As the Compliance Architect at Fountain Life, you build the foundation that allows innovation to flourish safely. While we push the boundaries with AI-driven diagnostics and personalized medicine, you ensure we protect the members who trust us with their health data.
You partner with engineers developing patient-facing AI tools, turning HITRUST, HIPAA, and GDPR requirements into frameworks our 200-person team can execute. Your work accelerates trust, opens markets, and protects our mission. You're building this program from the ground up鈥攖he architect, not just the auditor.
What You'll Do
Own Our Regulatory Foundation
路聽聽聽聽聽聽聽Manage our HITRUST r2 certification program end-to-end, from evidence collection to external assessor coordination
路聽聽聽聽聽聽聽Build and maintain our HIPAA compliance program across all clinical and operational systems
路聽聽聽聽聽聽聽Design compliance frameworks that enable international expansion with GDPR readiness
聽
Pioneer AI Governance in Healthcare
路聽聽聽聽聽聽聽Partner with engineering to establish governance for patient-facing AI diagnostic tools
路聽聽聽聽聽聽聽Develop controls addressing algorithmic bias, model explainability, data leakage, and patient safety
路聽聽聽聽聽聽聽Integrate compliance into product development workflows
路聽聽聽聽聽聽聽Prepare for EU AI Act
聽
Build Cross-Functional Trust
路聽聽聽聽聽聽聽Advise executive leadership on risk and regulatory strategy
路聽聽聽聽聽聽聽Translate regulations into clear guidance that enables teams
路聽聽聽聽聽聽聽Deliver HIPAA and security awareness training
路聽聽聽聽聽聽聽Manage compliance incidents with urgency and discretion
聽
Key Responsibilities
路聽聽聽聽聽聽聽Manage HITRUST r2 certification: scoping, controls, evidence, and assessor coordination
路聽聽聽聽聽聽聽Maintain HIPAA Security Rule, Privacy Rule, and Breach Notification compliance
路聽聽聽聽聽聽聽Create AI risk assessment frameworks integrated into product development
路聽聽聽聽聽聽聽Conduct third-party vendor due diligence and risk assessments
路聽聽聽聽聽聽聽Develop data protection frameworks satisfying HIPAA and GDPR
路聽聽聽聽聽聽聽Conduct quarterly internal audits and gap assessments
路聽聽聽聽聽聽聽Monitor regulatory changes and adapt programs proactively
聽
Your Qualifications
Required
路聽聽聽聽聽聽聽5-8 years compliance experience in healthcare, health tech, or medical devices
路聽聽聽聽聽聽聽Direct HITRUST r2 certification management experience (non-negotiable)
路聽聽聽聽聽聽聽Expert knowledge of HIPAA Security Rule, Privacy Rule, and HITRUST CSF r2
路聽聽聽聽聽聽聽Experience implementing HIPAA compliance in cloud-based healthcare environments
路聽聽聽聽聽聽聽Track record working with engineering teams in product-driven organizations
路聽聽聽聽聽聽聽Ability to build compliance programs independently with minimal oversight
路聽聽聽聽聽聽聽Strong understanding of cloud security architecture (AWS, Azure, or GCP)
路聽聽聽聽聽聽聽Working knowledge of AI/ML systems and patient-facing AI diagnostic risks
路聽聽聽聽聽聽聽Foundational understanding of GDPR and international privacy regulations
聽
Preferred
路聽聽聽聽聽聽聽HITRUST CCSFP, CISA, CISSP, CRISC, CISM, CIPP/US, CCEP, or CRCM certifications
路聽聽聽聽聽聽聽Experience with ISO 27001, NIST Cybersecurity Framework
聽
Core Competencies
路聽聽聽聽聽聽聽Technical fluency to work directly with engineers and translate regulatory requirements
路聽聽聽聽聽聽聽Strategic risk thinker who balances compliance rigor with business needs
路聽聽聽聽聽聽聽Clear communicator to both technical teams and executive leadership
路聽聽聽聽聽聽聽Self-directed with strong ownership and initiative
路聽聽聽聽聽聽聽Collaborative partner seen as innovation enabler, not blocker
路聽聽聽聽聽聽聽Calm under pressure during audits, incidents, and regulatory situations
聽
What Success Looks Like in Year One
路聽聽聽聽聽聽聽Complete HITRUST r2 re-certification with zero major findings
路聽聽聽聽聽聽聽Build trusted advisor relationships with Engineering, Product, and Executive teams
路聽聽聽聽聽聽聽Create comprehensive compliance documentation accessible to all teams
路聽聽聽聽聽聽聽Develop GDPR readiness roadmap for international expansion
路聽聽聽聽聽聽聽Position compliance program for scale as we grow
聽
As the Compliance Architect, you'll:
路聽聽聽聽聽聽聽Build a compliance program for one of healthcare's most innovative models
路聽聽聽聽聽聽聽Work on emerging challenges at the intersection of healthcare AI and patient privacy
路聽聽聽聽聽聽聽Protect 8,000 members while enabling life-changing healthcare innovation
路聽聽聽聽聽聽聽Grow into leadership as our first compliance hire when we scale globally
Learn more about this Employer on their Career Site
