Senior Security Engineer I, GRC
$163.94k - $215.18kOscar Health
Hi, we're Oscar. We're hiring a Senior Security Engineer 1, GRC to join our Security Team.
Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the kind of health insurance company we would want for ourselves-one that behaves like a doctor in the family. About the role: The Principal GRC Engineer designs and operates the systems that enable continuous security assurance, deep risk visibility, and scalable regulatory compliance. Rather than managing documentation or preparing for audits, this role engineers the infrastructure that allows the organization to demonstrate security and compliance continuously through automation, telemetry, and self-evidencing controls. Operating at the intersection of security engineering, platform engineering, risk management, and regulatory assurance, you will embed governance and control validation directly into how systems are built and operated. By connecting controls, operational telemetry, engineering workflows, and risk signals, you will surface patterns and relationships that traditional GRC programs cannot see, creating a feedback loop where security intelligence continuously informs engineering guardrails and platform architecture. You will report into the Sr. Manager GRC. Work Location: This position is based in our New York City office, requiring a hybrid work schedule with 3 days of in-office work per week. Thursdays are a required in-office day for team meetings and events, while your other two office days are flexible to suit your schedule.Pay Transparency: The base pay for this role is: $163,944 per year - $215,176 per year. You are also eligible for employee benefits, participation in Oscar's unlimited vacation program, company equity grants and annual performance bonuses. Responsibilities:
- Design systems that continuously measure and validate security controls through operational telemetry, automated evidence generation, and control health monitoring.
- Build automation and orchestration across security tools, cloud platforms, and engineering systems to eliminate manual compliance processes and reduce audit overhead.
- Translate governance expectations into machine-enforceable guardrails embedded within infrastructure platforms, CI/CD pipelines, and engineering workflows.
- Apply automation, orchestration, and AI-assisted capabilities to scale governance workflows, enabling intelligent analysis and adaptive control systems.
- Architect control and telemetry pipelines where operational systems produce the evidence required for regulatory assurance and audit readiness.
- Compliance with all applicable laws and regulations
- Other duties as assigned
- 4+ years experience in Technology related field.
- 4+ years experience in Security Engineering.
- Familiarity with industry standards and compliance frameworks (such as SOC, SOX., NIST, HIPAA) and experience in ensuring organizational adherence to these standards.
- Certifications such as CISSP, CISM, CISA, CEH, or vendor-specific certifications.
- Proficiency in managing security projects, including planning, execution, and successful delivery within timelines and budgets.
- 4+ years of experience in Security Engineering, DevSecOps, or Site Reliability Engineering (SRE), with at least 3 years specifically focused on GRC automation or internal security tooling.
At Oscar, being an Equal Opportunity Employer means more than upholding discrimination-free hiring practices. It means that we cultivate an environment where people can be their most authentic selves and find both belonging and support. We're on a mission to change health care -- an experience made whole by our unique backgrounds and perspectives. Pay Transparency: Final offer amounts, within the base pay set forth above, are determined by factors including your relevant skills, education, and experience. Full-time employees are eligible for benefits including: medical, dental, and vision benefits, 11 paid holidays, paid sick time, paid parental leave, 401(k) plan participation, life and disability insurance, and paid wellness time and reimbursements. Artificial Intelligence (AI): Our AI Guidelines outline the acceptable use of artificial intelligence for candidates and detail how we use AI to support our recruiting efforts. Reasonable Accommodation: Oscar applicants are considered solely based on their qualifications, without regard to applicant's disability or need for accommodation. Any Oscar applicant who requires reasonable accommodations during the application process should contact the Oscar Benefits Team (View email address on click.appcast.io) to make the need for an accommodation known. California Residents: For information about our collection, use, and disclosure of applicants' personal information as well as applicants' rights over their personal information, please see our Privacy Policy.
Vacancy posted 9 hours ago
Similar jobs that could be interesting for youBased on the Senior Security Engineer I, GRC in New York, NY vacancy
$124k - $150k
...information about American Home Shield and Frontdoor, please visit frontdoorhome.com. Responsibilities Summary: As an L5 Sr Security Engineer in IT GRC at Frontdoor, you will serve as an advanced practitioner that can lead complex security, risk, and compliance initiatives...SeniorFull timeFor contractors- Variety-Staffing is seeking an SAP GRC and Cloud Security Specialist in New Jersey to oversee security features in SAP and Cloud based applications. The role includes conducting security audits, managing SAP security roles, and developing security policies to ensure compliance...Senior
- ...Neos is seeking a Cloud Security Engineer with Splunk experience for a remote, long-term contract... ...IT governance, risk, and compliance (GRC) advisory services, including control frameworks... ..., and internal/external audit support. Seniority level Mid-Senior level Employment type...SeniorLong term contractContract workRemote work
$150k - $200k
...Senior Security Engineer - Compliance and Risk New York, NY About the Role We are seeking a detail-oriented, proactive Security Compliance... ..., Governance, Risk, Vulnerability Management, Compliance (GRC), or IT Audit. Program Management: Proven experience managing...SeniorFull timeLocal area- A leading staffing firm is seeking a Senior Governance, Risk, and Compliance (GRC) Analyst / Engineer. In this role, you will work on security best practices and compliance for cutting-edge robotic delivery solutions. You'll assess risks related to financial and IT systems...SeniorRemote work
- ...GRC Security Engineer, Federal & Public Sector Engineering · Full-time · San Francisco Our mission is to automate coding. The first step... ...adjacent authorizations — is a key path, and we're looking for a senior GRC engineer to lead the technical execution. This is a...Full time
$153.4k - $186k
...Health Care and New York, and top 50 nationwide. The Role As a Senior Security Engineer, Enterprise SaaS, you’ll serve as Ro’s hands-on technical... ...enterprise. You’ll partner across Security Operations, IT, GRC, and Product Security to shape a unified SaaS security strategy...SeniorLocal areaFlexible hours$152k - $224k
...serving millions of families worldwide. About the Job As a Senior Enterprise Security Engineer, you’ll be a technical owner of the controls that protect... ...& Response. You’ll partner closely with IT Engineering, GRC, and the broader security team. With IT, you’ll co‑own...SeniorFor contractorsSummer workRemote workWorldwideFlexible hours$230k - $240k
...A leading software company is seeking a remote Security Engineering lead to enhance their security program. Responsibilities include team leadership, enabling partnerships with Security GRC and Legal, and developing secure engineering practices. The ideal candidate will...SeniorRemote workFlexible hours- A leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves collaboration with various departments to implement governance and risk management processes. The ideal candidate has...Senior
$192k - $240k
...support you need to grow your career. Engineering at Brex Engineering at Brex is... ...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy... ...Application Security, Corporate Engineering, GRC and IT and to improve security...SeniorWork at officeRemote workWork from home- ...A tech consulting firm is looking for a Sr. Infrastructure Security Engineer to develop and enhance security systems across AWS, GCP, and Azure. This remote role requires expertise in cloud security and automation, with responsibilities including architecting security...SeniorRemote work
- ...A fast-growing fintech company in the U.S. is seeking a Senior Security Engineer to enhance security within their innovative platform. This remote role involves leading security initiatives across application and cloud environments, conducting vulnerability assessments...SeniorRemote work
$230k - $240k
...performed remotely from anywhere within the United States. The Security Engineering team at Fullstory ensures that engineering teams across the... ...strategy and mentorship. Enable our partners, such as Security GRC and Legal, in supporting business outcomes. Create “paved...SeniorFull timeWork at officeRemote workFlexible hours1 day per week- ...Senior Security Engineer, Security Incident Response Team (SIRT) Remote, US GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance...SeniorRemote work
- ...Overstory is looking for a talented Senior Security Engineer to enhance the company's security and compliance posture. The ideal candidate will lead security initiatives across vulnerability management, compliance, and security operations while collaborating with various...SeniorRemote workFlexible hours
