FamilyWell Health Logo

FamilyWell Health

Security & Compliance Manager

Posted 13 Days Ago
Remote
Hiring Remotely in USA
132K-140K Annually
Mid level
Remote
Hiring Remotely in USA
132K-140K Annually
Mid level
Own the day-to-day security and compliance program for a HIPAA-regulated AI healthcare platform. Responsibilities include managing risk assessments, penetration-test remediation, vendor and BAA reviews, policies, device compliance, incident response, access-management initiatives, compliance automation, AI security guardrails, and board reporting. The role partners with the CPO, contractor CISO, IT administrator, and MSP while building readiness for SOC 2 or HITRUST certification.
The summary above was generated by AI

FamilyWell Health is an AI-enabled mental health startup dedicated to addressing the women’s mental health crisis by seamlessly embedding high-quality, equitable, and affordable mental health care into women’s health practices and health systems. Our comprehensive virtual care model delivers evidence-based mental health services across the full reproductive lifecycle, from fertility through menopause, using the proven Collaborative Care Model (CoCM).

Our AI-enabled platform integrates coaching, therapy, psychiatry, and care coordination services directly into clinical workflows, making mental health care accessible, affordable, and insurance-covered. With 95% of patients experiencing clinical improvement within four months, FamilyWell is addressing one of healthcare’s most underserved areas while building a financially sustainable model for provider partners.

Following our recent Series A raise, we are expanding nationally and seeking exceptional talent to join our mission-driven team. Learn more at www.familywellhealth.com.

FamilyWell is scaling a HIPAA-regulated, AI-enabled care platform, and our security program has outgrown what our CPO and contractor CISO can manage day-to-day. We're hiring a Security & Compliance Manager to own the operational backbone of our security and compliance program — running the security calendar, tracking risk assessment and pentest remediation to closure, managing vendor/BAA risk, and building toward a formal compliance certification (SOC2 or HITRUST, timing dependent on feasibility). You'll work closely with our CPO (Security Officer) and our contractor CISO, who will continue to own governance, sign-off, and board-level risk reporting, while you own the day-to-day execution that makes that reporting possible.

Key Responsibilities & Duties
  • Own day-to-day management of the security program: Security Risk Assessment (SRA) cadence, penetration test coordination and remediation tracking, phishing simulations, and the annual security awareness training calendar.
  • Draft Policies & Procedures (P&Ps) for CISO and leadership review/approval, and keep documentation current as the org and regulatory landscape evolve (e.g., the 2025 HIPAA Security Rule overhaul).
  • Lead vendor security assessments and Business Associate Agreement (BAA) audits across FamilyWell's vendor ecosystem.
  • Own MDM/BYOD device compliance monitoring, partnering with the IT Systems Administrator and our MSP on enrollment and endpoint security status.
  • Serve as day-to-day lead on incident/breach response, escalating to the CPO and contractor CISO per FamilyWell's response plan.
  • Support rollout of identity and access management improvements, including SSO and a company-wide password manager.
  • Partner with the CPO and contractor CISO to prepare recurring board-level risk and compliance status reporting, including a forward-looking roadmap.
  • Own compliance-automation tooling evaluation and rollout (e.g., Drata or Vanta) as FamilyWell works toward a SOC2 or HITRUST-ready posture.
  • Track open items from SRAs, audits, and vendor reviews to closure (e.g., encryption gaps, audit-log access, policy sign-off) using FamilyWell's Security Program Tracker.
  • Help define and maintain AI security guardrails (e.g., PHI handling policy for Claude/Cowork and other AI tools) as the platform and AI usage scale.
  • Maintain detailed documentation and records of all security program controls, risks, incidents, vendor audits, and roadmap initiatives.
Minimum Qualifications
  • 3–6+ years of experience in security compliance, IT security, or GRC (governance, risk, and compliance) roles.
  • Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor/BAA risk reviews — ideally in healthcare or another regulated industry.
  • Comfortable running a security calendar and tracking remediation items to closure across multiple stakeholders.
  • Experience partnering with a fractional or contractor CISO, MSP, or outside security advisor, and translating technical risk into clear, non-technical reporting for leadership or a board.
  • Strong documentation and project management habits.
  • Ability to work independently in a fast-paced, remote startup environment.
Nice-to-Haves
  • Direct experience preparing for or achieving SOC2 or HITRUST certification.
  • Familiarity with compliance automation platforms (Drata, Vanta, or similar).
  • Experience with MDM/endpoint tools, Google Workspace security controls (DLP, Vault), and password manager rollouts.
  • Experience in an early-stage or high-growth startup, comfortable building process from scratch.
  • Familiarity with AI governance/security considerations for tools used with PHI.

Compensation Range: $132,000-$140,000


Similar Jobs

An Hour Ago
In-Office or Remote
150K-190K Annually
Senior level
150K-190K Annually
Senior level
Healthtech
Lead Leap’s security and compliance program, including HITRUST certification, SOC 2 Type II audits, HIPAA controls, policy development, vendor risk reviews, security questionnaires, and client security engagements. Build a prioritized security roadmap, advise Engineering on GCP and data-stack controls, manage an external security partner, and report security posture and compliance risks to leadership.
Top Skills: DrataGCPHipaaHitrustIso 27001SecureframeSoc 2Vanta
One Month Ago
In-Office or Remote
134K-202K Annually
Senior level
134K-202K Annually
Senior level
Biotech • Pharmaceutical
Manages security governance, risk, compliance, and control programs for enterprise SaaS and PaaS platforms. Coordinates security initiatives, control frameworks, audits, assessments, exceptions, vendor risk reviews, and continuous monitoring. Partners with IT, security, compliance, business, IAM, data governance teams, and vendors to improve platform security, access controls, data protection, and compliance maturity. Reports risks, metrics, KRIs, and compliance status to leadership while supporting secure adoption across Workday, Salesforce, Snowflake, ServiceNow, and Microsoft 365.
Top Skills: AWSAzureGCPIamIso 27001Microsoft 365NistOwaspPaasSaaSSalesforceServicenowSnowflakeWorkday
33 Minutes Ago
Remote or Hybrid
US
200K-200K Annually
Expert/Leader
200K-200K Annually
Expert/Leader
Artificial Intelligence • Cloud • Payments • Software • Business Intelligence • Generative AI • Automation
Sell connectivity, data solutions, and AI-powered risk digitization software to insurance carriers and MGA clients across Canada. Responsibilities include developing strategic account plans, acquiring new logos, expanding existing accounts, managing executive relationships, negotiating renewals, forecasting sales, gathering market feedback, and meeting or exceeding quotas. The role uses a consultative solution-selling methodology and involves virtual, telephone, onsite, and industry-event engagements.
Top Skills: Ai-Powered Risk Digitization PlatformsCrm SystemsExcelMicrosoft OutlookMicrosoft PowerpointMicrosoft WordSalesforceSlack

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account