Security & Compliance Manager
- Salary
- $132K–$140KUSD
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 23, 2026
FamilyWell Health is an AI-enabled mental health startup dedicated to addressing the women’s mental health crisis by seamlessly embedding high-quality, equitable, and affordable mental health care into women’s health practices and health systems. Our comprehensive virtual care model delivers evidence-based mental health services across the full reproductive lifecycle, from fertility through menopause, using the proven Collaborative Care Model (CoCM). Our AI-enabled platform integrates coaching, therapy, psychiatry, and care coordination services directly into clinical workflows, making mental health care accessible, affordable, and insurance-covered. With 95% of patients experiencing clinical improvement within four months, FamilyWell is addressing one of healthcare’s most underserved areas while building a financially sustainable model for provider partners. Following our recent Series A raise, we are expanding nationally and seeking exceptional talent to join our mission-driven team. Learn more at www.familywellhealth.com. FamilyWell is scaling a HIPAA-regulated, AI-enabled care platform, and our security program has outgrown what our CPO and contractor CISO can manage day-to-day. We're hiring a Security & Compliance Manager to own the operational backbone of our security and compliance program — running the security calendar, tracking risk assessment and pentest remediation to closure, managing vendor/BAA risk, and building toward a formal compliance certification (SOC2 or HITRUST, timing dependent on feasibility). You'll work closely with our CPO (Security Officer) and our contractor CISO, who will continue to own governance, sign-off, and board-level risk reporting, while you own the day-to-day execution that makes that reporting possible. Key Responsibilities & Duties Own day-to-day management of the security program: Security Risk Assessment (SRA) cadence, penetration test coordination and remediation tracking, phishing simulations, and the annual security awareness training calendar. Draft Policies & Procedures (P&Ps) for CISO and leadership review/approval, and keep documentation current as the org and regulatory landscape evolve (e.g., the 2025 HIPAA Security Rule overhaul). Lead vendor security assessments and Business Associate Agreement (BAA) audits across FamilyWell's vendor ecosystem. Own MDM/BYOD device compliance monitoring, partnering with the IT Systems Administrator and our MSP on enrollment and endpoint security status. Serve as day-to-day lead on incident/breach response, escalating to the CPO and contractor CISO per FamilyWell's response plan. Support rollout of identity and access management improvements, including SSO and a company-wide password manager. Partner with the CPO and contractor CISO to prepare recurring board-level risk and compliance status reporting, including a forward-looking roadmap. Own compliance-automation tooling evaluation and rollout (e.g., Drata or Vanta) as FamilyWell works toward a SOC2 or HITRUST-ready posture. Track open items from SRAs, audits, and vendor reviews to closure (e.g., encryption gaps, audit-log access, policy sign-off) using FamilyWell's Security Program Tracker. Help define and maintain AI security guardrails (e.g., PHI handling policy for Claude/Cowork and other AI tools) as the platform and AI usage scale. Maintain detailed documentation and records of all security program controls, risks, incidents, vendor audits, and roadmap initiatives. Minimum Qualifications 3–6+ years of experience in security compliance, IT security, or GRC (governance, risk, and compliance) roles. Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor/BAA risk reviews — ideally in healthcare or another regulated industry. Comfortable running a security calendar and tracking remediation items to closure across multiple stakeholders. Experience partnering with a fractional or contractor CISO, MSP, or outside security advisor, and translating technical risk into clear, non-technical reporting for leadership or a board. Strong documentation and project management habits. Ability to work independently in a fast-paced, remote startup environment. Nice-to-Haves Direct experience preparing for or achieving SOC2 or HITRUST certification. Familiarity with compliance automation platforms (Drata, Vanta, or similar). Experience with MDM/endpoint tools, Google Workspace security controls (DLP, Vault), and password manager rollouts. Experience in an early-stage or high-growth startup, comfortable building process from scratch. Familiarity with AI governance/security considerations for tools used with PHI. Compensation Range: $132,000-$140,000