Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Engineer, GRC

$245.92k - $286.9k

Oscar Health Insurance

Hi, we're Oscar. We're hiring a Staff Security Engineer, GRC to join our Information Security Team.Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the kind of health insurance company we would want for ourselves—one that behaves like a doctor in the family.About the role:As a Staff GRC Engineer, you will be a cloud-aware governance, risk, and compliance expert supporting Oscar's healthcare technology environment, with a specific focus on CMS Enhanced Direct Enrollment (EDE) platforms and stage 3 certification readiness. You will translate CMS EDE requirements, FedRAMP Moderate-aligned expectations, and NIST SP 800-53 controls into practical control designs, compliance-as-code patterns, evidence workflows, and risk management practices for AWS-hosted and Azure-hosted systems. You will operate as a senior subject matter expert who can partner directly with engineering, security, legal, compliance, product, and CMS-facing stakeholders to keep regulated platforms audit-ready while enabling secure delivery.You will report into the CISO.Work Location: This position is based in our New York City office, requiring a hybrid work schedule with 3 days of in-office work per week. Thursdays are a required in-office day for team meetings and events, while your other two office days are flexible to suit your schedule. #LI-HybridPay Transparency: The base pay for this role is: $245,916 - $286,902 per year You are also eligible for employee benefits, participation in Oscar's unlimited vacation program, company equity grants, and annual performance bonuses.Responsibilities:CMS EDE Governance: Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms, with a focus on Phase 3 certification expectations, ongoing oversight, audit readiness, and regulator-facing evidence.Control Architecture: Map CMS EDE and NIST SP 800-53 requirements to technical, operational, and administrative controls that can be implemented and measured across AWS and Azure environments.Significant Change Management: Prepare, review, and submit CMS significant change requests, partner with technical teams on impact analysis, and maintain clear evidence of approval status, risk decisions, and implementation readiness.Compliance as Code: Build and mature compliance-as-code patterns for AWS, including control automation, policy-as-code, infrastructure-as-code guardrails, continuous evidence collection, and automated drift detection.POA&M Management: Own POA&M lifecycle management, including issue intake, risk rating, remediation planning, dependency tracking, stakeholder reporting, evidence validation, and closure readiness.Risk Assessment and Advisory: Perform risk assessments for cloud services, EDE platform changes, system integrations, third-party dependencies, and security exceptions using healthcare and federal control expectations.Audit and Evidence Operations: Build repeatable evidence workflows for CMS audits, independent assessments, internal reviews, and customer or partner assurance requests.Cross-Functional Leadership: Serve as a trusted GRC partner to engineering, security, product, compliance, legal, and business leaders, translating regulatory requirements into practical technical plans.Compliance with all applicable laws and regulationsOther duties as assignedRequirements:7+ years of combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments.Deep working knowledge of CMS Enhanced Direct Enrollment requirements, including the ability to support or lead Phase 3 certification activities.Strong knowledge of NIST SP 800-53 controls control expectations, including how those controls map to cloud-hosted healthcare platforms.Hands-on experience partnering with engineering teams to implement controls in AWS using infrastructure as code, policy as code, automated evidence collection, or similar compliance automation approaches.Experience preparing CMS significant change requests, security impact analyses, POA&Ms, audit evidence, control narratives, risk acceptances, and remediation plans.Ability to communicate regulatory and control requirements clearly to technical and non-technical audiences, including senior leaders and external assessors.Bonus points:Bachelor's degree or years of equivalent experience.Prior work experience in healthcare, health insurance, marketplace exchange, or other highly regulated technology environments.Experience supporting CMS EDE Phase 3 certification, annual CMS audits, independent security assessments, or regulator-facing security reviews.Experience with GRC platforms, cloud security posture management, SIEM/evidence pipelines, configuration management, or automated control monitoring.Relevant security, audit, or cloud certifications such as CISSP, CISA, CRISC, CCSP, AWS Security Specialty, or equivalent practical experience.This is an authentic Oscar Health job opportunity.At Oscar, being an Equal Opportunity Employer means more than upholding discrimination-free hiring practices. It means that we cultivate an environment where people can be their most authentic selves and find both belonging and support. We're on a mission to change health care -- an experience made whole by our unique backgrounds and perspectives.Pay Transparency: Final offer amounts, within the base pay set forth above, are determined by factors including your relevant skills, education, and experience. Full-time employees are eligible for benefits including: medical, dental, and vision benefits, 11 paid holidays, paid sick time, paid parental leave, 401(k) plan participation, life and disability insurance, and paid wellness time and reimbursements.Artificial Intelligence (AI): Our AI Guidelines outline the acceptable use of artificial intelligence for candidates and detail how we use AI to support our recruiting efforts.Reasonable Accommodation: Oscar applicants are considered solely based on their qualifications, without regard to applicant’s disability or need for accommodation. Any Oscar applicant who requires reasonable accommodations during the application process should contact the Oscar Benefits Team (View email address on click.appcast.io) to make the need for an accommodation known.California Residents: For information about our collection, use, and disclosure of applicants’ personal information as well as applicants’ rights over their personal information, please see our Privacy Policy.

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer, GRC in New York, NY vacancy
  • $247k - $290k

     ...Expectations are high, and so are the rewards.Robinhood's Security Operations team operates across two distinct disciplines: proactive...  ..., and outmaneuver agentic attackers — and we need a Senior Staff Security Engineer to help us build them.As a Senior Staff Security Engineer,... 
    Suggested
    Work at office
    Flexible hours
    Shift work
    3 days per week

    Robinhood Financial

    New York, NY
    17 hours ago
  •  ...Security GRC Engineer Engineering · Full-time · San Francisco; New York Our mission is to automate coding. The first step in our journey is to build the best tool for professional programmers, using a combination of inventive research, design, and engineering. Our... 
    Suggested
    Full time

    Anysphere

    New York, NY
    2 days ago
  •  ...Staff Security Engineer – Digital Assets Locations: San Francisco, CA OR New York, NY We’re working with a leading global financial technology company that is building infrastructure for a world where value can move as easily as information does today. As digital... 
    Suggested
    Remote work

    Iceberg

    New York, NY
    2 days ago
  •  ...I’m currently working with a leading global quantitative investment firm that is looking to add a Staff Security Engineer to its growing Platform Security team in New York. You’ll be working across cloud and on-prem infrastructure, helping design secure platforms for... 
    Suggested
    Full time

    NJF Global Holdings Ltd

    New York, NY
    2 hours ago
  • $169k - $199k

     ...standards, clear accountability, and a strong focus on security and ethics in everything we build!The Red Team’s mission...  ...simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across applications... 
    Suggested
    Work at office
    Shift work
    3 days per week

    Robinhood Financial

    New York, NY
    2 days ago
  • $161k - $221k

    Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of...  ...customers’ trust. The Defensive Cyber Engineering organization is responsible for the Security...  ...’s Public Sector roadmap by hiring a Staff Software Engineer in the DC area. You’ll... 
    Local area
    Worldwide
    Flexible hours

    Okta

    New York, NY
    2 days ago
  • $210k - $234k

     ...to deliver exceptional service to seller and buyer clients. Engineering @ Compass Compass has built the first modern end-to-end...  ...and the operating platform that will transform real estate. Security @ Compass We are hands-on security engineers helping to build... 
    Minimum wage
    Flexible hours

    Jobleads-US

    New York, NY
    5 days ago
  • Second Sight Solutions, a subsidiary of Berkeley Research Group (BRG), is seeking a Security Engineer (Compliance) to join our Security team. You will own and implement key GRC programs, drive policies, and support annual audits in a primarily remote role with on-site... 
    Remote job

    Brg Corp

    New York, NY
    1 day ago
  •  ...that all official communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security... 
    Work at office
    Relocation
    3 days per week
    1 day per week

    Rippling

    New York, NY
    4 days ago
  • $168.2k - $310.1k

    The OpportunityAt Adobe, securing the future of creativity is our mission. Our customers rely on our products every day to...  ...products and platforms our customers depend on.We seek a Staff Product Security Engineer to act as a Security Partner for our most valuable products... 
    Full time
    Temporary work
    Local area
    Worldwide

    Adobe Systems

    New York, NY
    3 days ago
  •  ...Nscale is hiring a Staff Security Engineer - Network Security to define and implement network security patterns across corporate, OT/BMS, production, and customer networks. You will work with data centers, offices, and production management networks to establish trust... 
    Work at office

    Jobleads-US

    New York, NY
    6 days ago
  • $190k - $225k

     ...Staff Security Engineer, Threat Intelligence Houston; New York; San Francisco; Seattle About Nscale Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables... 
    Flexible hours

    Jobleads-US

    New York, NY
    2 days ago
  •  ...WRITER is hiring a staff-level Security engineer to build AI-focused detection and automated response for threats targeting the AI platform, training data, and model deployments. You will design detections for AI threats, automate responses, and coordinate incident handling... 

    Jobleads-US

    New York, NY
    6 days ago
  • Lead threat modeling and security architecture for AI-enabled systems, including LLM applications and cloud-native platforms. Define and implement secure engineering patterns and guardrails across AWS infrastructure, CI/CD pipelines, and third-party integrations. Partner... 
    Remote job

    Quanata, LLC

    New York, NY
    1 day ago
  • Seeking a highly-skilled Staff Security Engineer to work remotely, who will manage the security and integrity of applications and software systems, build a vulnerability management pipeline, and execute the application security program while collaborating closely with engineering... 
    Remote work

    Virtual Vocations Inc

    New York, NY
    4 days ago
  • $155.52k - $194.4k

     ...for team gatherings, functional off-sites or customer meetings. See yourself at Twilio Join the team as Twilio’s next Staff AI Security Engineer, Threat Hunting About the job The Threat Detection and Response team is looking for a Senior Security Engineer who is passionate... 
    Remote job
    Local area
    Worldwide

    Twilio

    New York, NY
    6 days ago
  •  ...Requirements ~8+ years of experience in product security, application security, offensive security, and/or security-focused software engineering ~ Long track record of identifying and...  ...What the job involves As a Staff Software Engineer on the Product Security... 
    Work experience placement

    Harvey

    New York, NY
    2 days ago
  •  ...I’m looking for an experienced security engineer who knows what it’s like to operate in a small security team with a very large technical footprint...  ...Security Engineer, an early security hire at a startup, or a Staff/Principal-level engineer in a small team where you couldn’t... 

    Iceberg

    New York, NY
    2 hours ago
  • $160k - $190k

     ...Staff Security Engineer, Network Security Houston; New York; San Francisco; Seattle About Nscale Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables... 
    Work at office
    Local area
    Remote work
    Flexible hours

    Jobleads-US

    New York, NY
    6 days ago
  • $244k - $305k

    As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and apply independently... 

    Datadog

    New York, NY
    4 days ago
  • Working remotely, the full-time salaried Staff Product Security Engineer will perform security assessments, develop security features for hardware and software products, and collaborate with cross-functional teams to ensure product security throughout the lifecycle. Key... 
    Full time
    Work experience placement
    Remote work

    Virtual Vocations Inc

    New York, NY
    4 days ago
  • Mysten Labs, Inc. is seeking a Staff Security Engineer to partner with the Walrus team, driving deep architectural security guidance across the lifecycle from design to deployment. You will lead assessments, foster a security-first culture, and apply AI-driven automation... 
    Remote job

    Mysten Labs, Inc.

    New York, NY
    5 days ago
  • $165.2k - $295k

     ...thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end, spanning cloud...  ...firmware running on IoT hardware in the field. As a Staff Application Security Engineer, you’ll drive the overarching technical direction for... 
    Remote work
    Flexible hours
    Shift work

    Samsara

    New York, NY
    5 days ago
  • $200k - $220k

     ...they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our...  ...easier to use. You'll partner closely with IT, Infrastructure, GRC, and Detection & Response to improve the security foundations... 
    Work at office
    Local area

    Notion Labs

    New York, NY
    2 days ago
  •  ...management of our SIEM solution. You will develop alerts to respond to security incidents across multiple layers. Security Analysis & Reviews:...  ...your messaging across teams to move security work forward. Engine Engine is the AI-native platform for intelligent travel,... 
    Remote job

    engine

    New York, NY
    2 days ago
  • Focusing on the strategy, development, implementation, and maintenance of the application security program, the full-time remote Staff Application Security Engineer will advise on secure product design, perform security reviews and testing, and collaborate with engineering... 
    Full time
    Remote work

    Virtual Vocations Inc

    New York, NY
    4 days ago
  • A leading healthcare technology company in the U.S. seeks a Staff Cloud Security Engineer to enhance security controls across cloud environments, primarily AWS. This hands-on position involves designing advanced security solutions through code, leading automation efforts... 
    Remote job

    Included Health

    New York, NY
    4 days ago
  • Fyerx seeks an experienced GRC Consultant to design, evaluate, and monitor our cybersecurity governance and risk management frameworks...  ...across ISO 27001, SOC 2, GDPR, HIPAA, and NIST, and mentor junior staff while reporting to senior stakeholders in #J-18808-Ljbffr Zoho
    Remote job

    Zoho

    New York, NY
    1 day ago
  • $221k - $299k

     ...does happen. You'll join a team that includes an AppSec-focused engineer and an infrastructure-focused engineer, and you'll guide...  ...broader process or control change. Partner with our Product Security Engineer on golden paths when a weakness points to a systemic gap... 
    Remote job
    Full time
    Contract work
    Work at office
    Immediate start
    Flexible hours
    3 days per week

    NextGen

    New York, NY
    11 days ago
  • $258k - $310k

     ...the U.S. — and using AI to scale that impact further and faster than anyone else can. About the role: We are seeking a Staff Security Engineer to serve as a technical anchor for our security function. This role is critical for leading technical design reviews and ensuring... 
    Remote work
    Flexible hours

    Garner Health

    New York, NY
    21 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Engineer, GRC. Be the first to apply!