VP of Security & Infrastructure
500M+ downloads. 80M+ monthly users. A decade of building – and we’re still accelerating.
Flo is the world’s #1 health & fitness app worldwide on a mission to build a better future for female health. Backed by a $200M investment led by General Atlantic, we became the first product of our kind to reach a $1B valuation in 2024 – and we’re not slowing down.
With 7M paid subscribers and the highest-rated experience in the App Store’s health category, we’ve spent 10 years earning trust at scale. Now, we’re building the next generation of digital health – AI-powered, privacy-first, clinically backed – to help our users know their body better.
The job
This role unites Security and Infrastructure under a single organizational mandate to ensure security practices align directly with rapid engineering execution and platform scalability. Flo Health protects the data of over 80 million monthly active users, holding ISO 27001 and ISO 27701 certifications alongside privacy-first features such as Anonymous Mode. The VP of Security & Infrastructure is accountable for maintaining and elevating these security, privacy, and architectural standards across the organization. We are building organisation where secure is the default path and the fast path.
Core Ownership & Responsibilities
1. Security Strategy & Governance
- Security Stategy and Roadmap: Develop, evolve and communicate Flo’s security strategy and roadmap, promoting strong shared security ownership culture.
- Security Programme: Oversee all aspects of Flo’s security programme, risk management, security architecture, product security, and security operations, including embedded security engineering functions.
- Data Protection & Governance: Define and enforce standards for storing, protecting, and deleting personal and health data across production systems, analytics warehouses, AI model training sets, backups, and search indexes.
- Regulatory & Compliance Engineering: Deliver and oversee the performance of technical controls, automated evidence extraction, and ongoing compliance for ISO 27001, ISO 27701, SOC 2 Type 2, HIPAA, EU AI Act, and Cyber Resilience Act.
- Third-Party & Supply-Chain Risk: Establish evaluation criteria and ongoing governance controls for vendors, SDKs, and external partners accessing internal environments or data.
- Vulnerability Management: Oversee the management life cycle of code, third party and platform vulnerabilities, ensuring remediation paths are transparent, risk-based, and tracked to closure.
- Security Operations & Incident Response: Oversee detection engineering, continuous threat monitoring, and serve as the accountable executive for major incident escalations.
2. Platform & Infrastructure Engineering
- Cloud & Developer Infrastructure: Own GCP and AWS multi-account architecture, Kubernetes, Terraform, and developer platform delivery to drive down lead times and change failure rates.
Secure SDLC: embed technical security requirements across the development lifecycle, optimising automated security controls within CI/CD pipelines, and ensuring well informed platform and product security architecture decisions drive strong protection, resilience and scalability.
- Corporate IT & Access Controls: Manage IT service provision, including identity, hardware devices, collaboration tools and joiner-mover-leaver lifecycle workflows through automated, self-service access controls.
3. User Identity & AI Security
- Product Identity & Access Management: Direct cross-functional roadmaps for user facing security services and account safety, including authentication, sessions management, and cryptography,while balancing conversion metrics with security controls.
- AI & Machine Actor Security: Establish governance, scoping, permissioning, appropriate security guardrails and auditing for AI-assisted engineering agents and consumer-facing AI features.
4. External Trust and Transparency
- Advocate for Security In FemTech: Set and continually raisethe bar as market leader, executing transparent and proactive external communications and raising Flo's security profile through external events and industry engagement.
Key Qualifications & Technical Requirements
- Leadership Experience: Proven track record of managing combined or parallel Security and Production Infrastructure functions at consumer scale (tens of millions of active users).
- Product Integration: Demonstrated experience partnering with Product, Design, and Mobile/Backend Engineering teams to ship user-facing features to roadmap.
- Audit Track Record: Successful execution and ongoing maintenance of ISO 27001, SOC 2, HIPAA, or equivalent certification frameworks through external audits.
- Data Privacy Systems: Deep technical experience implementing GDPR, automated data deletion, retention policies, DPIAs, and cross-border transfer controls programmatically.
- AI Governance & Security: Practical implementation experience securing AI models, autonomous code/development agents, and automated permission/audit systems.
- Preferred Qualifications: Experience with consumer sign-in optimization, health/biometric data protection, in-house offensive security engineering, and mobile platform security.
How we work
We’re a mission-led, product-driven team. We move fast, stay focused and take ownership – from brief to build to impact. Debate is encouraged. Decisions are shared. We care about craft, ship with purpose, and always raise the bar.
You’ll be working with people who take their work seriously, not themselves. It takes commitment, resilience, and the drive to keep going when things get tough. Because better health outcomes are worth it.
What you'll get
We support impact with meaningful reward. Here’s what that looks like:
- Competitive salary and annual reviews
- Opportunity to participate in Flo’s performance incentive scheme
- Paid holiday, sick leave, and female health leave
- Enhanced parental leave and pay for maternity, paternity, same-sex and adoptive parents
- Accelerated professional growth through world-changing work and learning support
- In-person collaboration and work in a hybrid model, with 3 days per week spent in the office
- 5-week fully paid sabbatical at 5-year Floversary
- Flo Premium for friends & family, plus more health, pension and wellbeing perks
Diversity, equity and inclusion
Our strength is in our differences. At Flo, hiring is based on merit, skill and what you bring to the role – nothing else. We’re proud to be an equal opportunity employer, and we welcome applicants from all backgrounds, communities and identities. Read our privacy notice for job applicants.