
Security & Compliance Manager
FamilyWell Health & FamilyWell Academy
WorldwideFully remoteFull TimeMid LevelHealthcare & Telemedicine
USD 132,000–140,000 a yearPosted 4 hours ago4h agoApply link checked 4 hours ago
Why we think you can apply
- Hiring model
- Open worldwide · the employer states no country restriction
- Work from
- Anywhere, the UAE included
Posted 4 hours ago · apply link checked 4 hours ago
About the role
Responsibilities
- Own day-to-day management of the security program: Security Risk Assessment (SRA) cadence, penetration test coordination and remediation tracking, phishing simulations, and the annual security awareness training calendar.
- Draft Policies & Procedures (P&Ps) for CISO and leadership review/approval.
- Lead vendor security assessments and Business Associate Agreement (BAA) audits.
- Own MDM/BYOD device compliance monitoring.
- Serve as day-to-day lead on incident/breach response.
- Support rollout of identity and access management improvements.
- Partner with the CPO and contractor CISO to prepare recurring board-level risk and compliance status reporting.
- Own compliance-automation tooling evaluation and rollout (e.g., Drata or Vanta).
- Track open items from SRAs, audits, and vendor reviews to closure.
- Help define and maintain AI security guardrails.
- Maintain detailed documentation and records of all security program controls, risks, incidents, vendor audits, and roadmap initiatives.
Requirements
- 3–6+ years of experience in security compliance, IT security, or GRC (governance, risk, and compliance) roles.
- Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor/BAA risk reviews.
- Comfortable running a security calendar and tracking remediation items to closure across multiple stakeholders.
- Experience partnering with a fractional or contractor CISO, MSP, or outside security advisor.
- Strong documentation and project management habits.
- Ability to work independently in a fast-fast paced, remote startup environment.
Preferred Qualifications
- Direct experience preparing for or achieving SOC2 or HITRUST certification.
- Familiarity with compliance automation platforms (Drata, Vanta, or similar).
- Experience with MDM/endpoint tools, Google Workspace security controls (DLP, Vault), and password manager rollouts.
- Experience in an early-stage or high-growth startup.
- Familiarity with AI governance/security considerations for tools used with PHI.
About the Company
FamilyWell Health is an AI-enabled mental health startup dedicated to addressing the women's mental health crisis by seamlessly embedding high-quality, equitable, and affordable mental health care into women's health practices and health systems.
What we look for
- 3–6+ years of experience in security compliance, IT security, or GRC
- Direct experience with HIPAA Security Rule requirements
- Experience with Security Risk Assessments and vendor/BAA risk reviews
- Strong documentation and project management habits
- Ability to work independently in a fast-paced, remote startup environment
ComplianceHIPAASOC2HITRUST
SponsorWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matchesSimilar jobsbased on title, category and scope

FamilyWell Health & FamilyWell Academy
SponsorWake up to a shortlist, not a search results page.
NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.
Get your daily matchesSecurity & Compliance ManagerFamilyWell Health & FamilyWell Academy · free account, 30 seconds