SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Security Engineer, GRC

Oscar Health - New York, NY, United States - Hybrid - posted 2026-08-20

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 245,916 - 286,902 / annual

Oscar Health is seeking a Staff Security Engineer, GRC to join its Information Security Team, reporting directly to the CISO. This is a senior technical leadership role focused on governance, risk, and compliance for Oscar's healthcare technology platforms, with specific emphasis on CMS Enhanced Direct Enrollment (EDE) systems and Phase 3 certification readiness. In this role, you will serve as a cloud-aware GRC expert translating CMS EDE requirements, FedRAMP Moderate-aligned expectations, and NIST SP 800-53 controls into practical control designs, compliance-as-code patterns, and risk management practices across AWS and Azure environments. You will operate as a senior subject matter expert partnering directly with engineering, security, legal, compliance, product, and CMS-facing stakeholders to maintain audit readiness while enabling secure delivery. Key responsibilities include: leading governance and compliance strategy for CMS EDE platforms with focus on Phase 3 certification and regulator-facing evidence; mapping CMS EDE and NIST requirements to technical, operational, and administrative controls measurable across cloud environments; preparing and submitting CMS significant change requests with impact analysis and evidence tracking; building and maturing compliance-as-code patterns for AWS including control automation, policy-as-code, and infrastructure-as-code guardrails; owning POA&M lifecycle management from intake through closure; performing risk assessments for cloud services, platform changes, integrations, and third-party dependencies; building repeatable evidence workflows for CMS audits and independent assessments; and serving as a trusted GRC partner translating regulatory requirements into practical technical plans. You will need 7+ years of combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments. Deep working knowledge of CMS EDE requirements and Phase 3 certification is essential. Strong knowledge of NIST SP 800-53 controls and their application to cloud-hosted healthcare platforms is required. Hands-on experience partnering with engineering teams to implement controls in AWS using infrastructure-as-code, policy-as-code, and automated evidence collection is critical. You must have experience preparing CMS significant change requests, security impact analyses, POA&Ms, audit evidence, control narratives, and remediation plans. Strong communication skills for both technical and non-technical audiences, including senior leaders and external assessors, are essential. Bonus qualifications include a Bachelor's degree, prior healthcare or health insurance industry experience, CMS EDE Phase 3 certification support, annual CMS audit participation, independent security assessment experience, and familiarity with GRC platforms or cloud security posture management tools.

Similar roles