- ...services! Job Summary The Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst plays a critical role in ensuring that UGI Utilities... .... Qualifications Bachelor’s degree in Information Security, Risk Management, Computer Science, or related field, required...SeniorFor contractors
- ...A leading restaurant technology provider is seeking a Staff Security Engineer (Blue Team) to act as the technical lead for cybersecurity initiatives. This role involves guiding the Blue Team, enhancing information protection, and managing incident detection and response...SeniorRemote work
$195k - $240k
...Here at Datadog, we think about offensive security a little bit differently. We embrace automation... ...environment, and we expect our offensive engineers to build the tooling that makes that possible. We're looking for a Senior Security Engineer who can execute sophisticated...SeniorWork at office$145k - $155k
...Thrive is seeking a Security Engineer to join their Offensive Security team in the United States. This role involves vulnerability management, penetration testing, and client relationship management. Ideal candidates will possess strong understanding of network protocols...Senior$100k - $160k
...A cybersecurity firm is looking for a Senior/Principal Federal Security Engineer experienced in managing detection, response, and vulnerability issues within Federally regulated environments. The role requires expertise in security technologies and compliance standards...Senior$167.5k - $226.3k
...Senior Security Engineer (AI Security) New York, New York Apply Who We Are At Justworks, you’ll enjoy a welcoming and casual environment, great benefits, wellness program offerings, company retreats, and the ability to interact with and learn from leaders in...SeniorCasual workWork at officeLocal area- ...A rapidly-growing technology company in the United States is seeking a Senior Security Engineer to enhance the security of their SaaS platform and infrastructure. The ideal candidate has a strong background in secure software development, risk assessment, and compliance...SeniorRemote work
$235k - $255k
...WeightWatchers is looking for a Senior Security Engineer - Detection and Response to join their remote team. In this role, you will build and enhance a detection and response program, collaborate with multiple teams to secure infrastructure, and mentor others on security...SeniorRemote work- ...A cybersecurity firm seeks a Senior Security Engineer specializing in Application Security for Agentic AI systems. This role involves conducting security assessments, developing prompt injection techniques, and engaging with clients on AI security concepts. Applicants...SeniorRemote work
- ...A leading data streaming company in the United States is seeking an experienced security engineer to join their infrastructure security engineering team. This role focuses on threat detection and response, collaborating with engineering teams to enhance security across...Senior
- ...A leading technology consulting firm is seeking a Senior Network Security Engineer to join their team in the United States. This role will involve designing, implementing, and supporting vendor network security solutions for enterprise clients. The ideal candidate will...SeniorRemote work
- ...Shield AI is seeking a Senior Cyber Engineer, focusing on endpoint security management in a remote capacity. Key responsibilities include deploying security tooling, enforcing configurations, and collaborating with IT teams for integration. The ideal candidate will possess...SeniorRemote work
$172k - $225.7k
...platform, Snowflake requires a secure-by-design foundation to drive... ...value. The Security Applied Field Engineering (AFE) organization is at the... ...than a bottleneck. As a Senior Security Architect on the Applied... ..., Risk, and Compliance (GRC): Strong background in aligning...SeniorFlexible hours- ...AppOmni Inc. is seeking a Senior SaaS Security Engineer to enhance our platform security by designing detection rules and advancing our understanding of SaaS security models. The role requires 5-8 years of cybersecurity experience, particularly in threat detection and...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer I, GRC. Be the first to apply!
Related searches
- staff security engineer New York, NY
- senior application security engineer New York, NY
- sr information security engineer New York, NY
- security engineering manager New York, NY
- security operations engineer New York, NY
- cloud security engineer New York, NY
- azure security engineer New York, NY
- endpoint security engineer New York, NY
- physical security engineer New York, NY
- systems security engineer New York, NY

