Staff Security Engineer, GRC
Oscar Health · New York, New York, United States
About this role
**Oscar — Staff Security Engineer, GRC (Information Security Team)** **About the role** As a Staff GRC Engineer, you’ll be a cloud-aware governance, risk, and compliance expert supporting Oscar’s healthcare technology environment—focused on **CMS Enhanced Direct Enrollment (EDE) platforms** and **Stage 3 certification readiness**. You’ll translate **CMS EDE requirements**, **FedRAMP Moderate-aligned expectations**, and **NIST SP 800-53 controls** into practical **control designs**, **compliance-as-code patterns**, **evidence workflows**, and **risk management practices** for **AWS- and Azure-hosted** systems. You’ll partner directly with engineering, security, legal, compliance, product, and CMS-facing stakeholders to keep regulated platforms audit-ready while enabling secure delivery. You’ll report into the **CISO**. **Work Location** - **New York City (Hybrid)**: 3 days in-office per week - **Thursdays** are required in-office for team meetings/events - Other two days are flexible - **#LI-Hybrid** **Pay Transparency** - **Base pay:** $245,916 – $286,902 per year - Eligible for benefits, unlimited vacation, equity grants, and annual performance bonuses **Responsibilities** - **CMS EDE Governance:** Lead governance/compliance strategy for CMS EDE platforms (Phase 3 expectations, oversight, audit readiness, regulator-facing evidence) - **Control Architecture:** Map CMS EDE + NIST SP 800-53 requirements to technical/operational/admin controls implementable and measurable across **AWS/Azure** - **Significant Change Management:** Prepare/review/submit CMS significant change requests; maintain evidence of approvals, risk decisions, and implementation readiness - **Compliance as Code:** Build/mature compliance-as-code patterns (control automation, policy-as-code, IaC guardrails, continuous evidence collection, automated drift detection) - **POA&M Management:** Own POA&M lifecycle (intake, risk rating, remediation planning, dependencies, stakeholder reporting, evidence validation, closure readiness) - **Risk Assessment & Advisory:** Assess risk for cloud services, EDE changes, integrations, third-party dependencies, and security exceptions - **Audit & Evidence Operations:** Build repeatable evidence workflows for CMS audits, independent assessments, internal reviews, and partner/customer assurance requests - **Cross-Functional Leadership:** Trusted GRC partner translating regulatory requirements into practical technical plans - Comply with applicable laws and regulations **Requirements** - **7+ years** combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments - Deep working knowledge of **CMS Enhanced Direct Enrollment**, including ability to support/lead **Phase 3** certification activities - Strong knowledge of **NIST SP 800-53** control expectations and how they map to cloud-hosted healthcare platforms - Hands-on experience partnering with engineering to implement controls in **AWS** (IaC, policy-as-code, automated evidence collection, or similar) - Experience preparing **CMS significant change requests**, security impact analyses, **POA&Ms**, audit evidence, control narratives, risk acceptances, and remediation plans - Ability to communicate regulatory/control requirements clearly to technical and non-technical audiences (including senior leaders and external assessors) **Bonus points** - Bachelor’s degree or equivalent experience - Experience in healthcare
Listing freshness
CronJobs last confirmed this listing 5h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.