SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 132,000 - 140,000 / annual
FamilyWell Health is an AI-enabled mental health startup addressing the women's mental health crisis by embedding high-quality, equitable, and affordable mental health care into women's health practices and health systems. The company delivers evidence-based mental health services across the full reproductive lifecycle using the Collaborative Care Model (CoCM), with 95% of patients experiencing clinical improvement within four months.
FamilyWell is scaling a HIPAA-regulated, AI-enabled care platform and seeking a Security & Compliance Manager to own the operational backbone of the security and compliance program. You will report to the Chief Privacy Officer (CPO) and work closely with a contractor CISO, who will continue to own governance, sign-off, and board-level risk reporting. You will own day-to-day execution including security calendar management, risk assessment and penetration test remediation tracking, vendor/BAA risk management, and building toward formal compliance certification (SOC2 or HITRUST).
Key responsibilities include:
- Own day-to-day management of the security program: Security Risk Assessment (SRA) cadence, penetration test coordination and remediation tracking, phishing simulations, and annual security awareness training calendar
- Draft Policies & Procedures (P&Ps) for CISO and leadership review/approval, keeping documentation current as the organization and regulatory landscape evolve
- Lead vendor security assessments and Business Associate Agreement (BAA) audits across FamilyWell's vendor ecosystem
- Own MDM/BYOD device compliance monitoring, partnering with IT Systems Administrator and MSP on enrollment and endpoint security status
- Serve as day-to-day lead on incident/breach response, escalating to CPO and contractor CISO per response plan
- Support rollout of identity and access management improvements, including SSO and company-wide password manager
- Partner with CPO and contractor CISO to prepare recurring board-level risk and compliance status reporting with forward-looking roadmap
- Own compliance-automation tooling evaluation and rollout (e.g., Drata or Vanta) as FamilyWell works toward SOC2 or HITRUST-ready posture
- Track open items from SRAs, audits, and vendor reviews to closure using FamilyWell's Security Program Tracker
- Help define and maintain AI security guardrails (e.g., PHI handling policy for Claude/Cowork and other AI tools) as platform and AI usage scale
- Maintain detailed documentation and records of all security program controls, risks, incidents, vendor audits, and roadmap initiatives
Requirements:
- 3–6+ years of experience in security compliance, IT security, or GRC (governance, risk, and compliance) roles
- Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor/BAA risk reviews — ideally in healthcare or another regulated industry
- Comfortable running a security calendar and tracking remediation items to closure across multiple stakeholders
- Experience partnering with a fractional or contractor CISO, MSP, or outside security advisor, and translating technical risk into clear, non-technical reporting for leadership or a board
- Strong documentation and project management habits
- Ability to work independently in a fast-paced, remote startup environment
Nice-to-haves:
- Direct experience preparing for or achieving SOC2 or HITRUST certification
- Familiarity with compliance automation platforms (Drata, Vanta, or similar)
- Experience with MDM/endpoint tools, Google Workspace security controls (DLP, Vault), and password manager rollouts
- Experience in an early-stage or high-growth startup, comfortable building process from scratch
- Familiarity with AI governance/security considerations for tools used with PHI