
Staff Security Engineer, GRC
Oscar Health17 days ago
Base Salary
$246k - $287k/yr
Responsibilities
- Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms, including Phase 3 certification readiness, ongoing oversight, audit readiness, and regulator-facing evidence.
- Map CMS EDE and NIST SP 800-53 requirements to technical, operational, and administrative controls across AWS and Azure environments.
- Prepare and manage CMS significant change requests, impact analyses, approval evidence, risk decisions, and implementation readiness.
- Build compliance-as-code patterns, including control automation, policy-as-code, infrastructure-as-code guardrails, continuous evidence collection, and automated drift detection.
- Own POA&M lifecycle management from issue intake and risk rating through remediation planning, evidence validation, and closure readiness.
- Perform cloud, platform-change, integration, third-party, and security-exception risk assessments.
- Build repeatable evidence workflows for CMS audits, independent assessments, internal reviews, and assurance requests.
- Partner with engineering, security, product, compliance, legal, and business leaders to translate regulatory requirements into practical technical plans.
Requirements
- 7+ years of combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments.
- Deep working knowledge of CMS Enhanced Direct Enrollment requirements and experience supporting or leading Phase 3 certification activities.
- Strong knowledge of NIST SP 800-53 controls and their application to cloud-hosted healthcare platforms.
- Hands-on experience partnering with engineering teams to implement AWS controls using infrastructure as code, policy as code, automated evidence collection, or similar compliance automation.
- Experience preparing CMS significant change requests, security impact analyses, POA&Ms, audit evidence, control narratives, risk acceptances, and remediation plans.
- Ability to communicate regulatory and control requirements to technical and non-technical audiences, including senior leaders and external assessors.
- Bachelor’s degree or equivalent experience is preferred.
- Experience in healthcare, health insurance, marketplace exchange, or another highly regulated technology environment is preferred.
- Experience with CMS EDE Phase 3 certification, annual CMS audits, independent security assessments, regulator-facing reviews, GRC platforms, cloud security posture management, SIEM or evidence pipelines, configuration management, or automated control monitoring is preferred.
- Relevant certifications such as CISSP, CISA, CRISC, CCSP, or AWS Security Specialty are preferred.
Benefits
- Hybrid schedule based in the New York City office with three in-office days per week, including required Thursdays.
- Base benefits include medical, dental, and vision coverage, 11 paid holidays, paid sick time, paid parental leave, 401(k) participation, life and disability insurance, and paid wellness time and reimbursements.
- Unlimited vacation program, employee equity grants, and annual performance bonuses are available.
About Oscar Health
Oscar Health is a leading healthcare technology company, whose mission is to make a healthier life accessible and affordable for all.