Staff Security Engineer, GRC

Oscar Health

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
New York, NY
Salary
$245,916–$286,902 / yr
Posted
21 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $180k
This role $266k
$112k most similar roles pay here $306k

This role pays more than 97% of similar roles. Most pay $151,500–$208,800 — the shaded band above. At the midpoint, this role pays about $266k versus about $180k for comparable roles.

Based on 240 similar postings.

Employer

About Oscar Health

Oscar Health is a technology-driven health insurance company offering individual, family, and small business health plans.

Oscar Health currently has 70 open roles on FindRole.

Listed pay typically runs $149,040–$195,615 across 65 roles with salary data.

Most-posted roles

View all roles at Oscar Health

At a glance

TL;DR · Staff Security Engineer, GRC

The Staff Security Engineer, GRC joins the Information Security Team to serve as a cloud-aware expert supporting a healthcare technology environment. This role focuses on CMS Enhanced Direct Enrollment platforms and stage 3 certification readiness. The engineer will translate CMS EDE requirements, FedRAMP Moderate-aligned expectations, and NIST SP 800-53 controls into practical control designs, compliance-as-code patterns, evidence workflows, and risk management practices for AWS and Azure hosted systems. Key responsibilities include managing the POA&M lifecycle, performing risk assessments for cloud services and third-party dependencies, and building automated evidence collection pipelines. The candidate must possess deep knowledge of CMS EDE requirements and experience with infrastructure as code and policy as code. This role solves the complex challenge of maintaining audit-ready status for regulated healthcare platforms while enabling secure technical delivery across multi-cloud environments.

What does a Security Engineer earn?

Median $185250 from 84 postings across 39 companies.

See salary data

What you'll do

  • Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms and Phase 3 certification readiness.
  • Map CMS EDE and NIST SP 800-53 requirements to technical controls across AWS and Azure environments.
  • Develop and implement compliance-as-code patterns, including automated evidence collection and infrastructure-as-code guardrails.
  • Manage the full Plan of Action and Milestones (POA&M) lifecycle, including risk rating and remediation tracking.
  • Prepare and submit CMS significant change requests while performing security impact analyses for technical teams.
  • Conduct risk assessments for cloud services, system integrations, third-party dependencies, and security exceptions.
  • Build repeatable evidence workflows for CMS audits, internal reviews, and external assurance requests.
  • Translate complex regulatory requirements into actionable technical plans for engineering, product, and legal stakeholders.

What we're looking for

  • 7+ years of combined experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments.
  • Deep working knowledge of CMS Enhanced Direct Enrollment requirements and Phase 3 certification activities.
  • Strong knowledge of NIST SP 800-53 controls for cloud-hosted healthcare platforms.
  • Hands-on experience implementing controls in AWS using infrastructure as code, policy as code, and automated evidence collection.
  • Experience preparing CMS significant change requests, security impact analyses, POA&Ms, audit evidence, and risk acceptances.
  • Ability to communicate regulatory and control requirements clearly to technical and non-technical audiences.
  • Bachelor's degree or equivalent experience (preferred).
  • Prior experience in healthcare, highly regulated environments, or with GRC platforms and cloud security certifications (preferred).

More like this

Similar roles

Security Engineer, GRC

Plaid

San Francisco, CA +2 57 days ago $156,000$213,600
Python SQL AWS Terraform CI/CD OPA Rego Sentinel Policy-as-Code OpenAI Claude SOC 2 ISO 27001 NIST CSF FedRAMP Mode GitHub API

Lead Security Engineer, GRC

Anduril Industries

Costa Mesa, CA 168 days ago $166,000$253,000
Go Python Rust Terraform AWS CDK CMMC NIST 800-171 FedRAMP SOC 2 APIs Data Pipelines Kubernetes CSPM STIG ConMon Security Data Lakes Log Aggregation
6+ yrs exp

Lead Security Engineer, GRC

Anduril Industries

Boston, MA 16 days ago $166,000$253,000
Python Go Rust Terraform AWS CDK CMMC NIST 800-171 FedRAMP SOC 2 APIs Data Pipelines Kubernetes CSPM STIG ConMon Security Data Lakes
6+ yrs exp

Lead Security Engineer, GRC

Anduril Industries

Washington, DC 16 days ago $166,000$253,000
Go Python Rust Terraform AWS CDK CMMC NIST 800-171 FedRAMP SOC 2 APIs Data Pipelines Kubernetes CSPM STIG ConMon Security Data Lakes Log Aggregation
6+ yrs exp

Lead Security Engineer, GRC

Anduril Industries

Seattle, WA 16 days ago $166,000$253,000
Python Go Rust Terraform AWS CDK CMMC NIST 800-171 FedRAMP SOC 2 APIs Data Pipelines Kubernetes CSPM STIG ConMon Security Data Lakes Log Aggregation
6+ yrs exp