Hiring.Camp

Security & Compliance Manager

Familywell

·

Today

Salary
$132k – $140k
Location
Remote · Remote, United States
Workplace
Remote
Department
Product & Technology
Seniority
Manager
Experience
3+ years
Source
Greenhouse

Description

FamilyWell Health is an AI-enabled mental health startup dedicated to addressing the women’s mental health crisis by seamlessly embedding high-quality, equitable, and affordable mental health care into women’s health practices and health systems. Our comprehensive virtual care model delivers evidence-based mental health services across the full reproductive lifecycle, from fertility through menopause, using the proven Collaborative Care Model (CoCM).

Our AI-enabled platform integrates coaching, therapy, psychiatry, and care coordination services directly into clinical workflows, making mental health care accessible, affordable, and insurance-covered. With 95% of patients experiencing clinical improvement within four months, FamilyWell is addressing one of healthcare’s most underserved areas while building a financially sustainable model for provider partners.

Following our recent Series A raise, we are expanding nationally and seeking exceptional talent to join our mission-driven team. Learn more at www.familywellhealth.com.

FamilyWell is scaling a HIPAA-regulated, AI-enabled care platform, and our security program has outgrown what our CPO and contractor CISO can manage day-to-day. We're hiring a Security & Compliance Manager to own the operational backbone of our security and compliance program — running the security calendar, tracking risk assessment and pentest remediation to closure, managing vendor/BAA risk, and building toward a formal compliance certification (SOC2 or HITRUST, timing dependent on feasibility). You'll work closely with our CPO (Security Officer) and our contractor CISO, who will continue to own governance, sign-off, and board-level risk reporting, while you own the day-to-day execution that makes that reporting possible.

Key Responsibilities & Duties

  • Own day-to-day management of the security program: Security Risk Assessment (SRA) cadence, penetration test coordination and remediation tracking, phishing simulations, and the annual security awareness training calendar.
  • Draft Policies & Procedures (P&Ps) for CISO and leadership review/approval, and keep documentation current as the org and regulatory landscape evolve (e.g., the 2025 HIPAA Security Rule overhaul).
  • Lead vendor security assessments and Business Associate Agreement (BAA) audits across FamilyWell's vendor ecosystem.
  • Own MDM/BYOD device compliance monitoring, partnering with the IT Systems Administrator and our MSP on enrollment and endpoint security status.
  • Serve as day-to-day lead on incident/breach response, escalating to the CPO and contractor CISO per FamilyWell's response plan.
  • Support rollout of identity and access management improvements, including SSO and a company-wide password manager.
  • Partner with the CPO and contractor CISO to prepare recurring board-level risk and compliance status reporting, including a forward-looking roadmap.
  • Own compliance-automation tooling evaluation and rollout (e.g., Drata or Vanta) as FamilyWell works toward a SOC2 or HITRUST-ready posture.
  • Track open items from SRAs, audits, and vendor reviews to closure (e.g., encryption gaps, audit-log access, policy sign-off) using FamilyWell's Security Program Tracker.
  • Help define and maintain AI security guardrails (e.g., PHI handling policy for Claude/Cowork and other AI tools) as the platform and AI usage scale.
  • Maintain detailed documentation and records of all security program controls, risks, incidents, vendor audits, and roadmap initiatives.

Minimum Qualifications

  • 3–6+ years of experience in security compliance, IT security, or GRC (governance, risk, and compliance) roles.
  • Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor/BAA risk reviews — ideally in healthcare or another regulated industry.
  • Comfortable running a security calendar and tracking remediation items to closure across multiple stakeholders.
  • Experience partnering with a fractional or contractor CISO, MSP, or outside security advisor, and translating technical risk into clear, non-technical reporting for leadership or a board.
  • Strong documentation and project management habits.
  • Ability to work independently in a fast-paced, remote startup environment.

Nice-to-Haves

  • Direct experience preparing for or achieving SOC2 or HITRUST certification.
  • Familiarity with compliance automation platforms (Drata, Vanta, or similar).
  • Experience with MDM/endpoint tools, Google Workspace security controls (DLP, Vault), and password manager rollouts.
  • Experience in an early-stage or high-growth startup, comfortable building process from scratch.
  • Familiarity with AI governance/security considerations for tools used with PHI.

Compensation Range: $132,000-$140,000

 

Skills

ComplianceProject ManagementHIPAA

Similar Jobs

30

Head - Payments Security Compliance, Security & Privacy Regulatory Enablement (SPRe)

Amazon·Remote

Today

Information Security & Compliance Engineer

OfficeRnD·Sofia, Hybrid·Hybrid

1d ago

Security & Compliance Analyst Manager

Eastern Bank·Brockton, MA·Hybrid

1d ago

Microsoft Security, Compliance & Identity Architect Senior Consultant

Roberthalf·HOUSTON, US +1

2d ago

Software Development Engineer, AWS Artifact, AWS Compliance & Security Assurance

Amazon·Remote

2d ago

Director, Security Compliance and Trust

Gomotive·United States - Remote·Remote

2d ago

Security Compliance Analyst

GDIT·USA DC Home Office, US·Remote

6d ago

Security Compliance Specialist

Adobe·Melbourne, Australia +1

6d ago

Security & Compliance Administrator

SOSi·Remote, US·Remote

6d ago

Microsoft Security, Compliance & Identity Architect Manager 

Roberthalf·HOUSTON, US +1

1w ago

Microsoft Security, Compliance & Identity Architect Associate Director

Roberthalf·SEATTLE, US

1w ago

Application Security Compliance Lead

Ncratleos·Gurgaon Office, India +1

1w ago

Security Compliance Analyst

Comscore·IND - Pune, India

1w ago

Information Security Compliance Analyst

Vestwell·New York, NY +1·Hybrid, Onsite

1w ago

Security/Compliance SME (REMOTE)

Koniag Government Services·Remote

1w ago

Senior Application Engineer (Compliance Security BSA/OFAC)

Navy Federal Financial Group·Vienna, VA·Hybrid

1w ago

Senior Security Compliance Analyst

Netbrain·Burlington, MA +1·Hybrid

1w ago

Supervisor, Security Compliance

Greater Orlando Aviation Authority·Orlando, FL

1w ago

IT Networking & Information Security Compliance Administrator

"Eagle Creek Renewable Energy, LLC"·Badin, NC·Remote, Hybrid

2w ago

Assistant Director of Airport Security: Compliance and Enforcement - Denver International Airport

Denver means seeing yourself working·DEN CONA East Lvl 04, US

2w ago

Senior Director, Security & Compliance

Prompt·Remote·Remote

2w ago

Director of IT, Information Security & Compliance

Sciens Logistics·Dallas, TX·Onsite

2w ago

Tech Governance - Security Compliance & Governance Engineer (Mandarin Bilingual Required)

Okx·San Jose, California

2w ago

Cyber Security & Compliance Manager

Rivell·Sewell, New Jersey

2w ago

Business Security Compliance Officer

Securitas·Luton, England

2w ago

Federal Compliance & Security Architect

Salesforce·Virginia - Washington DC Metro - Remote, US +10·Onsite, Remote

2w ago

Senior Security Compliance Analyst

Taskus·IND - Mohali - Oorja, India

2w ago

Senior Security Compliance Engineer, Public Sector

Gitlab·Remote, US·Remote

2w ago

Information Security Compliance Analyst

ImageTrend·Eagan, MN·Remote

2w ago

Jr Engineer - Product Security Compliance

Elo Touch Solutions·Milpitas, CA

2w ago