via Greenhouse · 9 September 2026 ·10 days ago

VP of Security & Infrastructure

flohealth
London
This listing is from Greenhouse
View original listing ↗

<div class="content-intro"><p><strong>500M+ downloads. 80M+ monthly users. A decade of building – and we’re still accelerating.</strong></p>
<p>Flo is the world’s #1 health &amp; fitness app worldwide on a mission to build a better future for female health. Backed by a $200M investment led by General Atlantic, we became the first product of our kind to reach a $1B valuation in 2024 – and we’re not slowing down.</p>
<p>With 7M paid subscribers and the highest-rated experience in the App Store’s health category, we’ve spent 10 years earning trust at scale. Now, we’re building the next generation of digital health – AI-powered, privacy-first, clinically backed – to help our users know their body better.</p>
<p><strong>The job</strong></p></div><p>This role unites Security and Infrastructure under a single organizational mandate to ensure security practices align directly with rapid engineering execution and platform scalability. Flo Health protects the data of over 80 million monthly active users, holding ISO 27001 and ISO 27701 certifications alongside privacy-first features such as Anonymous Mode. The VP of Security &amp; Infrastructure is accountable for maintaining and elevating these security, privacy, and architectural standards across the organization. We are building organisation where secure is the default path and the fast path.</p>
<h2><strong>Core Ownership &amp; Responsibilities</strong></h2>
<h3><strong>1. Security Strategy &amp; Governance</strong></h3>
<ul>
<li><strong>Security Stategy and Roadmap: </strong>Develop, evolve and communicate Flo’s security strategy and roadmap, promoting strong shared security ownership culture.</li>
<li><strong>Security Programme:</strong> Oversee all aspects of Flo’s security programme, risk management, security architecture, product security, and security operations, including embedded security engineering functions. </li>
<li><strong>Data Protection &amp; Governance: </strong>Define and enforce standards for storing, protecting, and deleting personal and health data across production systems, analytics warehouses, AI model training sets, backups, and search indexes.</li>
<li><strong>Regulatory &amp; Compliance Engineering: </strong>Deliver and oversee the performance of technical controls, automated evidence extraction, and ongoing compliance for ISO 27001, ISO 27701, SOC 2 Type 2, HIPAA, EU AI Act, and Cyber Resilience Act.</li>
<li><strong>Third-Party &amp; Supply-Chain Risk: </strong>Establish evaluation criteria and ongoing governance controls for vendors, SDKs, and external partners accessing internal environments or data.</li>
<li><strong>Vulnerability Management:</strong> Oversee the management life cycle of code, third party and platform vulnerabilities, ensuring remediation paths are transparent, risk-based, and tracked to closure.</li>
<li><strong>Security Operations &amp; Incident Response: </strong>Oversee detection engineering, continuous threat monitoring, and serve as the accountable executive for major incident escalations.</li>
</ul>
<h3><strong>2. Platform &amp; Infrastructure Engineering</strong></h3>
<ul>
<li><strong>Cloud &amp; Developer Infrastructure: </strong>Own GCP and AWS multi-account architecture, Kubernetes, Terraform, and developer platform delivery to drive down lead times and change failure rates.</li>
</ul>
<p><strong>Secure SDLC: embed technical security requirements across the development lifecycle, optimising automated security controls within CI/CD pipelines, and ensuring well informed platform and product security architecture decisions drive strong protection, resilience and scalability.</strong></p>
<ul>
<li><strong>Corporate IT &amp; Access Controls: </strong>Manage IT service provision, including identity, hardware devices, collaboration tools and joiner-mover-leaver lifecycle workflows through automated, self-service access controls.</li>
</ul>
<h3><strong>3. User Identity &amp; AI Security</strong></h3>
<ul>
<li><strong>Product Identity &amp; Access Management: </strong>Direct cross-functional roadmaps for user facing security services and account safety, including authentication, sessions management, and cryptography,while balancing conversion metrics with security controls.</li>
