Sr. GRC Engineer

· Remote

Location

Remote

Type

Full Time

Job Description

Sr. GRC Engineer

Reposted 13 Hours Ago
Easy Apply
2 Locations
In-Office or Remote
148K-175K Annually
Senior level
Healthtech • Pharmaceutical • Telehealth
Ro's mission is to help patients achieve their health goals by delivering the easiest most effective care possible.
The Role
Lead audit readiness and continuous compliance automation: manage Vanta perform risk assessments and vendor reviews support SOC 2/HIPAA/HITRUST audits maintain cyber risk register and build GRC reporting dashboards with BI tools.
Summary Generated by Built In
Ro is a direct-to-patient healthcare company with a mission of helping patients achieve their health goals by delivering the easiest most effective care possible. Ro is the only company to offer nationwide telehealth labs and pharmacy services. This is enabled by Ro's vertically integrated platform that helps patients achieve their goals through a convenient end-to-end healthcare experience spanning from diagnosis to delivery of medication to ongoing care. Since 2017 Ro has helped millions of patients in nearly every single county in the United States including 99% of primary care deserts.
 
Ro is consistently recognized as a top workplace in Health Care in New York and for Women and Parents—earning more than 20 honors from Fortune Great Place to Work and PEOPLE since 2021. In 2025 alone we ranked top 5 among medium workplaces in Health Care and New York and top 50 nationwide.

The Role:
The Governance Risk and Compliance Engineer role will be a core member of Ro’s GRC team. This is a remote Individual Contributor role. The GRC team enables Ro to manage risk by vigorously assessing our operations against leading compliance frameworks and standing legislation. This individual contributor role will be a key player in both leading our audit readiness program while driving continuous compliance using leading AI and automation platforms..
 

What You’ll Do:

  • Serve as both a risk practitioner and automation engineer. Automate everything.
  • Own and maintain the compliance platform (Vanta) including control mapping evidence collection continuous monitoring and audit workflows
  • Perform risk assessments vendor security reviews and control gap analyses and track remediation through to completion
  • Manage control documentation policies procedures and supporting artifacts across multiple compliance frameworks
  • Partner with Security IT Infrastructure and Engineering teams to ensure technical and administrative controls align with documented policies and compliance requirements
  • Support internal and external audits (SOC 2 HIPAA HITRUST)
  • Own and maintain the cyber risk register collaborating with risk owners to quantify risks and develop remediation plans.
  • Develop and maintain risk reporting metrics and executive summaries with BI tools (Looker Hex etc)

What You’ll Bring to the Team:

  • 5+ years of combined experience across governance risk compliance security engineering or adjacent technical roles including hands-on experience working with compliance frameworks such as SOC 2 HIPAA HITRUST NIST and PCI in modern technology-driven environments.
  • 3+ years of experience with ongoing compliance operations with demonstrated progression from manual evidence collection to automated continuously monitored controls.
  • 2+ years of hands-on experience implementing and administering continuous compliance and evidence automation platforms (e.g. Vanta Drata SecureFrame) including configuring and creating custom integrations as well as optimizing automated evidence workflows.
  • Working knowledge of cloud computing platforms (AWS Azure GCP) and how their native services and configurations support security and compliance requirements. 
  • Expertise in using Looker (or similar BI tool; HEX) to create dashboards generate reports and visualize GRC data for stakeholders with a focus on simplifying complex data into actionable insights.
  • Ability to automate data ingestion transformation and reporting using scripting or programmatic approaches (e.g. Python JavaScript APIs Tines.)
  • Strong analytical and root cause analysis skills
  • Kindness and an ability to communicate to all levels of the organization

Bonus Points

  • Advanced GRC Automation & Engineering Mindset (custom automatons or workflows beyond out-of-the-box compliance tools)

We’ve Got You Covered:

  • Full medical dental and vision insurance + OneMedical membership
  • Healthcare and Dependent Care FSA
  • 401(k) with company match
  • Flexible PTO
  • Wellbeing + Learning & Growth reimbursements
  • Paid parental leave + Fertility benefits
  • Pet insurance
  • Student loan refinancing
  • Virtual resources for mindfulness counseling and fitness

The target base salary for this position ranges from $148000 to $175000 in addition to a competitive equity and benefits package (as applicable). When determining compensation we analyze and carefully consider several factors including location job-related knowledge skills and experience. These considerations may cause your compensation to vary.

Ro recognizes the power of in-person collaboration while supporting the flexibility to work anywhere in the United States. For our Ro’ers in the tri-state (NY) area you will join us at HQ on Tuesdays and Thursdays. For those outside of the tri-state area you will be able to join in-person collaborations throughout the year (i.e. during team on-sites).
 
At Ro we believe that our diverse perspectives are our biggest strengths — and that embracing them will create real change in healthcare. As an equal opportunity employer we provide equal opportunity in all aspects of employment including recruiting hiring compensation training and promotion termination and any other terms and conditions of employment without regard to race ethnicity color religion sex sexual orientation gender identity gender expression familial status age disability and/or any other legally protected classification protected by federal state or local law.
 
Ro is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and interview process. If you require a reasonable accommodation in the application or interview process please contact us at [email protected].
 
See our California Privacy Policy here.

Top Skills

APIs
AWS
Azure
Drata
GCP
Hex
Hipaa
Hitrust
JavaScript
Looker
Nist
Pci
Python
Secureframe
Soc 2
Tines
Vanta

What the Team is Saying

Kim
Rachel
Andres
Ross
Kerry
Jay
Zach
Am I A Good Fit?
beta
Expert contributor network
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York NY
824 Employees
Year Founded: 2017

What We Do

Ro is a direct-to-patient healthcare company with a mission of helping patients achieve their health goals by delivering the easiest most effective care possible. Ro is the only company to offer nationwide telehealth labs and pharmacy services. This is enabled by Ro's vertically integrated platform that helps patients achieve their goals through a convenient end-to-end healthcare experience spanning from diagnosis to delivery of medication to ongoing care. Since 2017 Ro has helped millions of patients in nearly every single county in the United States including 98% of primary care deserts.

Why Work With Us

Ro is powering quality care at scale. The Ro Operating System (ro.OS) vertically integrates the core parts of healthcare bringing together nationwide telehealth lab and pharmacy services on one platform. The result? ro.OS makes it easier for patients to access and providers to deliver high-quality care – millions of times over.

Gallery

Ro (Ro.co) Teams

Team
Tech Org
Team
Clinical
Team
Pharmacy
About our Teams

Ro (Ro.co) Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Ro’ers in the tri-state area join their colleagues in the NY Hub twice a week for in-person collaboration.

Typical time on-site: 2 days a week
HQRo HQ
US
Learn more

Similar Jobs

Ro (Ro.co)

Cloud Security Engineer

Healthtech • Pharmaceutical • Telehealth
Easy Apply
In-Office or Remote
2 Locations
824 Employees
200K-245K Annually

Ro (Ro.co)

Medical Content Reviewer

Healthtech • Pharmaceutical • Telehealth
Easy Apply
In-Office or Remote
2 Locations
824 Employees

Ro (Ro.co)

Senior Security Engineer

Healthtech • Pharmaceutical • Telehealth
Easy Apply
In-Office or Remote
2 Locations
824 Employees
153K-186K Annually
Easy Apply
In-Office or Remote
2 Locations
824 Employees
106K-128K Annually
Apply Now

Date Posted

04/13/2026

Views

0

Back to Job Listings Add To Job List Company Profile View Company Reviews
Neutral
Subjectivity Score: 0
142,000+ Jobs Tracked
12,400+ Companies
1,930 Categories