Jobs Companies Oscar Health Staff Security Engineer, GRC

About this Staff Security Engineer, GRC role at Oscar Health

Oscar Health · Onsite · New York, New York, United States

Hi, we're Oscar. We're hiring a Staff Security Engineer, GRC to join our Information Security Team.

Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the kind of health insurance company we would want for ourselves—one that behaves like a doctor in the family.

About the role:

As a Staff GRC Engineer, you will be a cloud-aware governance, risk, and compliance expert supporting Oscar's healthcare technology environment, with a specific focus on CMS Enhanced Direct Enrollment (EDE) platforms and stage 3 certification readiness. You will translate CMS EDE requirements, FedRAMP Moderate-aligned expectations, and NIST SP 800-53 controls into practical control designs, compliance-as-code patterns, evidence workflows, and risk management practices for AWS-hosted and Azure-hosted systems. You will operate as a senior subject matter expert who can partner directly with engineering, security, legal, compliance, product, and CMS-facing stakeholders to keep regulated platforms audit-ready while enabling secure delivery.

You will report into the CISO.

Work Location: This position is based in our New York City office, requiring a hybrid work schedule with 3 days of in-office work per week. Thursdays are a required in-office day for team meetings and events, while your other two office days are flexible to suit your schedule. #LI-Hybrid

Pay Transparency: The base pay for this role is: $245,916 - $286,902 per year You are also eligible for employee benefits,  participation in Oscar's unlimited vacation program, company equity grants, and annual performance bonuses.

Responsibilities:

  • CMS EDE Governance: Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms, with a focus on Phase 3 certification expectations, ongoing oversight, audit readiness, and regulator-facing evidence.
  • Control Architecture: Map CMS EDE and NIST SP 800-53 requirements to technical, operational, and administrative controls that can be implemented and measured across AWS and Azure environments.
  • Significant Change Management: Prepare, review, and submit CMS significant change requests, partner with technical teams on impact analysis, and maintain clear evidence of approval status, risk decisions, and implementation readiness.
  • Compliance as Code: Build and mature compliance-as-code patterns for AWS, including control automation, policy-as-code, infrastructure-as-code guardrails, continuous evidence collection, and automated drift detection.
  • POA&M Management: Own POA&M lifecycle management, including issue intake, risk rating, remediation planning, dependency tracking, stakeholder reporting, evidence validation, and closure readiness.
  • Risk Assessment and Advisory: Perform risk assessments for cloud services, EDE platform changes, system integrations, third-party dependencies, and security exceptions using healthcare and federal control expectations.
  • Audit and Evidence Operations: Build repeatable evidence workflows for CMS audits, independent assessments, internal reviews, and customer or partner assurance requests.
  • Cross-Functional Leadership: Serve as a trusted GRC partner to engineering, security, product, compliance, legal, and business leaders, translating regulatory requirements into practical technical plans.
  • Compliance with all applicable laws and regulations
  • Other duties as assigned

Requirements:

  • 7+ years of combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments.
  • Deep working knowledge of CMS Enhanced Direct Enrollment requirements, including the ability to support or lead Phase 3 certification activities.
  • Strong knowledge of NIST SP 800-53 controls control expectations, including how those controls map to cloud-hosted healthcare platforms.
  • Hands-on experience partnering with engineering teams to implement controls in AWS using infrastructure as code, policy as code, automated evidence collection, or similar compliance automation approaches.
  • Experience preparing CMS significant change requests, security impact analyses, POA&Ms, audit evidence, control narratives, risk acceptances, and remediation plans.
  • Ability to communicate regulatory and control requirements clearly to technical and non-technical audiences, including senior leaders and external assessors.

Bonus points:

  • Bachelor's degree or years of equivalent experience.
  • Prior work experience in healthcare, health insurance, marketplace exchange, or other highly regulated technology environments.
  • Experience supporting CMS EDE Phase 3 certification, annual CMS audits, independent security assessments, or regulator-facing security reviews.
  • Experience with GRC platforms, cloud security posture management, SIEM/evidence pipelines, configuration management, or automated control monitoring.
  • Relevant security, audit, or cloud certifications such as CISSP, CISA, CRISC, CCSP, AWS Security Specialty, or equivalent practical experience.