<li><strong>AI &amp; Machine Actor Security: </strong>Establish governance, scoping, permissioning, appropriate security guardrails and auditing for AI-assisted engineering agents and consumer-facing AI features.</li>
</ul>
<h3><strong>4. External Trust and Transparency</strong></h3>
<ul>
<li><strong>Advocate for Security In FemTech:</strong> Set and continually raisethe bar as market leader, executing transparent and proactive external communications and raising Flo's security profile through external events and industry engagement.</li>
</ul>
<h2><strong>Key Qualifications &amp; Technical Requirements</strong></h2>
<ul>
<li><strong>Leadership Experience: </strong>Proven track record of managing combined or parallel Security and Production Infrastructure functions at consumer scale (tens of millions of active users).</li>
<li><strong>Product Integration: </strong>Demonstrated experience partnering with Product, Design, and Mobile/Backend Engineering teams to ship user-facing features to roadmap.</li>
<li><strong>Audit Track Record: </strong>Successful execution and ongoing maintenance of ISO 27001, SOC 2, HIPAA, or equivalent certification frameworks through external audits.</li>
<li><strong>Data Privacy Systems: </strong>Deep technical experience implementing GDPR, automated data deletion, retention policies, DPIAs, and cross-border transfer controls programmatically.</li>
<li><strong>AI Governance &amp; Security: </strong>Practical implementation experience securing AI models, autonomous code/development agents, and automated permission/audit systems.</li>
<li><strong>Preferred Qualifications: </strong>Experience with consumer sign-in optimization, health/biometric data protection, in-house offensive security engineering, and mobile platform security.</li>
</ul><div class="content-pay-transparency"><div class="pay-input"><div class="title">Annual Salary Range (ranges may vary based on skills and experience)</div><div class="pay-range"><span>£200,000</span><span class="divider">&mdash;</span><span>£220,000 GBP</span></div></div></div><div class="content-conclusion"><p><strong>How we work</strong></p>
<p>We’re a mission-led, product-driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.</p>
<p>You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience, and the drive to keep going when things get tough. Because better health outcomes are worth it. </p>
<p><strong>What you'll get</strong></p>
<p>We support impact with meaningful reward. Here’s what that looks like:</p>
<ul>
<li>Competitive salary and annual reviews</li>
<li>Opportunity to participate in Flo’s performance incentive scheme</li>
<li>Paid holiday, sick leave, and female health leave</li>
<li>Enhanced parental leave and pay for maternity, paternity, same-sex and adoptive parents</li>
<li>Accelerated professional growth through world-changing work and learning support</li>
<li>In-person collaboration and work in a hybrid model, with 3 days per week spent in the office</li>
<li>5-week fully paid sabbatical at 5-year Floversary</li>
<li>Flo Premium for friends &amp; family, plus more health, pension and wellbeing perks</li>
</ul>
<p><strong>Diversity, equity and inclusion</strong></p>
<p>Our strength is in our differences. At Flo, hiring is based on merit, skill and what you bring to the role – nothing else. We’re proud to be an equal opportunity employer, and we welcome applicants from all backgrounds, communities and identities. Read our <a href="https://flo.health/privacy-policy-for-job-applicants">privacy notice for job applicants</a>.</p></div>

The market for this type of role

Similar openings
20,211
jobs in London
Full-time
80%
of roles in the UK
Remote possible
4%
of roles
flohealth

3 open positions · London

📊 Job market · the UK
68,619
active jobs
7.9%
Remote
Ø 2d
avg. online

Frequently asked questions

How many jobs are available in London?
Currently 20,211 roles in London on AlmostHired, across 6,737 different companies. Our data is updated daily.
Do roles in the UK offer remote work?
4% of roles in the UK allow remote work, either partial or full. To filter specifically for remote positions, use AlmostHired.
How do I know if I match this role?
Upload your CV — our AI compares your profile to the job requirements and gives you a precise match score, with matching and missing skills.