×
Register Here to Apply for Jobs or Post Jobs. X

Sr. GRC Engineer

Job in New York, New York County, New York, 10261, USA
Listing for: Ro
Full Time position
Listed on 2026-02-28
Job specializations:
  • Security
    Cybersecurity, Data Security
Salary/Wage Range or Industry Benchmark: 60000 - 80000 USD Yearly USD 60000.00 80000.00 YEAR
Job Description & How to Apply Below
Location: New York

Ro is a direct‑to‑patient healthcare company with a mission of helping patients achieve their health goals by delivering the easiest, most effective care possible. Ro is the only company to offer nationwide telehealth, labs, and pharmacy services. This is enabled by Ro's vertically integrated platform that helps patients achieve their goals through a convenient, end‑to‑end healthcare experience spanning from diagnosis, to delivery of medication, to ongoing care.

Since 2017, Ro has helped millions of patients in nearly every single county in the United States, including 99% of primary care deserts.

Ro is consistently recognized as a top workplace in Health Care, in New York, and for Women and Parents—earning more than 20 honors from Fortune, Great Place to Work, and PEOPLE since 2021. In 2025 alone, we ranked top 5 among medium workplaces in Health Care and New York, and top 50 nationwide.

The Role

The Governance Risk and Compliance Engineer role will be a core member of Ro’s GRC team. This is a remote, Individual Contributor role. The GRC team enables Ro to manage risk by vigorously assessing our operations against leading compliance frameworks and standing legislation. This individual contributor role will be a key player in both leading our audit readiness program while driving continuous compliance using leading AI and automation platforms.

What

You’ll Do
  • Serve as both a risk practitioner and automation engineer. Automate everything.
  • Own and maintain the compliance platform (Vanta), including control mapping, evidence collection, continuous monitoring, and audit workflows.
  • Perform risk assessments, vendor security reviews, and control gap analyses, and track remediation through to completion.
  • Manage control documentation, policies, procedures, and supporting artifacts across multiple compliance frameworks.
  • Partner with Security, IT, Infrastructure, and Engineering teams to ensure technical and administrative controls align with documented policies and compliance requirements.
  • Support internal and external audits (SOC 2, HIPAA, HITRUST).
  • Own and maintain the cyber risk register, collaborating with risk owners to quantify risks and develop remediation plans.
  • Develop and maintain risk reporting, metrics, and executive summaries with BI tools (Looker, Hex, etc).
What You’ll Bring To The Team
  • 5+ years of combined experience across governance, risk, compliance, security engineering, or adjacent technical roles, including hands‑on experience working with compliance frameworks such as SOC 2, HIPAA, HITRUST, NIST, and PCI in modern, technology‑driven environments.
  • 3+ years of experience with ongoing compliance operations, with demonstrated progression from manual evidence collection to automated, continuously monitored controls.
  • 2+ years of hands‑on experience implementing and administering continuous compliance and evidence automation platforms (e.g., Vanta, Drata, Secure Frame), including configuring and creating custom integrations as well as optimizing automated evidence workflows.
  • Working knowledge of cloud computing platforms (AWS, Azure, GCP) and how their native services and configurations support security and compliance requirements.
  • Expertise in using Looker (or similar BI tool; HEX) to create dashboards, generate reports, and visualize GRC data for stakeholders, with a focus on simplifying complex data into actionable insights.
  • Ability to automate data ingestion, transformation, and reporting using scripting or programmatic approaches (e.g., Python, JavaScript, APIs, Tines).
  • Strong analytical and root cause analysis skills.
  • Kindness, and an ability to communicate to all levels of the organization.
Bonus Points
  • Advanced GRC Automation & Engineering Mindset (custom automations or workflows beyond out‑of‑the‑box compliance tools).
We’ve Got You Covered
  • Full medical, dental, and vision insurance + One Medical membership
  • Healthcare and Dependent Care FSA
  • 401(k) with company match
  • Flexible PTO
  • Wellbeing + Learning & Growth reimbursements
  • Paid parental leave + Fertility benefits
  • Pet insurance
  • Student loan refinancing
  • Virtual resources for mindfulness, counseling, and fitness

The target base salary for this position ranges…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary