Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Engineer, GRC

$245.92k - $286.9k

Oscar Health Insurance

Hi, we're Oscar. We're hiring a Staff Security Engineer, GRC to join our Information Security Team.Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the kind of health insurance company we would want for ourselves—one that behaves like a doctor in the family.About the role:As a Staff GRC Engineer, you will be a cloud-aware governance, risk, and compliance expert supporting Oscar's healthcare technology environment, with a specific focus on CMS Enhanced Direct Enrollment (EDE) platforms and stage 3 certification readiness. You will translate CMS EDE requirements, FedRAMP Moderate-aligned expectations, and NIST SP 800-53 controls into practical control designs, compliance-as-code patterns, evidence workflows, and risk management practices for AWS-hosted and Azure-hosted systems. You will operate as a senior subject matter expert who can partner directly with engineering, security, legal, compliance, product, and CMS-facing stakeholders to keep regulated platforms audit-ready while enabling secure delivery.You will report into the CISO.Work Location: This position is based in our New York City office, requiring a hybrid work schedule with 3 days of in-office work per week. Thursdays are a required in-office day for team meetings and events, while your other two office days are flexible to suit your schedule. #LI-HybridPay Transparency: The base pay for this role is: $245,916 - $286,902 per year You are also eligible for employee benefits, participation in Oscar's unlimited vacation program, company equity grants, and annual performance bonuses.Responsibilities:CMS EDE Governance: Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms, with a focus on Phase 3 certification expectations, ongoing oversight, audit readiness, and regulator-facing evidence.Control Architecture: Map CMS EDE and NIST SP 800-53 requirements to technical, operational, and administrative controls that can be implemented and measured across AWS and Azure environments.Significant Change Management: Prepare, review, and submit CMS significant change requests, partner with technical teams on impact analysis, and maintain clear evidence of approval status, risk decisions, and implementation readiness.Compliance as Code: Build and mature compliance-as-code patterns for AWS, including control automation, policy-as-code, infrastructure-as-code guardrails, continuous evidence collection, and automated drift detection.POA&M Management: Own POA&M lifecycle management, including issue intake, risk rating, remediation planning, dependency tracking, stakeholder reporting, evidence validation, and closure readiness.Risk Assessment and Advisory: Perform risk assessments for cloud services, EDE platform changes, system integrations, third-party dependencies, and security exceptions using healthcare and federal control expectations.Audit and Evidence Operations: Build repeatable evidence workflows for CMS audits, independent assessments, internal reviews, and customer or partner assurance requests.Cross-Functional Leadership: Serve as a trusted GRC partner to engineering, security, product, compliance, legal, and business leaders, translating regulatory requirements into practical technical plans.Compliance with all applicable laws and regulationsOther duties as assignedRequirements:7+ years of combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments.Deep working knowledge of CMS Enhanced Direct Enrollment requirements, including the ability to support or lead Phase 3 certification activities.Strong knowledge of NIST SP 800-53 controls control expectations, including how those controls map to cloud-hosted healthcare platforms.Hands-on experience partnering with engineering teams to implement controls in AWS using infrastructure as code, policy as code, automated evidence collection, or similar compliance automation approaches.Experience preparing CMS significant change requests, security impact analyses, POA&Ms, audit evidence, control narratives, risk acceptances, and remediation plans.Ability to communicate regulatory and control requirements clearly to technical and non-technical audiences, including senior leaders and external assessors.Bonus points:Bachelor's degree or years of equivalent experience.Prior work experience in healthcare, health insurance, marketplace exchange, or other highly regulated technology environments.Experience supporting CMS EDE Phase 3 certification, annual CMS audits, independent security assessments, or regulator-facing security reviews.Experience with GRC platforms, cloud security posture management, SIEM/evidence pipelines, configuration management, or automated control monitoring.Relevant security, audit, or cloud certifications such as CISSP, CISA, CRISC, CCSP, AWS Security Specialty, or equivalent practical experience.This is an authentic Oscar Health job opportunity. Learn more about how you can safeguard yourself from recruitment fraud here. At Oscar, being an Equal Opportunity Employer means more than upholding discrimination-free hiring practices. It means that we cultivate an environment where people can be their most authentic selves and find both belonging and support. We're on a mission to change health care -- an experience made whole by our unique backgrounds and perspectives.Pay Transparency: Final offer amounts, within the base pay set forth above, are determined by factors including your relevant skills, education, and experience. Full-time employees are eligible for benefits including: medical, dental, and vision benefits, 11 paid holidays, paid sick time, paid parental leave, 401(k) plan participation, life and disability insurance, and paid wellness time and reimbursements.Artificial Intelligence (AI): Our AI Guidelines outline the acceptable use of artificial intelligence for candidates and detail how we use AI to support our recruiting efforts.Reasonable Accommodation: Oscar applicants are considered solely based on their qualifications, without regard to applicant’s disability or need for accommodation. Any Oscar applicant who requires reasonable accommodations during the application process should contact the Oscar Benefits Team (View email address on click.appcast.io) to make the need for an accommodation known.California Residents: For information about our collection, use, and disclosure of applicants’ personal information as well as applicants’ rights over their personal information, please see our Privacy Policy.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer, GRC in New York, NY vacancy
  • $152k - $258k

     ...Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who...  ...seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI... 
    Suggested
    Permanent employment
    Temporary work

    X

    New York, NY
    2 days ago
  • $152k - $258k

     ...small, highly motivated, and focused on engineering excellence. This organization is for individuals...  ...Governance, Risk, and Compliance (GRC) Engineer focused on fintech and...  ...— prioritize issues that represent real security or business risk over checkbox compliance... 
    Suggested
    Permanent employment
    Temporary work

    X

    New York, NY
    2 days ago
  • $188k - $275k

     ...7, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at .What You’ll Do:We are seeking a Staff Security Engineer to lead the most complex technical work in CoreWeave’s Vulnerability Management program. You will design and implement scalable... 
    Suggested
    Permanent employment
    Full time
    Temporary work
    Casual work
    Work at office
    Flexible hours

    CoreWeave

    New York, NY
    4 days ago
  • $169k - $199k

     ...standards, clear accountability, and a strong focus on security and ethics in everything we build!The Red Team’s mission...  ...simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across applications... 
    Suggested
    Work at office
    Shift work
    3 days per week

    Robinhood Financial

    New York, NY
    4 days ago
  • $190k - $230k

     ...About Nscale Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-...  ...About the Role We are seeking a Staff Security Engineer, Product and Platform Security...  ...tooling, SIEM platforms, EDR tools, and GRC systems. ~ Experience with responsible... 
    Suggested
    Full time
    Flexible hours

    Nscale

    New York, NY
    4 days ago
  • $180k - $247k

    Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of AI. Okta secures AI by building...  ...We're building a world where Identity belongs to you.The Staff Product Security Engineer OpportunityThe Security team's mission is to strengthen Okta... 
    Local area
    Worldwide
    Flexible hours

    Okta

    New York, NY
    4 days ago
  •  ...that all official communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security... 
    Work at office
    Relocation
    3 days per week
    1 day per week

    Rippling

    New York, NY
    1 day ago
  • $224k - $300k

     ...your impact and unlock incredible career growth opportunities, join us, and build real world value. THE WORK: As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest technical expert at the intersection of artificial intelligence and security... 
    Full time
    Work at office
    Local area

    P2P

    New York, NY
    2 days ago
  • $180k - $247.5k

    Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of AI. Okta secures AI by building the...  ...'re all in on this mission. If you are too, let's talk.The Staff AI Security Engineer OpportunityIdentity is the key to unlocking the potential of... 
    Local area
    Worldwide
    Flexible hours

    Okta

    New York, NY
    4 days ago
  • $244k - $305k

    As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach application security at scale. You'll define the frameworks, methodologies, and architectural patterns that engineering teams across Datadog adopt and apply independently... 

    Datadog

    New York, NY
    1 day ago
  • $200k - $220k

     ...they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our...  ...easier to use. You'll partner closely with IT, Infrastructure, GRC, and Detection & Response to improve the security foundations... 
    Work at office
    Local area

    Notion Labs

    New York, NY
    4 days ago
  • $120k - $145k

     ...content reflecting our world. Job Description Role Overview NBCUniversal is seeking a Staff Cyber Systems Engineer to build and scale modern application security capabilities across the enterprise. This hands-on role within Software Security Services... 
    Full time
    Local area
    Remote work

    NBCUniversal

    New York, NY
    25 days ago
  •  ...Corporate Security Engineer Millions of people rely on Notion to do their most important work. Protecting that trust starts with protecting...  ...easier to use. You'll partner closely with IT, Infrastructure, GRC, and Detection & Response to improve the security foundations... 
    Local area

    Notion, LLC

    New York, NY
    5 days ago
  • Profound is hiring a Security GRC Specialist to own and scale our security and compliance programs, partnering with engineering, sales, and customer success. This role drives the lifecycle of audits, frameworks, and automation to accelerate deals and protect customer trust... 

    Slope

    New York, NY
    2 days ago
  •  ...Responsibilities Drive Ripple’s AI Security technical strategy and roadmap across AI systems, agentic workflows, and the AI development...  ...AI security. Requirements ~10+ years of Security Engineering experience with depth in at least two domains such as Product... 
    Full time
    Work at office

    Ripple

    New York, NY
    15 days ago
  • $130k

    About the roleWe are looking for a versatile Security Software Engineer to join our team and operate across product security, application security...  ...)Pen testing or bug bounty experienceFamiliarity with GRC tools and frameworks#LI-Hybrid #LI-JL1A little about usAt Chime... 
    Full time
    Work at office
    Local area
    Remote work

    Chime

    New York, NY
    1 day ago
  •  ...posture, advance toward CMMC readiness, and bridge compliance with engineering and delivery. You will influence architecture, automate policy...  ...sales with pristine evidence. You will partner across IT, Security, Product, and Delivery to bake in compliance by design,... 

    Socket

    New York, NY
    2 days ago
  • $237.6k - $297k

    We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Full time

    Scale AI

    New York, NY
    4 days ago
  • $175.1k - $236.9k

     ...checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Senior Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services... 
    Internship
    Flexible hours

    Amazon

    New York, NY
    3 days ago
  • $174k - $252k

    Identify security issues and implement and design security controls, tools, and services to improve security systems and processes.Drive...  ...or threat modeling.5 years of experience with security engineering, computer and network security and security protocols.5 years... 

    Google

    New York, NY
    1 day ago
  • $167.5k - $226.3k

     ...team.Our ValuesIf this sounds like you, you’ll fit right in.Who You AreJustworks is looking for an experienced, hands-on Senior Security Engineer specializing in AI who will drive and execute the company’s AI strategy and Digital Security’s objectives. Our ideal candidate... 
    Casual work
    Work at office
    Local area

    Justworks

    New York, NY
    4 days ago
  • $159.3k - $212.8k

     ...to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services... 
    Internship
    Flexible hours

    Amazon

    New York, NY
    1 day ago
  • $159.3k - $212.8k

    The ideal candidate will have a broad understanding of proactive security, have past experience leading security assessments, and have the ability to work with product and engineering teams in designing secure systems. In this role, you will conduct secure design reviews... 
    Internship
    Flexible hours

    Amazon

    New York, NY
    4 days ago
  • $147k - $210k

     ...) tooling to scale advanced vulnerability research, defensive engineering, and mitigation strategies across the organization.Participate...  ...into our VRP pipeline to improve efficiency.Conduct deep-dive security research into Android vulnerabilities and threat vectors, converting... 

    Google

    New York, NY
    3 days ago
  • $165k - $242k

     ...CRWV) in March 2025. Learn more at .What You’ll Do:The Enterprise Security team at CoreWeave is responsible for securing how our people...  ..., this is the team to join.About the Role:As a Senior Security Engineer, Enterprise Security, you’ll design and ship the security controls... 
    Permanent employment
    Full time
    Temporary work
    For contractors
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    New York, NY
    4 days ago
  • $195k - $240k

    Here at Datadog, we think about offensive security a little bit differently. We embrace automation and AI to run adversary simulations...  ...massive cloud-native environment, and we expect our offensive engineers to build the tooling that makes that possible. We're looking... 
    Work at office

    Datadog

    New York, NY
    4 days ago
  • $159.3k - $212.8k

    The AWS Security Hub team is looking for a passionate and innovative security engineer with a focus on compliance and security best practices for AWS, Azure, and GCP services. AWS Security Hub is the security and compliance center for AWS customers. One of its main functions... 
    Internship
    Flexible hours

    Amazon

    New York, NY
    4 days ago
  •  ...Principal Security Engineer FTAI owns and maintains commercial jet engines with a focus on the Maintenance, Repair and Exchange (MRE) of CFM...  ...-party/vendor risk program, coordinating with internal audit/GRC and the legal team Collaborate with MSP and vCISO (managing... 

    FTAI Aviation

    New York, NY
    5 days ago
  • $152.5k - $205k

     ...encouraged and everyone is a stakeholder.What you'll be responsible for:Circle is seeking a hands-on and technically sharp Senior Security Engineer, Executive & Endpoint Security to contribute to Circle’s security program while serving as the primary on-site technical... 
    Contract work
    Work at office
    Local area
    Remote work
    Flexible hours

    Circle

    New York, NY
    4 days ago
  • A leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves collaboration with various departments to implement governance and risk management processes. The ideal candidate has... 

    UGI Utilities, Inc.

    New York, NY
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Engineer, GRC. Be the first to apply!