Jobs › New York › New York City › Staff Security Engineer, GRC
Staff Security Engineer, GRC
Oscar Health is hiring for the job of Staff Security Engineer, GRC, New York, NY (On-site). This is a Governance job in the governance, risk, and compliance field, with a posted range of $245,916 - $286,902. Review the full details below and apply directly with Oscar Health.
Hi, we re Oscar. We re hiring a Staff Security Engineer, GRC to join our Information Security Team.
Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the kind of health insurance company we would want for ourselves, one that behaves like a doctor in the family.
About the role:
As a Staff GRC Engineer, you will be a cloud-aware governance, risk, and compliance expert supporting Oscar s healthcare technology environment, with a specific focus on CMS Enhanced Direct Enrollment (EDE) platforms and stage 3 certification readiness. You will translate CMS EDE requirements, FedRAMP Moderate-aligned expectations, and NIST SP 800-53 controls into practical control designs, compliance-as-code patterns, evidence workflows, and risk management practices for AWS-hosted and Azure-hosted systems. You will operate as a senior subject matter expert who can partner directly with engineering, security, legal, compliance, product, and CMS-facing stakeholders to keep regulated platforms audit-ready while enabling secure delivery.
You will report into the CISO.
Work Location: This position is based in our New York City office, requiring a hybrid work schedule with 3 days of in-office work per week. Thursdays are a required in-office day for team meetings and events, while your other two office days are flexible to suit your schedule. # -Hybrid
Pay Transparency: The base pay for this role is: $245,916 - $286,902 per year You are also eligible for employee benefits, participation in Oscar s unlimited vacation program, company equity grants, and annual performance bonuses.
Responsibilities:
CMS EDE Governance: Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms, with a focus on Phase 3 certification expectations, ongoing oversight, audit readiness, and regulator-facing evidence.
Control Architecture: Map CMS EDE and NIST SP 800-53 requirements to technical, operational, and administrative controls that can be implemented and measured across AWS and Azure environments.
Significant Change Management: Prepare, review, and submit CMS significant change requests, partner with technical teams on impact analysis, and maintain clear evidence of approval status, risk decisions, and implementation readiness.
Compliance as Code: Build and mature compliance-as-code patterns for AWS, including control automation, policy-as-code, infrastructure-as-code guardrails, continuous evidence collection, and automated drift detection.
POA and M Management: Own POA and M lifecycle management, including issue intake, risk rating, remediation planning, dependency tracking, stakeholder reporting, evidence validation, and closure readiness.
Risk Assessment and Advisory: Perform risk assessments for cloud services, EDE platform changes, system integrations, third-party dependencies, and security exceptions using healthcare and federal control expectations.
Audit and Evidence Operations: Build repeatable evidence workflows for CMS audits, independent assessments, internal reviews, and customer or partner assurance requests.
Cross-Functional Leadership: Serve as a trusted GRC partner to engineering, security, product, compliance, legal, and business leaders, translating regulatory requirements into practical technical plans.
Compliance with all applicable laws and regulations
Other duties as assigned
Requirements:
7+ years of combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments.
Deep working knowledge of CMS Enhanced Direct Enrollment requirements, including the ability to support or lead Phase 3 certification activities.
Strong knowledge of NIST SP 800-53 controls control expectations, including how those controls map to cloud-hosted healthcare platforms.
Hands-on experience partnering with engineering teams to implement controls in AWS using infrastructure as code, policy as code, automated evidence collection, or similar compliance automation approaches.
Experience preparing CMS significant change requests, security impact analyses, POA and Ms, audit evidence, control narratives, risk acceptances, and remediation plans.
Ability to communicate regulatory and control requirements clearly to technical and non-technical audiences, including senior leaders and external assessors.
Bonus points:
Bachelor s degree or years of equivalent experience.
Prior work experience in healthcare, health insurance, marketplace exchange, or other highly regulated technology environments.
Experience supporting CMS EDE Phase 3 certification, annual CMS audits, independent security assessments, or regulator-facing security reviews.
Experience with GRC platforms, cloud security posture management, SIEM/evidence pipelines, configuration management, or automated control monitoring.
Relevant security, audit, or cloud certifications such as CISSP, CISA, CRISC, CCSP, AWS Security Specialty, or equivalent practical experience.
span 400; This is an authentic Oscar Health job opportunity.
span 400; At Oscar, being an Equal Opportunity Employer means more than upholding discrimination-free hiring practices. It means that we cultivate an environment where people can be their most authentic selves and find both belonging and support. We re on a mission to change health care -- an experience made whole by our unique backgrounds and perspectives.
Pay Transparency: span 400; Final offer amounts, within the base pay set forth above, are determined by factors including your relevant skills, education, and experience. span 400; Full-time employees are eligible for benefits including: medical, dental, and vision benefits, 11 paid holidays, paid sick time, paid parental leave, 401(k) plan participation, life and disability insurance, and paid wellness time and reimbursements.
span 400; Artificial Intelligence (AI): Our a AI Guidelines outline the acceptable use of artificial intelligence for candidates and detail how we use AI to support our recruiting efforts.
Reasonable Accommodation: span 400; Oscar applicants are considered solely based on their qualifications, without regard to applicant’s disability or need for accommodation. Any Oscar applicant who requires reasonable accommodations during the application process should contact the Oscar Benefits Team (accommodations@hioscar.com) to make the need for an accommodation known.
span 400; California Residents: For information about our collection, use, and disclosure of applicants’ personal information as well as applicants’ rights over their personal information, please see our a Privacy Policy.
Certifications this role asks for
Studying for one of these? Try the free CISA practice questions in our academy. No signup, no cost.
Location and market context
This job is based in New York on-site. Local candidates benefit from being close to Oscar Health's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About governance jobs
Governance jobs design the structures, policies, and oversight that keep complex programs accountable, coordinating across legal, risk, compliance, and technology. Jobs like this one are typically evaluated against frameworks such as governance frameworks, policy standards, and oversight and reporting practices.
How to position yourself for this governance job
Strong candidates emphasize policy and standard-setting, committee and stakeholder coordination, oversight reporting, and translating strategy into durable operating structures. In your resume and outreach, tie your experience to how Oscar Health would apply governance frameworks, policy standards, and oversight and reporting practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Subject Matter Expert - Election Integrity, Violent Extremism, and Fraud · Reflection AI · New York, NY
- Senior Software Engineer II, KYC · Carta · New York, NY
- Head of Regulatory Affairs · Brex · New York, NY
- GRC Program Manager · Palantir Technologies · New York, NY
- Head of AI Governance · Guardian Life · New York, NY
- Regulatory Counsel, Americas · Airwallex · New York
- Global AML Manager · Airwallex · New York
- Corporate Sanctions Advisory Officer - Assistant Vice President · Deutsche Bank · New York, 1 Columbus Circle
More jobs at Oscar Health
- Associate Medical Director, Regulatory Management · Oscar Health · Remote
- Risk Adjustment Auditor · Oscar Health · Texas
- Senior Director, Enterprise Compliance · Oscar Health · New York, NY
- Senior Director, Enterprise Compliance · Oscar Health · Dallas, TX
- Associate Director, Claims Compliance · Oscar Health · Dallas, Texas
- Senior Director, Enterprise Compliance · Oscar Health · Atlanta, Georgia
More GRC jobs in New York
- Associate, Financial Crimes Compliance · Vestwell · New York, NY, TX King of Prussia
- Financial Crimes Compliance Strategist · Ramp · New York, NY
- Senior Fraud Risk Manager · OKX · New York
- Security GRC Analyst/Program Manager, Bridge · Stripe · New York
- Associate/Investigations (Risk, Investigations & Analytics practice) · Charles River Associates · New York, NY
- User Risk Strategist · Stripe · New York, NY
Hiring for Governance?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Staff Security Engineer, GRC in New York, NY open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.