hero

A More Equitable and Inclusive Innovation Economy

Applying to a role? Please add yourself to our job application log
here
Colorwave
companies
Jobs

Security, Compliance & Privacy Manager

Function Health

Function Health

Compliance / Regulatory
United States · Remote
Posted on Oct 10, 2025
Security, Compliance & Privacy Manager
US - Remote
Security
Remote
Full-time

About Us:

Function was founded with a singular focus: empower you to live 100 healthy years. We’re doing that by using the best available technology to make sure people don't suffer or die a preventable death. Function has been recognized as one of Fast Company’s Most Innovative Companies of 2024, and is venture-backed by Andreessen Horowitz (a16z). Hundreds of thousands of members have joined Function to take control of their health. We are growing our team and seeking out world-class talent that deeply believes in our mission to positively impact global health, has a relentless bias toward action and a growth mindset. Function fosters a collaborative and dynamic environment, where every day we are building the future.


Role:

Function Health is building a lean, automation-first compliance program to meet SOC 2 Type II and HIPAA requirements while preparing for future regulations. As Security Compliance & Privacy Manager, you’ll lead our compliance operations, partner with Legal on privacy and data protection, and ensure our controls and policies scale with the business.
This role is hands-on and impact-driven: you’ll be the primary liaison with auditors and vendors, run compliance and privacy operations across the company, and help ensure Function meets the trust expectations of our members, partners, and regulators.

Key Responsibilities:

  • Lead SOC 2 Type II and HIPAA compliance operations, including evidence collection, control testing, and audit readiness.
  • Serve as the primary contact with auditors, external assessors, and internal stakeholders for compliance activities.
  • Partner with Legal on privacy requirements (HIPAA Privacy Rule, GDPR, state laws) and ensure controls meet both security and privacy obligations.
  • Maintain a unified control framework that maps SOC 2, HIPAA, and future frameworks (e.g., HITRUST).
  • Own vendor and third-party risk management, including onboarding, reviews, and BAAs/DPAs.
  • Drive quarterly compliance rituals: access reviews, risk register updates, policy acknowledgments, and training compliance.
  • Translate regulatory requirements into engineer-friendly tickets, policy updates, and executive-ready risk summaries.
  • Identify opportunities for automation in compliance workflows (evidence collection, access certifications, vendor reviews).
  • Support privacy operations, including data retention, deletion, and handling of member data requests where applicable.
  • Build awareness across the business so compliance and privacy are seen as enablers, not blockers.

Qualifications/Skills:

  • 6–10 years of experience in compliance, GRC, or risk management, ideally in SaaS or healthtech.
  • Strong knowledge of SOC 2 and HIPAA; familiarity with privacy frameworks such as GDPR, CCPA/CPRA, or HITRUST.
  • Proven ability to lead audits end-to-end and represent compliance posture to external parties.
  • Experience coordinating across functions (Engineering, IT, Legal, Ops) to implement and sustain controls.
  • Familiarity with compliance automation tools (Drata, Tugboat Logic, ConductorOne) and cloud environments (Okta, GCP, GitHub).
  • Excellent communication skills; able to draft policies, auditor-facing documentation, and executive-ready risk reports.
  • Ability to influence teams toward secure, compliant patterns without slowing down business goals.
  • Bonus: experience with healthcare data protection or building privacy programs in regulated industries.

To be a strong fit, you also need:

  • Bias Toward Action: Demonstrated ability to take initiative, make decisions under uncertainty, and move projects forward even in the face of ambiguity. We value individuals who are self-starters and ready to act on opportunities and challenges alike.
  • Entrepreneurial Spirit: Strong adaptability to changing business needs with a knack for building and optimizing processes. Your entrepreneurial mindset will be crucial in navigating the dynamic landscape of our industry, ensuring our platform remains competitive and responsive to user needs.
  • Communication: Excellent communication skills, capable of explaining complex technical concepts to non-technical stakeholders. Effective communication is vital for cross-functional collaboration and ensuring alignment across our organization.
  • Remote Work Adaptability: Comfort with remote work environments, demonstrating the ability to stay productive and connected with the team irrespective of physical location.
  • Continuous Improvement: A willingness to question assumptions and a commitment to continuous improvement. Your openness to feedback and dedication to personal and professional growth will contribute significantly to our collective success.
We value our team at Function and offer a competitive salary and benefits package, flexible working hours, and a dynamic work environment where creativity and innovation are encouraged. If you are a highly motivated and experienced individual who is passionate about using technology to improve people’s lives, we would love to hear from you.
Join the Function Health team and become a part of our mission to revolutionize healthcare. Work with us to make a difference in the lives of thousands, ensuring a healthier future for all. Discover more about us and how we're changing the face of healthcare at Function Health.
Ready to apply?
Powered by
First name *
Last name *
Email *
LinkedIn URL *
Phone number *
Location *
Resume *
Click to upload or drag and drop here
Are you authorized to work in the country where the position is located without requiring sponsorship for a work visa now or in the future?
Were you referred for this position? *
If you were referred, please share who referred you.
Please provide the name of the person who referred you.
Why are you interested in working at Function Health and specifically this role?
Voluntary Self-Identification
To comply with government reporting requirements, we invite candidates to participate in the self-identification survey below. Your completion of this form is entirely optional, and your decision will neither influence the hiring process nor any subsequent stages. Any information you choose to share will be kept confidential and stored in a secure file. As outlined in our Equal Employment Opportunity policy, we uphold a commitment to non-discrimination based on any protected group status specified in applicable laws.
Gender
Race
Race and ethnicity descriptions
PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.
By applying you agree to Gem's terms and privacy policy.
Save your info to apply to other roles faster & help employers reach you.
Req ID: R201