Technical Program Manager, Security & Compliance
Heidihealth Com Au · Melbourne · 2026-07-28
About this role
We’re Heidi.
We're building the future of healthcare by giving every clinician the earth's finest AI Care Partner. In just 18 months, our clinical AI products have absorbed the administrative chaos of 73 million patient visits. Today, we support over 2.5 million patient sessions a week across 190+ countries.
Healthcare systems are failing us; clinicians spend more time on documentation than on patients, and the human connection that makes medicine worth practicing is eroding. Our mission is simple: double the world’s healthcare capacity and strengthen the human connection at its heart.
We found product-market fit with a freemium medical scribe that clinicians love. Now, we're expanding. Every task a clinician hands to Heidi is a patient who feels more attended to, a health system unclogged, and a clinician who gets to be a clinician again.
If you don’t choose easy and you want to build something way bigger than yourself then, choose the challenge, choose Heidi.
The role
Heidi operates across US, UK, Australia, beyond and in every market, the same question follows: is this safe, is this secure, and can we prove it? This TPM role is a central platform function: the regulatory and security layer that makes it possible for Heidi to operate inside clinical environments, handle patient data, and be trusted as a medical device.
Clinical AI is under a microscope. Regulators are writing the rules in real time. Every market has its own classification framework, its own submission pathway, its own idea of what a Software as a Medical Device actually is. The difference between a cleared product and a stalled one is often whether someone understood the spec well enough to build against it.
The stack is real and in motion: FDA SaMD classification, TGA registration, MHRA review pathways. ISO 13485 quality management. ISO 14971 risk frameworks. IEC 62304 software lifecycle. SOC 2 Type II. HIPAA. GDPR. The clinical safety standards that let a hospital say yes to deployment. You'll own the regulatory and security roadmap, what to pursue, in what order, and how deep the compliance architecture needs to go. A small dedicated engineering squad sits alongside you. The frameworks are being built. You're picking up a running operation with strong opinions about where it goes.
Your time will be spent translating regulatory reality into product requirements, working directly with legal, engineering, clinical, and commercial to clear the path for enterprise deals. The hard part is that every market moves differently, every hospital has its own security questionnaire, and the gap between what a standard says and what an auditor actually wants can be significant. You'll need to hold the line between one-customer compliance theatre and durable platform-level security architecture.
WHAT YOU'LL DO
- Help drive which certifications and regulatory clearances to pursue, in which markets, in what order — balancing commercial urgency, regulatory risk, and engineering cost.
- Work closely with the regulatory team to unpack the roadmap across FDA, TGA, MHRA and emerging markets — including classification, submission strategy, and ongoing post-market obligations.
- Act as the liaison between customers, legal, clinical, commercial, product and engineering on anything that touches safety, security or compliance.
- Translate the real requirements of ISO 13485, ISO 14971, IEC 62304, SOC 2, HIPAA and GDPR into product specs and engineering standards that the team can actually build against.
- Drive the security architecture forward — data handling, access controls, encryption, audit logging, penetration testing cadence, vendor risk management — and be accountable to it.
- Build the compliance infrastructure that scales: not one-off responses to one-off audits, but a durable program that grows with the product.
WHAT YOU'LL NEED
- BA/BS in a technical or analytical field (Computer Science, Engineering, Information Systems, Biomedical Engineering, Applied Sciences or related)
- 4+ years in product, regulatory, or technical roles — we care more about what you've shipped and cleared than years on the clock
- Real fluency with medical device regulation: FDA SaMD classification and 510(k)/De Novo pathways, TGA registration, MHRA review, ISO 13485, ISO 14971, IEC 62304. This is a requirement, not a nice-to-have
- Experience building compliance programs that scale, not one-off responses to one-off audits, but durable architecture that grows as the product and market footprint grows
- Comfort making build-vs-document trade-offs daily, and the judgment to know when a shortcut today becomes a regulatory finding tomorrow
- The ability to hold a coherent regulatory roadmap under pressure from multiple regional teams with competing commercial timelines
- Diagnostic security fluency: you can read a customer security questionnaire, identify what's a product gap versus a configuration question versus a compliance theatre request, and triage accordingly
- A romantic streak about software and a belief that great design, including security design that transforms someone's day
- You build with AI tools (Cursor, Claude Code, whatever ships faster) and can show what you've made with them
- Fluency with core LLM concepts and how they interact with regulatory risk — model drift, output validation, intended use boundaries, evaluation and the judgment to translate these into compliant, reliable products
- Strong opinions, weakly held: you'll shift the room when you're right
How we show up
- Build for the next decade, not next quarter. Our targets are outrageous on purpose. The world's health doesn't have the luxury of incrementalism.
- Lead, don't wait. We treat tomorrow's problems today. Sometimes we build what's needed before it's wanted, and we're fine with that.
- Follow the evidence. Trust the patient. We pursue truth relentlessly. But when the subjective and objective disagree, we…
Skills asked for
- go
- penetration testing
- llm
- rest
Similar jobs
- Technical Program Manager, IntegrationsHeidihealth Com Au · Melbourne
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.