SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Phylo is an applied research lab building agentic intelligence to accelerate biomedical discovery, spun out of Stanford's Biomni project. The company is backed by a $13.5M seed round led by a16z, Menlo Ventures, and Anthropic, bringing together researchers, engineers, and scientists across AI and biology.
You will own Phylo's security, privacy, and compliance program from the ground up. This is a hands-on role where you'll build and scale the entire security and compliance roadmap for an early-stage, high-impact company.
Key responsibilities include:
- Owning the security and compliance roadmap and driving execution
- Leading SOC 2, ISO 27001, and GDPR readiness initiatives, including audits, evidence collection, and remediation
- Building HIPAA-ready processes for workloads involving protected health information
- Assessing and planning for FedRAMP, NIST, privacy, and life-sciences regulatory requirements
- Partnering closely with engineering teams to implement scalable security controls across cloud infrastructure, applications, and AI systems
- Leading customer security questionnaires, RFPs, due diligence reviews, and security conversations
- Running risk assessments and driving remediation across systems, vendors, and processes
- Maintaining lightweight policies, customer-facing security documentation, and compliance reporting
- Automating evidence collection, monitoring, and compliance workflows
You bring 5+ years of experience in security GRC, compliance, or security engineering roles. You have hands-on experience leading SOC 2, ISO 27001, HIPAA, FedRAMP, or similar compliance programs. You understand cloud and application security deeply and can translate regulatory requirements into practical technical controls. You've supported enterprise audits and customer security reviews, and you communicate effectively across functions.
Ideal candidates have experience building security programs from early stage, background in healthcare or life sciences, familiarity with HIPAA/FedRAMP/NIST/HITRUST/GDPR, knowledge of AI governance frameworks (NIST AI RMF, ISO 42001), and experience automating GRC workflows.
You'll shape the security foundation for technology designed to accelerate biomedical discovery, working alongside exceptional researchers and engineers while influencing product and infrastructure decisions.