Назад
Company hidden
обновлено 5 дней назад

HIPAA Security Engineer (Healthcare)

100 000 - 130 000GBP
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
HIPAA Security Engineer (Healthcare/AWS): Designing and operating HIPAA and SOC 2 security controls across Flo's AWS environment with an accent on compliance leadership, PHI protection, and technical control design. Focus on leading audits, hardening EKS, Lambda, RDS, S3, IAM, and KMS workloads, and automating evidence collection for a compliant digital health platform.

Location: London; hybrid work with 3 days per week in the office

Annual salary: £100,000–£130,000 GBP

Company

hirify.global develops a privacy-first, clinically backed digital health and female health platform used by millions of people worldwide.

What you will do

  • Lead annual SOC 2 and HIPAA certifications, coordinating external auditors and professional services partners.
  • Design and review technical security controls for AWS workloads, including EKS, EC2, data pipelines, Lambda, RDS, S3, VPC networking, IAM, and KMS.
  • Perform architectural risk assessments for services that handle protected health information.
  • Define security policies and standards and integrate risk assessments into engineering processes.
  • Support vendor risk management through contract reviews and security posture assessments.
  • Automate evidence collection and manage GRC and compliance automation platforms.

Requirements

  • 7+ years of experience in security, compliance, or risk management, including 3+ years in a leadership capacity.
  • Bachelor’s degree in a related field or equivalent experience.
  • Deep expertise in SOC 2 and HIPAA frameworks in AWS environments.
  • Experience with PHI handling, GRC and compliance automation platforms, and multiple concurrent audit workstreams.
  • Strong written and verbal communication skills, with the ability to translate compliance requirements into engineering and business actions.
  • Availability for hybrid work in London, including 3 days per week in the office.

Nice to have

  • CISA, CISM, or CISSP certification.
  • Experience with NIST 800-53, CSA, CIS, HITRUST, or other regulated-industry frameworks.
  • Experience with Docker, Kubernetes, serverless, big data platforms, DevSecOps, Agile development, or vendor management.
  • Experience building compliance roadmaps in early-stage startups.

Culture & Benefits

  • Mission-led, product-driven environment focused on ownership, collaboration, and purposeful delivery.
  • Competitive salary with annual reviews and participation in a performance incentive scheme.
  • Paid holiday, sick leave, female health leave, and enhanced parental leave and pay.
  • Professional growth through challenging work and learning support.
  • Five-week fully paid sabbatical after five years, plus Flo Premium, health, pension, and wellbeing benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →