Staff Security Engineer, GRC
at Oscar Health
- Seniority
- Staff Principal
- Work model
- Hybrid
- Location
- New York, New York, United States
- Posted
- 5d ago
at Oscar Health
<p>Hi, we're Oscar. We're hiring a Staff Security Engineer, GRC to join our Information Security Team.</p> <p>Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the kind of health insurance company we would want for ourselves—one that behaves like a doctor in the family.</p> <p><strong>About the role:</strong></p> <p>As a Staff GRC Engineer, you will be a cloud-aware governance, risk, and compliance expert supporting Oscar's healthcare technology environment, with a specific focus on CMS Enhanced Direct Enrollment (EDE) platforms and stage 3 certification readiness. You will translate CMS EDE requirements, FedRAMP Moderate-aligned expectations, and NIST SP 800-53 controls into practical control designs, compliance-as-code patterns, evidence workflows, and risk management practices for AWS-hosted and Azure-hosted systems. You will operate as a senior subject matter expert who can partner directly with engineering, security, legal, compliance, product, and CMS-facing stakeholders to keep regulated platforms audit-ready while enabling secure delivery.</p> <p>You will report into the CISO.</p> <p><strong>Work Location: </strong>This position is based in our New York City office, requiring a hybrid work schedule with 3 days of in-office work per week. Thursdays are a required in-office day for team meetings and events, while your other two office days are flexible to suit your schedule. #LI-Hybrid</p> <p><strong>Pay Transparency: </strong>The base pay for this role is: $245,916 - $286,902 per year You are also eligible for employee benefits, participation in Oscar's unlimited vacation program, company equity grants, and annual performance bonuses.</p> <p><strong>Responsibilities:</strong></p> <ul> <li><strong>CMS EDE Governance:</strong> Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms, with a focus on Phase 3 certification expectations, ongoing oversight, audit readiness, and regulator-facing evidence.</li> <li><strong>Control Architecture:</strong> Map CMS EDE and NIST SP 800-53 requirements to technical, operational, and administrative controls that can be implemented and measured across AWS and Azure environments.</li> <li><strong>Significant Change Management:</strong> Prepare, review, and submit CMS significant change requests, partner with technical teams on impact analysis, and maintain clear evidence of approval status, risk decisions, and implementation readiness.</li> <li><strong>Compliance as Code:</strong> Build and mature compliance-as-code patterns for AWS, including control automation, policy-as-code, infrastructure-as-code guardrails, continuous evidence collection, and automated drift detection.</li> <li><strong>POA&M Management:</strong> Own POA&M lifecycle management, including issue intake, risk rating, remediation planning, dependency tracking, stakeholder reporting, evidence validation, and closure readiness.</li> <li><strong>Risk Assessment and Advisory:</strong> Perform risk assessments for cloud services, EDE platform changes, system integrations, third-party dependencies, and security exceptions using healthcare and federal control expectations.</li> <li><strong>Audit and Evidence Operations:</strong> Build repeatable evidence workflows for CMS audits, independent assessments, internal reviews, and customer or partner assurance requests.</li> <li><strong>Cross-Functional Leadership:</strong> Serve as a trusted GRC partner to engineering, security, product, compliance, legal, and business leaders, translating regulatory requirements into practical technical plans.</li> <li>Compliance with all applicable laws and regulations</li> <li>Other duties as assigned</li> </ul> <p><strong>Requirements:</strong></p> <ul> <li>7+ years of combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments.</li> <li>Deep working knowledge of CMS Enhanced Direct Enrollment requirements, including the ability to support or lead Phase 3 certification activities.</li> <li>Strong knowledge of NIST SP 800-53 controls control expectations, including how those controls map to cloud-hosted healthcare platforms.</li> <li>Hands-on experience partnering with engineering teams to implement controls in AWS using infrastructure as code, policy as code, automated evidence collection, or similar compliance automation approaches.</li> <li>Experience preparing CMS significant change requests, security impact analyses, POA&Ms, audit evidence, control narratives, risk acceptances, and remediation plans.</li> <li>Ability to communicate regulatory and control requirements clearly to technical and non-technical audiences, including senior leaders and external assessors.</li> </ul> <p><strong>Bonus points:</strong></p> <ul> <li>Bachelor's degree or years of equivalent experience.</li> <li>Prior work experience in healthcare, health insurance, marketplace exchange, or other highly regulated technology environments.</li> <li>Experience supporting CMS EDE Phase 3 certification, annual CMS audits, independent security assessments, or regulator-facing security reviews.</li> <li>Experience with GRC platforms, cloud security posture management, SIEM/evidence pipelines, configuration management, or automated control monitoring.</li> <li>Relevant security, audit, or cloud certifications such as CISSP, CISA, CRISC, CCSP, AWS Security Specialty, or equivalent practical experience.</li> </ul><div class="content-conclusion"><p><span style="font-weight: 400;">This is an authentic Oscar Health job opportunity. Learn more about how you can safeguard yourself from recruitment fraud</span><a href="http://hioscar.com/careers/recruitment-fraud-alert"><span style="font-weight: 400;"> </span><span style="font-weight: 400;">here</span></a><span style="font-weight: 400;">. </span></p> <