Himalayas logo
RoRO

Sr. GRC Engineer

At Ro, we want to bring transparency to healthcare at every step of the patient journey, from the cost of their treatment to where their medication is sourced. Ro provides information to help patients make informed, important decisions about their healthcare and their lives, and to put patients back in control of their health.

Ro

Employee count: 501-1000

Salary: 148k-175k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Ro is a direct-to-patient healthcare company with a mission of helping patients achieve their health goals by delivering the easiest, most effective care possible. Ro is the only company to offer nationwide telehealth, labs, and pharmacy services. This is enabled by Ro's vertically integrated platform that helps patients achieve their goals through a convenient, end-to-end healthcare experience spanning from diagnosis, to delivery of medication, to ongoing care. Since 2017, Ro has helped millions of patients, including one in every county in the United States, and in 98% of primary care deserts.
Ro has been recognized as a Fortune Best Workplace in New York and Health Care for four consecutive years (2021-2024). In 2023, Ro was also named Best Workplace for Parents for the third year in a row. In 2022, Ro was listed as a CNBC Disruptor 50.

The Role:

The Governance Risk and Compliance Engineer role will be a core member of Ro’s GRC team. This is a remote, Individual Contributor role. The GRC team enables Ro to manage risk by vigorously assessing our operations against leading compliance frameworks and standing legislation. This individual contributor role will be a key player in both leading our audit readiness program while driving continuous compliance using leading AI and automation platforms..

What You’ll Do:

  • Serve as both a risk practitioner and automation engineer. Automate everything.
  • Own and maintain the compliance platform (Vanta), including control mapping, evidence collection, continuous monitoring, and audit workflows
  • Perform risk assessments, vendor security reviews, and control gap analyses, and track remediation through to completion
  • Manage control documentation, policies, procedures, and supporting artifacts across multiple compliance frameworks
  • Partner with Security, IT, Infrastructure, and Engineering teams to ensure technical and administrative controls align with documented policies and compliance requirements
  • Support internal and external audits (SOC 2, HIPAA, HITRUST)
  • Own and maintain the cyber risk register, collaborating with risk owners to quantify risks and develop remediation plans.
  • Develop and maintain risk reporting, metrics, and executive summaries with BI tools (Looker, Hex, etc)

What You’ll Bring to the Team:

  • 5+ years of combined experience across governance, risk, compliance, security engineering, or adjacent technical roles, including hands-on experience working with compliance frameworks such as SOC 2, HIPAA, HITRUST, NIST, and PCI in modern, technology-driven environments.
  • 3+ years of experience with ongoing compliance operations, with demonstrated progression from manual evidence collection to automated, continuously monitored controls.
  • 2+ years of hands-on experience implementing and administering continuous compliance and evidence automation platforms (e.g., Vanta, Drata, SecureFrame), including configuring and creating custom integrations as well as optimizing automated evidence workflows.
  • Working knowledge of cloud computing platforms (AWS, Azure, GCP) and how their native services and configurations support security and compliance requirements.
  • Expertise in using Looker (or similar BI tool; HEX) to create dashboards, generate reports, and visualize GRC data for stakeholders, with a focus on simplifying complex data into actionable insights.
  • Ability to automate data ingestion, transformation, and reporting using scripting or programmatic approaches (e.g., Python, JavaScript, APIs, Tines.)
  • Strong analytical and root cause analysis skills
  • Kindness, and an ability to communicate to all levels of the organization

Bonus Points

  • Advanced GRC Automation & Engineering Mindset (custom automatons or workflows beyond out-of-the-box compliance tools)

We’ve Got You Covered:

  • Full medical, dental, and vision insurance + OneMedical membership
  • Healthcare and Dependent Care FSA
  • 401(k) with company match
  • Flexible PTO
  • Wellbeing + Learning & Growth reimbursements
  • Paid parental leave + Fertility benefits
  • Pet insurance
  • Student loan refinancing
  • Virtual resources for mindfulness, counseling, and fitness
The target base salary for this position ranges from $148,000 to $175,000, in addition to a competitive equity and benefits package (as applicable). When determining compensation, we analyze and carefully consider several factors, including location, job-related knowledge, skills and experience. These considerations may cause your compensation to vary.
Ro recognizes the power of in-person collaboration, while supporting the flexibility to work anywhere in the United States. For our Ro’ers in the tri-state (NY) area, you will join us at HQ on Tuesdays and Thursdays. For those outside of the tri-state area, you will be able to join in-person collaborations throughout the year (i.e., during team on-sites).
At Ro, we believe that our diverse perspectives are our biggest strengths — and that embracing them will create real change in healthcare. As an equal opportunity employer, we provide equal opportunity in all aspects of employment, including recruiting, hiring, compensation, training and promotion, termination, and any other terms and conditions of employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, familial status, age, disability and/or any other legally protected classification protected by federal, state, or local law.
See our California Privacy Policy here.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Mid-level

Salary

Salary: 148k-175k USD

Location requirements

Hiring timezones

United States +/- 0 hours

About Ro

Learn more about Ro and their company culture.

View company profile
For too long, patients have been asked to blindly trust the healthcare system. No more.

At Ro, we want to bring transparency to healthcare at every step of the patient journey, from the cost of their treatment to where their medication is sourced. Ro provides information to help patients make informed, important decisions about their healthcare and their lives, and to put patients back in control of their health.

Patients deserve care with no surprises
They deserve to see every price before they pay. They deserve to see the risks and benefits of every treatment option. They deserve to know where their drugs are sourced. They deserve to know everything we know. That is Ro's promise.

Accurate and unbiased health information for our patients

VIPER is an internal process created by Ro that is designed to understand how law, medicine, and advertising intersect. The purpose of VIPER is to facilitate patient safety and trust in Ro by ensuring that the information we present to our patients and the public is truthful, non-misleading, and includes all of the information that we believe is important for a patient's treatment plan.

Patients deserve to see under the hood
Technology is essential to Ro's ability to provide access to affordable high-quality care. Patients deserve to know how Ro's technology works inside and out.

Helping patients in minutes from diagnosis to delivery
The future of healthcare is one in which providers are not replaced but empowered by technology, unburdened from administrative paperwork, and liberated to practice medicine in concert with their patients where and when they need it most. Ro is striving to make this a reality every single day.

Making it easy to cancel treatment

At Ro, we always put patients first. We send an email before every single shipment to make sure the patient still wants or needs their treatment (not after it's been shipped). And we built an amazing cancel flow. That's right, Ro has the easiest way to delay or cancel a shipment in healthcare.

Employee benefits

Learn about the employee benefits and perks provided at Ro.

View benefits

Fertility benefits

We'll help pay for people seeking fertility treatment.

Retirement benefits

Generous 401(k) with company match to help you invest in your future.

Company meals

We keep our team well-fed (cold-brew on tap, snacks galore, bi-weekly lunches).

Flexible working hours

We accommodate all kinds of lifestyles and life stages. Come work on your terms.

View Ro's employee benefits
Claim this profileRo logoRO

Ro

Company size

501-1000 employees

Founded in

2017

Chief executive officer

Zachariah Reitano

Employees live in

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

7 remote jobs at Ro

Explore the variety of open remote roles at Ro, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Ro

Remote companies like Ro

Find your next opportunity by exploring profiles of companies that are similar to Ro. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Ro hiring Sr. GRC Engineer • Remote (Work from Home) | Himalayas