Oscar Health

Senior Security Engineer I, GRC

$163,944 per yearFull-time · New York, NY
✓ Verified live on the employer's own system · added 104 days ago
Save search
Mid-level · 3+ yrs exp

Requirements

Experience: 3+ years

Skills & tools

HiringSecurityRegulatory ComplianceRecordkeepingOperationsCloud PlatformsDevopsIndustrial Automation

Benefits — mentioned in this posting

Remote / flexiblePaid time offEquity / stockBonus / commission
Apply on company site ↗ See your fit → free

Full job description

Hi, we're Oscar. We're hiring a Senior Security Engineer 1, GRC to join our Security Team.

The Principal GRC Engineer designs and operates the systems that enable continuous security assurance, deep risk visibility, and scalable regulatory compliance. Rather than managing documentation or preparing for audits, this role engineers the infrastructure that allows the organization to demonstrate security and compliance continuously through automation, telemetry, and self-evidencing controls.

Operating at the intersection of security engineering, platform engineering, risk management, and regulatory assurance, you will embed governance and control validation directly into how systems are built and operated. By connecting controls, operational telemetry, engineering workflows, and risk signals, you will surface patterns and relationships that traditional GRC programs cannot see, creating a feedback loop where security intelligence continuously informs engineering guardrails and platform architecture.

Work Location: This position is based in our New York City office, requiring a hybrid work schedule with 3 days of in-office work per week. Thursdays are a required in-office day for team meetings and events, while your other two office days are flexible to suit your schedule.

Pay Transparency: The base pay for this role is: $163,944 per year - $215,176 per year. You are also eligible for employee benefits, participation in Oscar's unlimited vacation program, company equity grants and annual performance bonuses.

  • Design systems that continuously measure and validate security controls through operational telemetry, automated evidence generation, and control health monitoring.
  • Build automation and orchestration across security tools, cloud platforms, and engineering systems to eliminate manual compliance processes and reduce audit overhead.
  • Translate governance expectations into machine-enforceable guardrails embedded within infrastructure platforms, CI/CD pipelines, and engineering workflows.
  • Apply automation, orchestration, and AI-assisted capabilities to scale governance workflows, enabling intelligent analysis and adaptive control systems.
  • Architect control and telemetry pipelines where operational systems produce the evidence required for regulatory assurance and audit readiness.
  • Familiarity with industry standards and compliance frameworks (such as SOC, SOX., NIST, HIPAA) and experience in ensuring organizational adherence to these standards.
  • Certifications such as CISSP, CISM, CISA, CEH, or vendor-specific certifications.
  • Proficiency in managing security projects, including planning, execution, and successful delivery within timelines and budgets.
  • 4+ years of experience in Security Engineering, DevSecOps, or Site Reliability Engineering (SRE), with at least 3 years specifically focused on GRC automation or internal security tooling.

More jobs at Oscar Health

Similar jobs near New York, NY

Tell me when more Senior AI Security Engineer II jobs post near New York, NY We re-check every listing against the employer’s own board — no résumé needed.

Search Senior Security Engineer I, GRC jobs near New York, NY → Browse all live jobs

This posting was published by Oscar Health on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.