Назад
Company hidden
4 дня назад

Staff Security Engineer, GRC

245 916 - 286 902$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer, GRC (CMS EDE/Cloud Security): Translating CMS Enhanced Direct Enrollment, FedRAMP Moderate-aligned, and NIST SP 800-53 requirements into control designs, compliance-as-code patterns, evidence workflows, and risk practices for AWS- and Azure-hosted healthcare platforms with an accent on Phase 3 certification readiness and audit operations. Focus on designing cloud control architecture, preparing significant change requests and POA&Ms, automating evidence collection and drift detection, and leading risk assessments across technical and regulatory stakeholders.

Location: New York City, United States; hybrid schedule with 3 days in the office per week, including Thursdays

Salary: $245,916–$286,902 per year, plus equity grants, annual performance bonuses, and employee benefits.

Company

hirify.global is a health insurance company built around a full-stack technology platform and a focus on improving the member healthcare experience.

What you will do

  • Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms, including Phase 3 certification readiness and regulator-facing evidence.
  • Map CMS EDE and NIST SP 800-53 requirements to measurable technical, operational, and administrative controls across AWS and Azure.
  • Prepare CMS significant change requests, perform impact analyses, and track risk decisions, approvals, and implementation readiness.
  • Build compliance-as-code capabilities, including policy-as-code, infrastructure-as-code guardrails, automated evidence collection, and drift detection.
  • Manage POA&M lifecycles, risk assessments, remediation planning, evidence validation, and audit operations.
  • Partner with engineering, security, product, compliance, legal, business leaders, external assessors, and CMS-facing stakeholders.

Requirements

  • 7+ years of experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments.
  • Deep knowledge of CMS Enhanced Direct Enrollment requirements and Phase 3 certification activities.
  • Strong knowledge of NIST SP 800-53 controls and their application to cloud-hosted healthcare platforms.
  • Hands-on experience implementing AWS controls through infrastructure as code, policy as code, automated evidence collection, or similar compliance automation.
  • Experience preparing significant change requests, security impact analyses, POA&Ms, audit evidence, control narratives, risk acceptances, and remediation plans.
  • Bachelor’s degree or equivalent experience, plus the ability to communicate with technical and non-technical stakeholders.

Nice to have

  • Experience in healthcare, health insurance, marketplace exchanges, or other highly regulated technology environments.
  • Experience with CMS EDE Phase 3 certification, annual CMS audits, independent security assessments, or regulator-facing security reviews.
  • Experience with GRC platforms, cloud security posture management, SIEM or evidence pipelines, configuration management, or automated control monitoring.
  • Certifications such as CISSP, CISA, CRISC, CCSP, or AWS Security Specialty.

Culture & Benefits

  • Employee medical, dental, and vision benefits.
  • Unlimited vacation program, paid holidays, paid sick time, and paid parental leave.
  • 401(k) participation, life and disability insurance, paid wellness time, and reimbursements.
  • Company equity grants and annual performance bonuses.
  • Inclusive workplace focused on belonging, equal opportunity, and authentic employee participation.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →