Staff Security Engineer, GRC
Core
Staff GRC Engineer leading governance, risk, and compliance strategy for CMS Enhanced Direct Enrollment (EDE) platforms and cloud security in a healthcare environment.
Role type
Staff GRC Engineer (Cloud Security & Compliance)
Builds
Compliance-as-code patterns, automated evidence workflows, and control architectures for AWS and Azure.
Domain
Healthcare / Health Insurance / Federal Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
CMS EDE Phase 3 certification expertise, NIST SP 800-53 controls mapping, cloud security engineering, compliance automation, risk assessment, audit evidence management, significant change management
Preferred skills
Healthcare industry experience, GRC platform usage, cloud security posture management, security certifications (CISSP, CISA, CRISC, CCSP, AWS Security Specialty)
Technologies
AWS, Azure, Infrastructure as Code, Policy as Code, SIEM, GRC platforms
Responsibilities
Lead governance and compliance strategy for CMS EDE platforms; Map regulatory requirements to technical controls across cloud environments; Manage POA&M lifecycle and risk assessments; Build compliance-as-code patterns and automated evidence workflows; Prepare CMS significant change requests and audit evidence; Partner with engineering and legal stakeholders on secure delivery.
Seniority
Staff, hands-on IC with strategic leadership
