4 дня назад
Staff Security Engineer, GRC
245 916 - 286 902$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Security Engineer, GRC (CMS EDE/Cloud Security): Translating CMS Enhanced Direct Enrollment, FedRAMP Moderate-aligned, and NIST SP 800-53 requirements into control designs, compliance-as-code patterns, evidence workflows, and risk practices for AWS- and Azure-hosted healthcare platforms with an accent on Phase 3 certification readiness and audit operations. Focus on designing cloud control architecture, preparing significant change requests and POA&Ms, automating evidence collection and drift detection, and leading risk assessments across technical and regulatory stakeholders.
Location: New York City, United States; hybrid schedule with 3 days in the office per week, including Thursdays
Salary: $245,916–$286,902 per year, plus equity grants, annual performance bonuses, and employee benefits.
Company
is a health insurance company built around a full-stack technology platform and a focus on improving the member healthcare experience.
What you will do
- Lead governance and compliance strategy for CMS Enhanced Direct Enrollment platforms, including Phase 3 certification readiness and regulator-facing evidence.
- Map CMS EDE and NIST SP 800-53 requirements to measurable technical, operational, and administrative controls across AWS and Azure.
- Prepare CMS significant change requests, perform impact analyses, and track risk decisions, approvals, and implementation readiness.
- Build compliance-as-code capabilities, including policy-as-code, infrastructure-as-code guardrails, automated evidence collection, and drift detection.
- Manage POA&M lifecycles, risk assessments, remediation planning, evidence validation, and audit operations.
- Partner with engineering, security, product, compliance, legal, business leaders, external assessors, and CMS-facing stakeholders.
Requirements
- 7+ years of experience in governance, risk, compliance, cloud security, security engineering, audit, or regulated technology environments.
- Deep knowledge of CMS Enhanced Direct Enrollment requirements and Phase 3 certification activities.
- Strong knowledge of NIST SP 800-53 controls and their application to cloud-hosted healthcare platforms.
- Hands-on experience implementing AWS controls through infrastructure as code, policy as code, automated evidence collection, or similar compliance automation.
- Experience preparing significant change requests, security impact analyses, POA&Ms, audit evidence, control narratives, risk acceptances, and remediation plans.
- Bachelor’s degree or equivalent experience, plus the ability to communicate with technical and non-technical stakeholders.
Nice to have
- Experience in healthcare, health insurance, marketplace exchanges, or other highly regulated technology environments.
- Experience with CMS EDE Phase 3 certification, annual CMS audits, independent security assessments, or regulator-facing security reviews.
- Experience with GRC platforms, cloud security posture management, SIEM or evidence pipelines, configuration management, or automated control monitoring.
- Certifications such as CISSP, CISA, CRISC, CCSP, or AWS Security Specialty.
Culture & Benefits
- Employee medical, dental, and vision benefits.
- Unlimited vacation program, paid holidays, paid sick time, and paid parental leave.
- 401(k) participation, life and disability insurance, paid wellness time, and reimbursements.
- Company equity grants and annual performance bonuses.
- Inclusive workplace focused on belonging, equal opportunity, and authentic employee participation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
18 часов назад
Sr Cloud Security Engineer I (Remote)
146 232 - 180 000$
4 дня назад
GRC Engineer (Cybersecurity)
200 000 - 250 000$
7 дней назад
Staff Cloud Security Engineer (AWS)
169 000 - 224 000$
2 дня назад
Risk Cyber Internal Audit Manager (Cybersecurity)
138 000 - 172 500$
3 дня назад
Senior Application Security Engineer (Cybersecurity)
109 500 - 208 500$
6 часов назад
Security Engineer
160 000 - 185 000$