Strong ability to manage multiple concurrent audit and certification workstreams
- Excellent written and verbal communication skills, able to translate complex compliance requirements into clear actions
About you
- Proven leadership in compliance and security within regulated environments
- Comfortable working cross-functionally with Engineering, Legal, and external partners
- Detail-oriented with strong organizational and stakeholder management skills
- Adaptable and proactive in a fast-paced, mission-driven startup environment
Qualifications
- Bachelor’s degree in a related field or equivalent experience
- Nice to have: CISA, CISM, or CISSP certifications
- Experience with NIST 800-53, Cloud Security Alliance (CSA), and Center for Internet Security (CIS) frameworks
- Experience in healthcare or other regulated industries; HITRUST experience is a plus
- Exposure to containerization (Docker/Kubernetes), serverless, big data platforms, DevSecOps, and Agile development
- Vendor management experience
Flo Health










