bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesRoSr. GRC Engineer

Sr. GRC Engineer

Ro · New York, NY or Remote · Remote · Active · Lever

Job facts

FieldValue
CompanyRo
TitleSr. GRC Engineer
Normalized title-
Department / teamCyber
LocationNew York, NY, United States
Work modelRemote / Remote
Employment typeFull Time
Salary-
Statusactive
ATS providerLever
Posted / first seen2026-02-19 / 2026-05-29
Changed / last seen2026-05-29 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Ro.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Lever.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in New York.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyRo
Sourced36937b1-51b6-4e86-9d91-0ac972e650c0
ATS providerLever

Description

Join Tech @ Ro to build the future of healthcare, from the ground up! At Ro, we believe that when people achieve their health goals, they can achieve their life goals. The highest-leverage way to move society forward is to give people their health, and the current healthcare system isn’t built to do that. It was built to bill, not to serve patients. We’re building a new system. One where the patient is in control. One designed from scratch for the digital age. At Ro, technology isn’t just a function… It's core to how we deliver care. We’ve built a vertically integrated healthcare platform that connects telehealth, diagnostics, pharmacy, and logistics into a seamless, end-to-end experience for millions of patients. …and we’re just getting started. As part of Tech @ Ro, you’ll work on systems that operate at scale, with an opportunity to: Solve complex, high-concurrency problems across a full-stack platform Build and ship quickly with tight feedback loops and real-world impact Own systems end-to-end, from architecture to production performance Work alongside experienced operators, technical leaders, and clinicians Help define how modern healthcare should be delivered We’re a performance-driven team with a strong sense of ownership and urgency. We move fast, learn quickly, and hold a high bar for what we build, and do so with a big heart — because patients depend on it. If you’re motivated by impact, scale, and the chance to help lead the patient revolution, come build with us. The Role The Governance Risk and Compliance Engineer role will be a core, individual contributor member of Ro’s GRC team. The GRC team enables Ro to manage risk by vigorously assessing our operations against leading compliance frameworks and standing legislation. This individual contributor role will be a key player in both leading our audit readiness program while driving continuous compliance using leading AI and automation platforms. The target base salary for this position ranges from $148,000 to $175,000, in addition to a competitive equity and benefits package (as applicable). When determining compensation, we analyze and carefully consider several factors, including location, job-related knowledge, skills and experience. These considerations may cause your compensation to vary. Ro is consistently recognized as a top workplace in Health Care, in New York, and for Women and Parents—earning more than 20 honors from Fortune, Great Place to Work, and PEOPLE since 2021. In 2025 alone, we ranked top 5 among medium workplaces in Health Care and New York, and top 50 nationwide. At Ro, we believe that our diverse perspectives are our biggest strengths — and that embracing them will create real change in healthcare. As an equal opportunity employer, we provide equal opportunity in all aspects of employment, including recruiting, hiring, compensation, training and promotion, termination, and any other terms and conditions of employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, familial status, age, disability and/or any other legally protected classification protected by federal, state, or local law. Ro is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and interview process. If you require a reasonable accommodation in the application or interview process, please contact us at [email protected]. See our California Privacy Policy here. What You’ll Do: Serve as both a risk practitioner and automation engineer. Automate everything. Own and maintain the compliance platform (Vanta), including control mapping, evidence collection, continuous monitoring, and audit workflows Perform risk assessments, vendor security reviews, and control gap analyses, and track remediation through to completion Manage control documentation, policies, procedures, and supporting artifacts across multiple compliance frameworks Partner with Security, IT, Infrastructure, and Engineering teams to ensure technical and administrative controls align with documented policies and compliance requirements Support internal and external audits (SOC 2, HIPAA, HITRUST) Own and maintain the cyber risk register, collaborating with risk owners to quantify risks and develop remediation plans. Develop and maintain risk reporting, metrics, and executive summaries with BI tools (Looker, Hex, etc) What You’ll Bring to the Team: 5+ years of combined experience across governance, risk, compliance, security engineering, or adjacent technical roles, including hands-on experience working with compliance frameworks such as SOC 2, HIPAA, HITRUST, NIST, and PCI in modern, technology-driven environments. 3+ years of experience with ongoing compliance operations, with demonstrated progression from manual evidence collection to automated, continuously monitored controls. 2+ years of hands-on experience implementing and administering continuous compliance and evidence automation platforms (e.g., Vanta, Drata, SecureFrame), including configuring and creating custom integrations as well as optimizing automated evidence workflows. Working knowledge of cloud computing platforms (AWS, Azure, GCP) and how their native services and configurations support security and compliance requirements. Expertise in using Looker (or similar BI tool; HEX) to create dashboards, generate reports, and visualize GRC data for stakeholders, with a focus on simplifying complex data into actionable insights. Ability to automate data ingestion, transformation, and reporting using scripting or programmatic approaches (e.g., Python, JavaScript, APIs, Tines.) Strong analytical and root cause analysis skills Kindness, and an ability to communicate to all levels of the organization Bonus Points Advanced GRC Automation & Engineering Mindset (custom automatons or workflows beyond out-of-the-box compliance tools) We’ve Got You Covered: Full medical, dental, and vision insurance + OneMedical membership Healthcare and Dependent Care FSA 401(k) with company match Flexible PTO Wellbeing + Learning & Growth reimbursements Paid parental leave + Fertility benefits Pet insurance Student loan refinancing Virtual resources for mindfulness, counseling, and fitness

