FamilyWell Health Logo

FamilyWell Health

Security & Compliance Manager

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
132K-140K Annually
Mid level
Remote
Hiring Remotely in USA
132K-140K Annually
Mid level
Own the day-to-day security and compliance program for a HIPAA-regulated AI healthcare platform. Responsibilities include managing risk assessments, penetration-test remediation, vendor and BAA reviews, policies, device compliance, incident response, access-management initiatives, compliance automation, AI security guardrails, and board reporting. The role partners with the CPO, contractor CISO, IT administrator, and MSP while building readiness for SOC 2 or HITRUST certification.
The summary above was generated by AI

FamilyWell Health is an AI-enabled mental health startup dedicated to addressing the women’s mental health crisis by seamlessly embedding high-quality, equitable, and affordable mental health care into women’s health practices and health systems. Our comprehensive virtual care model delivers evidence-based mental health services across the full reproductive lifecycle, from fertility through menopause, using the proven Collaborative Care Model (CoCM).

Our AI-enabled platform integrates coaching, therapy, psychiatry, and care coordination services directly into clinical workflows, making mental health care accessible, affordable, and insurance-covered. With 95% of patients experiencing clinical improvement within four months, FamilyWell is addressing one of healthcare’s most underserved areas while building a financially sustainable model for provider partners.

Following our recent Series A raise, we are expanding nationally and seeking exceptional talent to join our mission-driven team. Learn more at www.familywellhealth.com.

FamilyWell is scaling a HIPAA-regulated, AI-enabled care platform, and our security program has outgrown what our CPO and contractor CISO can manage day-to-day. We're hiring a Security & Compliance Manager to own the operational backbone of our security and compliance program — running the security calendar, tracking risk assessment and pentest remediation to closure, managing vendor/BAA risk, and building toward a formal compliance certification (SOC2 or HITRUST, timing dependent on feasibility). You'll work closely with our CPO (Security Officer) and our contractor CISO, who will continue to own governance, sign-off, and board-level risk reporting, while you own the day-to-day execution that makes that reporting possible.

Key Responsibilities & Duties
  • Own day-to-day management of the security program: Security Risk Assessment (SRA) cadence, penetration test coordination and remediation tracking, phishing simulations, and the annual security awareness training calendar.
  • Draft Policies & Procedures (P&Ps) for CISO and leadership review/approval, and keep documentation current as the org and regulatory landscape evolve (e.g., the 2025 HIPAA Security Rule overhaul).
  • Lead vendor security assessments and Business Associate Agreement (BAA) audits across FamilyWell's vendor ecosystem.
  • Own MDM/BYOD device compliance monitoring, partnering with the IT Systems Administrator and our MSP on enrollment and endpoint security status.
  • Serve as day-to-day lead on incident/breach response, escalating to the CPO and contractor CISO per FamilyWell's response plan.
  • Support rollout of identity and access management improvements, including SSO and a company-wide password manager.
  • Partner with the CPO and contractor CISO to prepare recurring board-level risk and compliance status reporting, including a forward-looking roadmap.
  • Own compliance-automation tooling evaluation and rollout (e.g., Drata or Vanta) as FamilyWell works toward a SOC2 or HITRUST-ready posture.
  • Track open items from SRAs, audits, and vendor reviews to closure (e.g., encryption gaps, audit-log access, policy sign-off) using FamilyWell's Security Program Tracker.
  • Help define and maintain AI security guardrails (e.g., PHI handling policy for Claude/Cowork and other AI tools) as the platform and AI usage scale.
  • Maintain detailed documentation and records of all security program controls, risks, incidents, vendor audits, and roadmap initiatives.
Minimum Qualifications
  • 3–6+ years of experience in security compliance, IT security, or GRC (governance, risk, and compliance) roles.
  • Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor/BAA risk reviews — ideally in healthcare or another regulated industry.
  • Comfortable running a security calendar and tracking remediation items to closure across multiple stakeholders.
  • Experience partnering with a fractional or contractor CISO, MSP, or outside security advisor, and translating technical risk into clear, non-technical reporting for leadership or a board.
  • Strong documentation and project management habits.
  • Ability to work independently in a fast-paced, remote startup environment.
Nice-to-Haves
  • Direct experience preparing for or achieving SOC2 or HITRUST certification.
  • Familiarity with compliance automation platforms (Drata, Vanta, or similar).
  • Experience with MDM/endpoint tools, Google Workspace security controls (DLP, Vault), and password manager rollouts.
  • Experience in an early-stage or high-growth startup, comfortable building process from scratch.
  • Familiarity with AI governance/security considerations for tools used with PHI.

Compensation Range: $132,000-$140,000


Similar Jobs

One Month Ago
In-Office or Remote
134K-202K Annually
Senior level
134K-202K Annually
Senior level
Biotech • Pharmaceutical
Manages security governance, risk, compliance, and control programs for enterprise SaaS and PaaS platforms. Coordinates security initiatives, control frameworks, audits, assessments, exceptions, vendor risk reviews, and continuous monitoring. Partners with IT, security, compliance, business, IAM, data governance teams, and vendors to improve platform security, access controls, data protection, and compliance maturity. Reports risks, metrics, KRIs, and compliance status to leadership while supporting secure adoption across Workday, Salesforce, Snowflake, ServiceNow, and Microsoft 365.
Top Skills: AWSAzureGCPIamIso 27001Microsoft 365NistOwaspPaasSaaSSalesforceServicenowSnowflakeWorkday
4 Minutes Ago
Remote or Hybrid
United States
87K-100K Annually
Senior level
87K-100K Annually
Senior level
AdTech • Agency • Artificial Intelligence • Digital Media • Marketing Tech • Social Media • PropTech
Manage strategically complex client relationships and portfolios, owning retention, expansion, and cross-channel digital marketing strategy. Lead quarterly business presentations, deliver data-backed recommendations, coordinate internal teams, and act as a Fiona platform expert. Drive departmental initiatives, process improvements, product feedback, client onboarding, and mentorship for Account Managers and Coordinators. Success is measured through retention, client satisfaction, response times, reporting accuracy, expansion, revenue growth, and team development.
Top Skills: AIDisplay AdvertisingEmail MarketingFionaGeofencingNative AdvertisingOrganic SocialPaid SearchPaid SocialReputation ManagementSeo
5 Minutes Ago
Remote or Hybrid
United States
79K-89K Annually
Entry level
79K-89K Annually
Entry level
Cloud • Fintech • Information Technology • Machine Learning • Software
Support Xero’s partner sales channel by guiding accounting and bookkeeping practices through onboarding, data migration, software implementation, and activation. Deliver one-on-one and group training on Xero and related products, manage stakeholder expectations, schedule virtual and on-site sessions, maintain Salesforce records, and create self-service resources. The role requires frequent travel to partner practices and strong accounting, communication, presentation, and relationship-building skills.
Top Skills: Advance TrackCloud Accounting PlatformsGmtHubdocJet ConvertMelioSaaSSalesforce CRMSyftXeroXero Payroll

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account