HIPAA Security Engineer
Flohealth · London
What this role requires
3 requirements, read out of the advert rather than guessed from the job title:
Also mentioned, not required: GRC platforms, Docker, Kubernetes, NIST, HiTrust, DevSecOps, English (B2). Worth having, but their absence is not what gets a CV filtered out.
See how often each of these is required across open security roles in Europe.
Free, no card. Tells you which of them your CV evidences and which it only implies.
Job description
500M+ downloads. 80M+ monthly users. A decade of building – and we’re still accelerating.
Flo is the world’s #1 health & fitness app worldwide on a mission to build a better future for female health. Backed by a $200M investment led by General Atlantic, we became the first product of our kind to reach a $1B valuation in 2024 – and we’re not slowing down.
With 7M paid subscribers and the highest-rated experience in the App Store’s health category, we’ve spent 10 years earning trust at scale. Now, we’re building the next generation of digital health – AI-powered, privacy-first, clinically backed – to help our users know their body better.
The job
We are seeking a HIPAA Security Engineer to join our team in London, UK . While this posting is open to candidates currently based in the United States, this position requires full-time relocation to London . We offer comprehensive visa sponsorship and a full relocation support package to ensure a smooth transition for the selected candidate.As a key member of Flo’s Security Architecture team, you will lead the design and operation of our US Healthcare security controls. You will own the roadmap for HIPAA compliance and SOC2 Type II certification , partnering with Engineering and Legal to build a secure, compliant platform for millions of users.
Read the full description (30 more sections)Show less
Key Responsibilities
Compliance Leadership: Lead annual SOC 2 and HIPAA certifications, managing interfaces with external auditors and professional services.
Policy & Risk: Define and maintain security policies; embed risk assessment activities within engineering processes and vendor management.
Operational Excellence: Partner with control owners to automate evidence gathering and ensure controls reduce friction rather than creating it.
Stakeholder Management: Serve as the primary Security POC for US regulators and partners; support the wider Security team with ISO 27001/27701 alignment.
Tooling: Manage and integrate GRC platforms to streamline compliance monitoring and reporting.
Qualifications
Experience: 7+ years in security/compliance (3+ in leadership), with a Bachelor’s degree in a related field.
Core Skills: Deep expertise in SOC 2 and HIPAA frameworks within a Cloud-based SaaS environment.
Technical Knowledge: Familiarity with PHI handling, GRC platforms, and compliance automation.
Soft Skills: Strong ability to translate complex compliance requirements into clear actions for engineering teams.
Preferred: CISA/CISSP certifications; experience with NIST, HiTrust, Docker/Kubernetes, and DevSecOps.
How we work
We’re a mission-led, product-driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.
You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience, and the drive to keep going when things get tough. Because better health outcomes are worth it.
What you'll get
We support impact with meaningful reward. Here’s what that looks like:
Competitive salary and annual reviews
Opportunity to participate in Flo’s performance incentive scheme
Paid holiday, sick leave, and female health leave
Enhanced parental leave and pay for maternity, paternity, same-sex and adoptive parents
Accelerated professional growth through world-changing work and learning support
In-person collaboration and work in a hybrid model, with 3 days per week spent in the office
5-week fully paid sabbatical at 5-year Floversary
Flo Premium for friends & family, plus more health, pension and wellbeing perks
Diversity, equity and inclusion
Our strength is in our differences. At Flo, hiring is based on merit, skill and what you bring to the role – nothing else. We’re proud to be an equal opportunity employer, and we welcome applicants from all backgrounds, communities and identities. Read our privacy notice for job applicants .
Find Jobs in United Kingdom on Arbeitnow
You will apply. Then you will hear nothing.
And no one will tell you what was wrong. See it before you send: your ATS score, every weak line, and the fix for each.
- 1
Drop in your CV
One PDF, thirty seconds. No card.
- 2
See what is wrong with it
Every weak passage, quoted from your own CV, with the line to replace it.
- 3
Apply where you fit
Every European role ranked against what your CV actually says.
What's actually stopping you?
- I apply and hear nothing backStart with the ATS scan — see what a filter does to your CV before a human sees it.Start here →
- I can't tell which roles I'd getStart with the match scores — every listing here ranked against what your CV actually says.Start here →
- Just browsing for nowKeep looking. Nothing to sign up for.
- Free, no card
- Your CV file is deleted after parsing
- Refreshed every 6 hours