This is an authentic Oscar Health job opportunity. Learn more about how you can safeguard yourself from recruitment fraud here

At Oscar, being an Equal Opportunity Employer means more than upholding discrimination-free hiring practices. It means that we cultivate an environment where people can be their most authentic selves and find both belonging and support. We're on a mission to change health care -- an experience made whole by our unique backgrounds and perspectives.

Pay Transparency:  Final offer amounts, within the base pay set forth above, are determined by factors including your relevant skills, education, and experience. Full-time employees are eligible for benefits including: medical, dental, and vision benefits, 11 paid holidays, paid sick time, paid parental leave, 401(k) plan participation, life and disability insurance, and paid wellness time and reimbursements.

Artificial Intelligence (AI): Our AI Guidelines outline the acceptable use of artificial intelligence for candidates and detail how we use AI to support our recruiting efforts.

Reasonable Accommodation: Oscar applicants are considered solely based on their qualifications, without regard to applicant’s disability or need for accommodation. Any Oscar applicant who requires reasonable accommodations during the application process should contact the Oscar Benefits Team ([email protected]) to make the need for an accommodation known.

California Residents: For information about our collection, use, and disclosure of applicants’ personal information as well as applicants’ rights over their personal information, please see our Privacy Policy.

Ready to apply to Oscar Health?
Apply to Oscar Health

How this Security Engineer salary compares

This role pays $266,409/yrabove the typical range for Security Engineer roles.

$155,000 median $189,560 $264,500

Typical range $164,472–$260,000/yr, from 33 comparable Security Engineer listings on JobsRadar (pay annualized to USD). See Security Engineer salary insights →

About Oscar Health

Health care is broken; we're trying to fix it. The Oscar team is focused on utilizing technology, design and data to humanize health care. We're a group of technology and health care professionals who looked at the current state of the US health care system, got frustrated by the horrible consumer experience, and decided to do something big about it. Backed by a renowned set of investors and advisors, we’ve set out to revolutionize health care.

See all jobs at Oscar Health →

Similar jobs

Ripple
Senior Staff Security Engineer, AI Security
Ripple
⚡ Apply early New York, NY, United States Onsite $224,000–$300,000
● New 👁 Seen ✓ Applied 6h ago
Ripple
Senior Staff Security Engineer, Ripple Treasury
Ripple
⚡ Apply early New York, NY, United States Onsite $224,000–$300,000
● New 👁 Seen ✓ Applied 6h ago
Iterative Health
Cybersecurity Engineer
Iterative Health
⚡ Apply early Cambridge, Massachusetts, Unit... Onsite
● New 👁 Seen ✓ Applied 23h ago
Mercury
Senior Cloud Security Engineer - InfoSec
Mercury
⚡ Apply early San Francisco, CA, New York, N... · location restricted
● New 👁 Seen ✓ Applied 1d ago
Pierce Technology Corp
Cyber Cloud Security Engineer
Pierce Technology Corp
⚡ Apply early New York, New York, United Sta... Onsite
● New 👁 Seen ✓ Applied 1d ago
iCapital
Cyber Cloud Security Engineer - Vice President
iCapital
⚡ Apply early Greenwich, Connecticut, Unite... Onsite $170,000–$200,000
● New 👁 Seen ✓ Applied 2d ago
Code and Theory
Senior Engineer, Security & Compliance (US)
Code and Theory
⚡ Apply early Austin, Texas, United States;... Onsite $110,000–$160,000
● New 👁 Seen ✓ Applied 2d ago
VE
Security Software Engineer, Open Source Frameworks
Vercel
⚡ Apply early Hybrid - San Francisco, New Yo... Hybrid $208,000–$312,000
● New 👁 Seen ✓ Applied 3d ago
VE
Senior Security Software Engineer, v0
Vercel
⚡ Apply early Hybrid - San Francisco, New Yo... Hybrid $208,000–$312,000
● New 👁 Seen ✓ Applied 3d ago

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at Oscar Health

See all jobs at Oscar Health →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free