Staff Security Engineer, GRC

Oscar HealthNew York, NY
$245,916 - $286,902Hybrid

About The Position

As a Staff GRC Engineer, you will be a cloud-aware governance, risk, and compliance expert supporting Oscar's healthcare technology environment, with a specific focus on CMS Enhanced Direct Enrollment (EDE) platforms and stage 3 certification readiness. You will translate CMS EDE requirements, FedRAMP Moderate-aligned expectations, and NIST SP 800-53 controls into practical control designs, compliance-as-code patterns, evidence workflows, and risk management practices for AWS-hosted and Azure-hosted systems. You will operate as a senior subject matter expert who can partner directly with engineering, security, legal, compliance, product, and CMS-facing stakeholders to keep regulated platforms audit-ready while enabling secure delivery. You will report into the CISO.

Requirements

  • 7+ years of combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments.
  • Deep working knowledge of CMS Enhanced Direct Enrollment requirements, including the ability to support or lead Phase 3 certification activities.
  • Strong knowledge of NIST SP 800-53 controls control expectations, including how those controls map to cloud-hosted healthcare platforms.
  • Hands-on experience partnering with engineering teams to implement controls in AWS using infrastructure as code, policy as code, automated evidence collection, or similar compliance automation approaches.
  • Experience preparing CMS significant change requests, security impact analyses, POA&Ms, audit evidence, control narratives, risk acceptances, and remediation plans.
  • Ability to communicate regulatory and control requirements clearly to technical and non-technical audiences, including senior leaders and external assessors.

Nice To Haves

  • Bachelor's degree or years of equivalent experience.
  • Prior work experience in healthcare, health insurance, marketplace exchange, or other highly regulated technology environments.
  • Experience supporting CMS EDE Phase 3 certification, annual CMS audits, independent security assessments, or regulator-facing security reviews.
  • Experience with GRC platforms, cloud security posture management, SIEM/evidence pipelines, configuration management, or automated control monitoring.
  • Relevant security, audit, or cloud certifications such as CISSP, CISA, CRISC, CCSP, AWS Security Specialty, or equivalent practical experience.

Responsibilities

  • Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms, with a focus on Phase 3 certification expectations, ongoing oversight, audit readiness, and regulator-facing evidence.
  • Map CMS EDE and NIST SP 800-53 requirements to technical, operational, and administrative controls that can be implemented and measured across AWS and Azure environments.
  • Prepare, review, and submit CMS significant change requests, partner with technical teams on impact analysis, and maintain clear evidence of approval status, risk decisions, and implementation readiness.
  • Build and mature compliance-as-code patterns for AWS, including control automation, policy-as-code, infrastructure-as-code guardrails, continuous evidence collection, and automated drift detection.
  • Own POA&M lifecycle management, including issue intake, risk rating, remediation planning, dependency tracking, stakeholder reporting, evidence validation, and closure readiness.
  • Perform risk assessments for cloud services, EDE platform changes, system integrations, third-party dependencies, and security exceptions using healthcare and federal control expectations.
  • Build repeatable evidence workflows for CMS audits, independent assessments, internal reviews, and customer or partner assurance requests.
  • Serve as a trusted GRC partner to engineering, security, product, compliance, legal, and business leaders, translating regulatory requirements into practical technical plans.
  • Compliance with all applicable laws and regulations
  • Other duties as assigned

Benefits

  • medical
  • dental
  • vision benefits
  • 11 paid holidays
  • paid sick time
  • paid parental leave
  • 401(k) plan participation
  • life and disability insurance
  • paid wellness time and reimbursements
  • unlimited vacation program
  • company equity grants
  • annual performance bonuses
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service