Full job record

Job ID5992d7dc5326bb4db6b9ba6bde31491f78d66032
Org IDa6d5404e-d751-4400-bdf3-15e194186451
Source IDd36937b1-51b6-4e86-9d91-0ac972e650c0
Board IDd36937b1-51b6-4e86-9d91-0ac972e650c0
Providerlever
Provider Job Keyaf3c256d-62e4-4b53-8329-c7a8d187301e
TitleSr. GRC Engineer
Normalized Title
Statusactive
Activeyes
Location TextNew York, NY or Remote
Department
TeamCyber
Employment TypeFull-time
Workplace Typeremote
Remote Policyremote
CountryUnited States
RegionNY
CityNew York
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://jobs.lever.co/ro/af3c256d-62e4-4b53-8329-c7a8d187301e
Apply URLhttps://jobs.lever.co/ro/af3c256d-62e4-4b53-8329-c7a8d187301e/apply
First Seen At2026-05-29 07:02:10Z
Last Seen At2026-06-06 07:57:20Z
Last Checked At2026-06-06 07:57:20Z
Last Changed At2026-05-29 07:02:10Z
Inactive At
Source Posted At2026-02-19 22:22:09Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=lever/board=ro/date=2026-06-06/2026-06-06T07-57-20-046Z-1ae64d50c744f8a4033e795affd734a22767d39367ab75918c1245fdb964a7ee.json
Event Fields
{
  "content_hash": "4f0444315b69288b0d661993d5328cc9f06a5137425487a7981d7f583de5c4cc",
  "source_hash": "bb938d5d63ff277ea81a541edabd414301a563bac819f4c7ef651842a9f0a3fd",
  "last_changed_at": "2026-05-29T07:02:10.572Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "New York, NY",
    "city": "New York",
    "region": "NY",
    "country": "United States",
    "is_remote": true,
    "confidence": 0.9
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-06T07:57:20.506Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "New York, NY",
      "city": "New York",
      "region": "NY",
      "country": "United States",
      "is_remote": true,
      "confidence": 0.9
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": null,
  "workplace_type": "remote",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "lists": [
    {
      "text": "What You’ll Do:",
      "content": "\n<li>Serve as both a risk practitioner and automation engineer. Automate everything.</li>\n<li>Own and maintain the compliance platform (Vanta), including control mapping, evidence collection, continuous monitoring, and audit workflows</li>\n<li>Perform risk assessments, vendor security reviews, and control gap analyses, and track remediation through to completion</li>\n<li>Manage control documentation, policies, procedures, and supporting artifacts across multiple compliance frameworks</li>\n<li>Partner with Security, IT, Infrastructure, and Engineering teams to ensure technical and administrative controls align with documented policies and compliance requirements</li>\n<li>Support internal and external audits (SOC 2, HIPAA, HITRUST)</li>\n<li>Own and maintain the cyber risk register, collaborating with risk owners to quantify risks and develop remediation plans.</li>\n<li>Develop and maintain risk reporting, metrics, and executive summaries with BI tools (Looker, Hex, etc)</li>\n"
    },
    {
      "text": "What You’ll Bring to the Team:",
      "content": "\n<li>5+ years of combined experience across governance, risk, compliance, security engineering, or adjacent technical roles, including hands-on experience working with compliance frameworks such as SOC 2, HIPAA, HITRUST, NIST, and PCI in modern, technology-driven environments.</li>\n<li>3+ years of experience with ongoing compliance operations, with demonstrated progression from manual evidence collection to automated, continuously monitored controls.</li>\n<li>2+ years of hands-on experience implementing and administering continuous compliance and evidence automation platforms (e.g., Vanta, Drata, SecureFrame), including configuring and creating custom integrations as well as optimizing automated evidence workflows.</li>\n<li>Working knowledge of cloud computing platforms (AWS, Azure, GCP) and how their native services and configurations support security and compliance requirements.&nbsp;</li>\n<li>Expertise in using Looker (or similar BI tool; HEX) to create dashboards, generate reports, and visualize GRC data for stakeholders, with a focus on simplifying complex data into actionable insights.</li>\n<li>Ability to automate data ingestion, transformation, and reporting using scripting or programmatic approaches (e.g., Python, JavaScript, APIs, Tines.)</li>\n<li>Strong analytical and root cause analysis skills</li>\n<li>Kindness, and an ability to communicate to all levels of the organization</li>\n"
    },
    {
      "text": "Bonus Points",
      "content": "\n<li>Advanced GRC Automation &amp; Engineering Mindset (custom automatons or workflows beyond out-of-the-box compliance tools)</li>\n"
    },
    {
      "text": "We’ve Got You Covered:",
      "content": "\n<li>Full medical, dental, and vision insurance + OneMedical membership</li>\n<li>Healthcare and Dependent Care FSA</li>\n<li>401(k) with company match</li>\n<li>Flexible PTO</li>\n<li>Wellbeing + Learning &amp; Growth reimbursements</li>\n<li>Paid parental leave + Fertility benefits</li>\n<li>Pet insurance</li>\n<li>Student loan refinancing</li>\n<li>Virtual resources for mindfulness, counseling, and fitness</li>\n"
    }
  ],
  "country": "US",
  "createdAt": 1771539729599,
  "updatedAt": null,
  "categories": {
    "team": "Cyber",
    "location": "New York, NY or Remote",
    "commitment": "Full-time",
    "allLocations": [
      "New York, NY or Remote"
    ]
  },
  "salaryRange": null,
  "workplaceType": "remote"
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/5992d7dc5326bb4db6b9ba6bde31491f78d66032?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/a6d5404e-d751-4400-bdf3-15e194186451JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/d36937b1-51b6-4e86-9d91-0ac972e650c0JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/5992d7dc5326bb4db6b9ba6bde31491f78d66032/eventsJSON