SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Heidi Health is building AI-powered clinical tools that handle administrative documentation for clinicians across 190+ countries, processing over 2.5 million patient sessions weekly. This Technical Program Manager role sits at the intersection of regulatory compliance, security architecture, and product development—a central platform function that enables Heidi to operate safely within clinical environments and handle sensitive patient data.
You will own the regulatory and security roadmap across multiple markets (FDA, TGA, MHRA, and emerging regions), translating complex medical device regulations into actionable product requirements. The role requires deep fluency with FDA SaMD classification, 510(k)/De Novo pathways, TGA registration, ISO 13485 quality management, ISO 14971 risk frameworks, IEC 62304 software lifecycle standards, SOC 2 Type II, HIPAA, and GDPR. You'll work directly with legal, engineering, clinical, and commercial teams to clear the path for enterprise deployments while balancing regulatory risk, engineering cost, and commercial urgency.
Key responsibilities include: prioritizing which certifications and regulatory clearances to pursue and in what order; unpacking regulatory roadmaps with the legal team; acting as the liaison between customers and internal teams on safety, security, and compliance matters; translating standards into engineering specifications; driving security architecture (data handling, access controls, encryption, audit logging, penetration testing); and building scalable compliance infrastructure rather than one-off audit responses.
You'll need a BA/BS in a technical or analytical field and 4+ years in product, regulatory, or technical roles. Critical requirements include real fluency with medical device regulation (not optional), experience building scalable compliance programs, diagnostic security expertise to triage customer questionnaires, and fluency with LLM concepts and their regulatory implications (model drift, output validation, intended use boundaries). You should be comfortable with build-vs-document trade-offs, hold coherent regulatory roadmaps under pressure, and have strong opinions weakly held. Experience with AI development tools (Cursor, Claude Code) and demonstrable work using them is valued.