Staff Security Engineer, GRCActive$246K–$287K

The opportunity

Hi, we're Oscar. We're hiring a Staff Security Engineer, GRC to join our Information Security Team.

What you'll do

  • CMS EDE Governance: Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms, with a focus on Phase 3 certification expectations, ongoing oversight, audit readiness, and regulator-facing evidence.

  • Control Architecture: Map CMS EDE and NIST SP 800-53 requirements to technical, operational, and administrative controls that can be implemented and measured across AWS and Azure environments.

  • Significant Change Management: Prepare, review, and submit CMS significant change requests, partner with technical teams on impact analysis, and maintain clear evidence of approval status, risk decisions, and implementation readiness.

  • Compliance as Code: Build and mature compliance-as-code patterns for AWS, including control automation, policy-as-code, infrastructure-as-code guardrails, continuous evidence collection, and automated drift detection.

  • POA&M Management: Own POA&M lifecycle management, including issue intake, risk rating, remediation planning, dependency tracking, stakeholder reporting, evidence validation, and closure readiness.

  • Risk Assessment and Advisory: Perform risk assessments for cloud services, EDE platform changes, system integrations, third-party dependencies, and security exceptions using healthcare and federal control expectations.

What they're looking for

  • Audit and Evidence Operations: Build repeatable evidence workflows for CMS audits, independent assessments, internal reviews, and customer or partner assurance requests.
  • Cross-Functional Leadership: Serve as a trusted GRC partner to engineering, security, product, compliance, legal, and business leaders, translating regulatory requirements into practical technical plans.
  • Compliance with all applicable laws and regulations
  • Other duties as assigned