At a Glance
- Tasks: Lead HIPAA compliance and SOC 2 certifications while ensuring security for millions of users.
- Company: Join Flo, the world’s #1 health & fitness app with a mission for female health.
- Benefits: Competitive salary, performance incentives, generous leave policies, and a 5-week sabbatical.
- Other info: Dynamic team culture focused on ownership, collaboration, and professional growth.
- Why this job: Make a real impact in digital health while working with cutting-edge technology.
- Qualifications: 7+ years in security/compliance, with deep expertise in SOC 2 and HIPAA frameworks.
Flo is the world’s #1 health & fitness app on a mission to build a better future for female health. We are seeking a HIPAA Security Engineer to join our team in London, UK. This position requires full-time relocation to London, and we offer comprehensive visa sponsorship and a full relocation support package.
As a key member of Flo’s Security Architecture team, you will lead the design and operation of our US Healthcare security controls. You will own the roadmap for HIPAA compliance and SOC2 Type II certification, partnering with Engineering and Legal to build a secure, compliant platform for millions of users.
Key Responsibilities
- Compliance Leadership: Lead annual SOC 2 and HIPAA certifications, managing interfaces with external auditors and professional services.
- Policy & Risk: Define and maintain security policies; embed risk assessment activities within engineering processes and vendor management.
- Operational Excellence: Partner with control owners to automate evidence gathering and ensure controls reduce friction rather than creating it.
- Stakeholder Management: Serve as the primary Security POC for US regulators and partners; support the wider Security team with ISO 27001/27701 alignment.
- Tooling: Manage and integrate GRC platforms to streamline compliance monitoring and reporting.
Qualifications
- Experience: 7+ years in security/compliance (3+ in leadership), with a Bachelor’s degree in a related field.
- Core Skills: Deep expertise in SOC 2 and HIPAA frameworks within a Cloud-based SaaS environment.
- Technical Knowledge: Familiarity with PHI handling, GRC platforms, and compliance automation.
- Soft Skills: Strong ability to translate complex compliance requirements into clear actions for engineering teams.
- Preferred: CISA/CISSP certifications; experience with NIST, HiTrust, Docker/Kubernetes, and DevSecOps.
How we work
We’re a mission-led, product-driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.
What you’ll get
- Competitive salary and annual reviews
- Opportunity to participate in Flo’s performance incentive scheme
- Paid holiday, sick leave, and female health leave
- Enhanced parental leave and pay for maternity, paternity, same-sex and adoptive parents
- Accelerated professional growth through world-changing work and learning support
- In-person collaboration and work in a hybrid model, with 3 days per week spent in the office
- 5-week fully paid sabbatical at 5-year Floversary
- Flo Premium for friends & family, plus more health, pension and wellbeing perks
Diversity, equity and inclusion
Our strength is in our differences. At Flo, hiring is based on merit, skill and what you bring to the role – nothing else. We’re proud to be an equal opportunity employer, and we welcome applicants from all backgrounds, communities and identities.
HIPAA Security Engineer employer: FLO
At Flo, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. With a focus on employee growth, we provide ample opportunities for professional development and advancement in the rapidly evolving field of data science. Located in a vibrant tech hub, our team enjoys a supportive environment that values creativity and encourages meaningful contributions to our mission of improving health for millions worldwide.
StudySmarter Expert Advice🤫
We think this is how you could land HIPAA Security Engineer
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including FLO, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through FLO
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at FLO. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace HIPAA Security Engineer
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at FLO insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to FLO that you’re committed to staying ahead in the game.
How to prepare for a job interview at FLO
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at FLO to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at FLO.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.