Ro (Ro.co)

Ro is a direct-to-patient healthcare company with a mission of helping patients achieve their health goals by delivering the easiest, most effective care possible. Ro is the only company to offer nationwide telehealth, labs, and pharmacy services. This is enabled by Ro's vertically integrated platform that helps patients achieve their goals through a convenient, end-to-end healthcare experience spanning from diagnosis, to delivery of medication, to ongoing care. Since 2017, Ro has helped millions of patients in nearly every single county in the United States, including 98% of primary care deserts.

Sr. GRC Engineer

Security EngineerSecurity EngineerFull TimeRemoteTeam 824Since 2017Company Site

Location

West Virginia

Posted

22 days ago

Salary

$148K - $175K / year

Bachelor Degree9 yrs expEnglishVantaDrataSecureframeAWSAzureGCPLookerHexPythonJava ScriptAPITinesSoc 2HipaaHitrustNistPci

Job Description

Ro is a direct-to-patient healthcare company with a mission of helping patients achieve their health goals by delivering the easiest, most effective care possible. Ro is the only company to offer nationwide telehealth, labs, and pharmacy services. This is enabled by Ro's vertically integrated platform that helps patients achieve their goals through a convenient, end-to-end healthcare experience spanning from diagnosis, to delivery of medication, to ongoing care. Since 2017, Ro has helped millions of patients, including one in every county in the United States, and in 98% of primary care deserts. Ro has been recognized as a Fortune Best Workplace in New York and Health Care for four consecutive years (2021-2024). In 2023, Ro was also named Best Workplace for Parents for the third year in a row. In 2022, Ro was listed as a CNBC Disruptor 50. The Role: The Governance Risk and Compliance Engineer role will be a core member of Ro’s GRC team. This is a remote, Individual Contributor role. The GRC team enables Ro to manage risk by vigorously assessing our operations against leading compliance frameworks and standing legislation. This individual contributor role will be a key player in both leading our audit readiness program while driving continuous compliance using leading AI and automation platforms.. What You’ll Do: Serve as both a risk practitioner and automation engineer. Automate everything. Own and maintain the compliance platform (Vanta), including control mapping, evidence collection, continuous monitoring, and audit workflows Perform risk assessments, vendor security reviews, and control gap analyses, and track remediation through to completion Manage control documentation, policies, procedures, and supporting artifacts across multiple compliance frameworks Partner with Security, IT, Infrastructure, and Engineering teams to ensure technical and administrative controls align with documented policies and compliance requirements What You’ll Bring to the Team: 5+ years of combined experience across governance, risk, compliance, security engineering, or adjacent technical roles, including hands-on experience working with compliance frameworks such as SOC 2, HIPAA, HITRUST, NIST, and PCI in modern, technology-driven environments. 3+ years of experience with ongoing compliance operations, with demonstrated progression from manual evidence collection to automated, continuously monitored controls. 2+ years of hands-on experience implementing and administering continuous compliance and evidence automation platforms (e.g., Vanta, Drata, SecureFrame), including configuring and creating custom integrations as well as optimizing automated evidence workflows. Working knowledge of cloud computing platforms (AWS, Azure, GCP) and how their native services and configurations support security and compliance requirements. Expertise in using Looker (or similar BI tool; HEX) to create dashboards, generate reports, and visualize GRC data for stakeholders, with a focus on simplifying complex data into actionable insights. Ability to automate data ingestion, transformation, and reporting using scripting or programmatic approaches (e.g., Python, JavaScript, APIs, Tines.) Strong analytical and root cause analysis skills Kindness, and an ability to communicate to all levels of the organization Bonus Points Advanced GRC Automation & Engineering Mindset (custom automatons or workflows beyond out-of-the-box compliance tools) We’ve Got You Covered: Full medical, dental, and vision insurance + OneMedical membership Healthcare and Dependent Care FSA 401(k) with company match Flexible PTO Wellbeing + Learning & Growth reimbursements Paid parental leave + Fertility benefits Pet insurance Student loan refinancing Virtual resources for mindfulness, counseling, and fitness The target base salary for this position ranges from $148,000 to $175,000, in addition to a competitive equity and benefits package (as applicable). When determining compensation, we analyze and carefully consider several factors, including location, job-related knowledge, skills and experience. These considerations may cause your compensation to vary. Ro recognizes the power of in-person collaboration, while supporting the flexibility to work anywhere in the United States. For our Ro’ers in the tri-state (NY) area, you will join us at HQ on Tuesdays and Thursdays. For those outside of the tri-state area, you will be able to join in-person collaborations throughout the year (i.e., during team on-sites). At Ro, we believe that our diverse perspectives are our biggest strengths — and that embracing them will create real change in healthcare. As an equal opportunity employer, we provide equal opportunity in all aspects of employment, including recruiting, hiring, compensation, training and promotion, termination, and any other terms and conditions of employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, familial status, age, disability and/or any other legally protected classification protected by federal, state, or local law. See our California Privacy Policy here .

Job Requirements

  • Support internal and external audits (SOC 2, HIPAA, HITRUST)
  • Own and maintain the cyber risk register, collaborating with risk owners to quantify risks and develop remediation plans.
  • Develop and maintain risk reporting, metrics, and executive summaries with BI tools (Looker, Hex, etc)

Related Categories

Related Job Pages

More Security Engineer Jobs

Senior Cybersecurity – Exploitation Engineer

Reveal Technology

Actionable intelligence at the tactical edge

Security Engineer22 days ago
Full TimeRemoteTeam 11-50H1B No Sponsor

Senior Cybersecurity Engineer developing offensive security capabilities for a tech startup

IoTLinuxPythonTCP/IP
United States
$150K - $210K / year

Product Security Engineer

Cedar

Cedar is the AI-powered healthcare financial experience platform, built for the rising cost and complexity of healthcare payments. We help millions of people every year understand and resolve their medical bills with clarity and compassion, while helping healthcare organizations operate more efficiently. We’re combining AI, smart design, and empathy to fix one of healthcare’s most urgent crises.

Security Engineer22 days ago
Full TimeRemoteTeam 420Since 2016

The Product Security Engineer at Cedar will develop security tools, advise product engineers, and enhance workflows to ensure secure software development while fostering collaboration and communication with teams.

AWSBashGoGraphQLgRPCHTTPPythonTerraform
United States
$157.3K - $185K / year

Benefits Investigation Specialist

Amerita

Amerita, an affiliate of BrightSpring Health Services, is a specialty infusion company focused on providing complex pharmaceutical products and clinical services to patients outside of the hospital. Committed to excellent service, our vision is to combine the administrative efficiencies of a large organization with the flexibility, responsiveness, and entrepreneurial spirit of a local provider.

Security Engineer22 days ago
Full TimeRemoteTeam 1,001-5,000

This role will be responsible for verifying patient medical and pharmacy coverage, investigating authorization requirements, and facilitating patient copay card assistance based on eligibility criteria. Verifies patient prescription benefits, including medical and pharmacy covera...

United States

UAS Operations Safety Specialist

Percepto

Percepto is the leading autonomous inspection and monitoring solution provider, revolutionizing how enterprises monitor and inspect their critical infrastructure and assets. Our solution, combining Percepto AIM software and Percepto Air drones with regulatory approvals and turnkey service support, empowers organizations to optimize performance, safety, and sustainability. Percepto offers autonomous data collection with our market-leading drone-in-a-box solution, powered by Percepto AIM software. AIM transforms complex data into actionable insights through automated data management and AI-driven analysis, optimizing operational efficiency on an unprecedented scale. With remote operations from day one, we enable seamless, large-scale deployment at Fortune 500 organizations globally. Percepto is trusted by heavy industry enterprises including Siemens Energy, Delek US, Koch Fertilizer and ICL Dead Sea Works

Security Engineer22 days ago
Full TimeRemoteTeam 176Since 2014

The Compliance Specialist ensures UAS operations comply with FAA regulations and internal standards, traveling frequently to evaluate and audit sites.

Faa RegulationsGeospatial Data ReviewGis ToolsUas
Texas