CronJobs

security jobs

Staff Security Engineer, GRC

Oscar Health · New York, New York, United States

hybridsenior$245,916–$286,902Posted Aug 20, 2026AWSAzureNIST SP 800-53Infrastructure as CodePolicy as CodeCMS EDEFedRAMP

Apply on the employer site

About this role

**Oscar — Staff Security Engineer, GRC (Information Security Team)** **About the role** As a Staff GRC Engineer, you’ll be a cloud-aware governance, risk, and compliance expert supporting Oscar’s healthcare technology environment—focused on **CMS Enhanced Direct Enrollment (EDE) platforms** and **Stage 3 certification readiness**. You’ll translate **CMS EDE requirements**, **FedRAMP Moderate-aligned expectations**, and **NIST SP 800-53 controls** into practical **control designs**, **compliance-as-code patterns**, **evidence workflows**, and **risk management practices** for **AWS- and Azure-hosted** systems. You’ll partner directly with engineering, security, legal, compliance, product, and CMS-facing stakeholders to keep regulated platforms audit-ready while enabling secure delivery. You’ll report into the **CISO**. **Work Location** - **New York City (Hybrid)**: 3 days in-office per week - **Thursdays** are required in-office for team meetings/events - Other two days are flexible - **#LI-Hybrid** **Pay Transparency** - **Base pay:** $245,916 – $286,902 per year - Eligible for benefits, unlimited vacation, equity grants, and annual performance bonuses **Responsibilities** - **CMS EDE Governance:** Lead governance/compliance strategy for CMS EDE platforms (Phase 3 expectations, oversight, audit readiness, regulator-facing evidence) - **Control Architecture:** Map CMS EDE + NIST SP 800-53 requirements to technical/operational/admin controls implementable and measurable across **AWS/Azure** - **Significant Change Management:** Prepare/review/submit CMS significant change requests; maintain evidence of approvals, risk decisions, and implementation readiness - **Compliance as Code:** Build/mature compliance-as-code patterns (control automation, policy-as-code, IaC guardrails, continuous evidence collection, automated drift detection) - **POA&M Management:** Own POA&M lifecycle (intake, risk rating, remediation planning, dependencies, stakeholder reporting, evidence validation, closure readiness) - **Risk Assessment & Advisory:** Assess risk for cloud services, EDE changes, integrations, third-party dependencies, and security exceptions - **Audit & Evidence Operations:** Build repeatable evidence workflows for CMS audits, independent assessments, internal reviews, and partner/customer assurance requests - **Cross-Functional Leadership:** Trusted GRC partner translating regulatory requirements into practical technical plans - Comply with applicable laws and regulations **Requirements** - **7+ years** combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments - Deep working knowledge of **CMS Enhanced Direct Enrollment**, including ability to support/lead **Phase 3** certification activities - Strong knowledge of **NIST SP 800-53** control expectations and how they map to cloud-hosted healthcare platforms - Hands-on experience partnering with engineering to implement controls in **AWS** (IaC, policy-as-code, automated evidence collection, or similar) - Experience preparing **CMS significant change requests**, security impact analyses, **POA&Ms**, audit evidence, control narratives, risk acceptances, and remediation plans - Ability to communicate regulatory/control requirements clearly to technical and non-technical audiences (including senior leaders and external assessors) **Bonus points** - Bachelor’s degree or equivalent experience - Experience in healthcare

Listing freshness

CronJobs last confirmed this listing 5h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord