Information Security Compliance Manager
Confidential
Posted: January 30, 2026
Interested in this position?
Create a free account to apply with AI-powered matching
Required Skills
Job Description
💡 We’re looking for an Information Security Compliance Manager (ISO 27001 / GDPR / HIPAA) with 3-5 years of experience to take ownership of our certified ISO/IEC 27001 ISMS and our privacy program in a health-data SaaS environment. You will maintain and continuously improve our ISO 27001 system (supported by Vanta), lead internal and external (surveillance) audits, and evolve our GDPR setup to also cover HIPAA expectations and special categories of data in close partnership with Engineering and Tech.
Why Flinn?
• We are building a truly exceptional culture: While many companies claim to have a great culture, we invite you to discover what truly sets ours apart. Visit our career page, speak with our team, listen to our founders’ podcast, or experience our culture first-hand during the interview process.
• Make a Meaningful Impact: Your work at Flinn contributes directly to solutions that improve people’s health and lives by making high-quality health products accessible for everyone.
• Experienced, well-funded, highly professional: As well-funded startup veterans, we know how to sustain long-term business health and success, ensuring an environment for continuous personal growth.
Your contributions to our journey:
• Take over end-to-end ownership of our certified ISO 27001 ISMS, ensuring it stays effective, current, and audit-ready year-round.
• Lead preparation and execution support for surveillance audits, including evidence readiness, stakeholder preparation, and closing findings.
• Run the internal audit program and drive corrective actions (CAPA) to closure with clear ownership and measurable outcomes.
• Harmonize security and privacy governance by aligning ISO 27001 and GDPR processes (risk, vendor management, incident/breach handling, access governance, retention).
• Expand the privacy program from GDPR to include HIPAA-related requirements and robust handling of health/sensitive data (incl. vendor/subprocessor controls).
• Translate security/privacy requirements into pragmatic, actionable work for Engineering and Operations (“what needs to be done, how, and what evidence is needed”).
• Improve scalability of compliance operations using Vanta (evidence automation, control monitoring, clean documentation) and help prepare for future SOC 2 / NIST needs.
What is in for you?
• Grow with us. We are committed to supporting you in your professional and personal development, no matter whether you aim to become a great leader, renowned expert, successful entrepreneur, or high performing specialist.
• Staying healthy is a top priority. We help each other to reflect, stay in balance, and free up company budget to support healthy activities (food, subscriptions, team activities etc.).
• Competitive compensation, including above-market salaries for exceptional talent.
• We offer you flexibility and empower you to design your days/weeks according to your needs. Therefore, we offer unlimited vacation and very flexible working hours.
• We commit ourselves to the highest integrity standards. Great performance is not an excuse for disrespectful, jerk-like behavior.