Full-Time

Manager, GRC Engineering

vCISO

Updated on 9/17/2026

Workstreet

Workstreet

51-200 employees

AI-powered security, GRC, and testing services

No salary listed

No H1B Sponsorship

Remote in USA

Remote

Must work standard hours in the U.S. Eastern Time zone; occasional local onsite meetings or travel may be required.

Category
Cybersecurity (1)
Required Skills
FedRAMP
Microsoft Azure
Incident Response
Threat modeling
SOC 2
AWS
Risk Management
Penetration Testing
HIPAA
Google Cloud Platform

Get referred to Workstreet

See people who can refer or advise you

Requirements
  • At least 8 years of experience in information security, including at least 3 years in a senior security leadership role driving security strategy, governance, and risk management across complex environments.
  • Experience owning client engagements, leading difficult conversations, serving as a trusted security advisor, and building long-term relationships with executive stakeholders.
  • Ability to discuss security architecture, compliance posture, and control trade-offs with clients and prospects and translate complex technical concepts into practical business decisions.
  • Extensive hands-on knowledge of security frameworks and standards such as SOC 2, ISO 27001, NIST Cybersecurity Framework, HIPAA, HITRUST, NIST Special Publication 800-171, and/or CMMC.
  • Experience managing multiple security programs or client engagements simultaneously, ideally in consulting, advisory, or fractional security leadership environments.
  • Ability to communicate technical risks clearly and precisely to executive, technical, and non-technical audiences.
  • Ability to own a client portfolio, exercise sound judgment, and make informed security decisions independently while maintaining accountability for outcomes.
  • Practical experience implementing and evaluating security controls across AWS, Google Cloud Platform, and Microsoft Azure, with knowledge of cloud security architecture and best practices.
  • Excellent written and verbal English communication skills.
  • Reliable high-speed internet connection and a professional home office environment supporting confidential conversations and uninterrupted collaboration.
  • Willingness to travel locally for occasional onsite meetings, team gatherings, or business activities.
  • Authorization to work in the United States without current or future visa sponsorship.
  • Successful completion of identity verification and background screening where permitted by law.
  • Participation in live video interviews with camera on and identity verification during recruitment and onboarding.
Responsibilities
  • Own the virtual CISO relationship end-to-end for a portfolio of clients.
  • Lead strategic client engagements and security roadmaps from initial risk assessment through certification milestones.
  • Represent clients on live prospect and customer calls as their acting CISO and answer technical security questions in real time.
  • Handle complex security issues and client escalations with urgency and independent executive authority.
  • Develop custom architecture recommendations, threat models, policy sets, and executive briefings based on each client’s technology stack, business model, and risk appetite.
  • Conduct risk assessments, maintain risk registers, and guide programs across SOC 2, ISO 27001, ISO 42001, HIPAA, CMMC, NIST Cybersecurity Framework, NIST 800-171, GDPR, CCPA, DORA, and NYDFS.
  • Facilitate quarterly access reviews, annual penetration tests, and tabletop incident-response exercises.
  • Use Vanta, Drata, and SecureFrame for continuous audit readiness and compliance operations.
  • Maintain client mastery by participating in regular syncs, contextualizing GRC platform telemetry, tracking architectural changes, and identifying emerging risks.
  • Manage 3–5 GRC analysts through direct coaching, performance management, and delivery oversight.
  • Refine internal virtual CISO playbooks and mentor junior practice members.
  • Participate in pre-sales scoping discussions and support proposal development.
  • Maintain a standard work schedule of 8:00 AM–5:00 PM U.S. Eastern Time.
  • Collaborate with hiring managers, candidates, and cross-functional stakeholders across global teams.
Desired Qualifications
  • CISSP, CISM, or CISA certification.
  • Prior experience delivering virtual CISO, fractional security leadership, or advisory services within a managed security service provider environment.
  • Hands-on experience using Vanta, Drata, or SecureFrame for continuous security-posture tracking.
  • Recent hands-on experience as a lead implementer or lead auditor for ISO 42001.
  • Experience supporting formal SOC 2 Type II audits, ISO 27001 certifications, or CMMC assessments.
  • Familiarity with ISO 42001, GDPR, CCPA, DORA, or NIST 800-171.
  • Security and regulatory experience in SaaS, fintech, or healthcare.

Workstreet provides AI-powered security and compliance services that turn security into a growth driver for startups, hypergrowth firms, and enterprises. Its offerings include Virtual CISO teams, AI-powered GRC for SOC 2, ISO 27001, CMMC and 35+ frameworks, AI-assisted security questionnaires with human review, penetration testing, and Vanta implementation as a top partner. It works by combining AI tooling with expert security professionals to automate risk assessments, policy creation, evidence collection, and ongoing compliance workflows within customer operations. The goal is to help customers build scalable security and compliance programs that unlock trust, market access, and sustainable growth.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

San Francisco, California

Founded

2023

Get referred to Workstreet

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Workstreet says it serves over 1,000 customers, signaling strong market pull.
  • BioMate’s 2026 partnership shows demand for regulated biotech compliance delivery.
  • Coalesce funding should expand talent, technology, and go-to-market before 2027.

What critics are saying

  • Vanta can internalize services and crush Workstreet’s partner-driven moat quickly.
  • Service margins erode if rival consultancies copy AI workflows and undercut pricing.
  • Coalesce’s growth mandate raises execution pressure; missed targets trigger retrenchment or layoffs.

What makes Workstreet unique

  • Workstreet is Vanta’s largest services partner, with more certified specialists.
  • Its AI-native GRC stack spans 35 frameworks and 100-plus services.
  • Coalesce Capital invested July 23, 2026, backing experienced cybersecurity-services scaling.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
FinSMEs
Jul 23rd, 2026
Workstreet receives investment from Coalesce Capital.

Workstreet receives investment from Coalesce Capital. July 23, 2026 Workstreet, a San Francisco, CA-based provider of AI-native compliance and cybersecurity solutions, received an investment from Coalesce Capital. The amount of the deal was not disclosed. The company intends to use the fund expand operations and its development efforts. Led by CEO Romeen Sheth, Workstreet is an AI-native security and compliance firm that helps companies build security and compliance programs that scale. Its solutions include full cybersecurity support across compliance, security, and privacy. Today, the company partners with more than 1,000 customers to turn security and compliance into a driver of growth. Don't just read the news. Own the data. Stop manually tracking deals. Access this round and over 100 others this week - in our structured Master Database (XML) + Weekly Intelligence PDF. [Access FinSMEs Intelligence Hub] 23/07/2026

PR Newswire
Jul 23rd, 2026
Coalesce Capital Announces Strategic Growth Investment in Workstreet, a Global Leader in AI-Native Cybersecurity and Compliance Services

/PRNewswire/ -- Coalesce Capital ("Coalesce"), a private equity firm focused on investing in next-generation technology-enabled services companies, today...

PE Hub
Jul 23rd, 2026
Exclusive: Coalesce buys Workstreet as cybersecurity challenges proliferate in age of AI | PE Hub

'Workstreet fits at the intersection of two powerful trends: the expansion of cybersecurity spending, as well as the growing complexity of regulatory compliance,' Coalesce Capital founder Stephanie Geveda tells PE Hub.

BioMate AI
Jul 21st, 2026
BioMate partners with Vanta and Workstreet on SOC 2 & HIPAA compliance.

BioMate partners with Vanta and Workstreet on SOC 2 & HIPAA compliance. BioMate is strengthening its security and compliance posture through partnerships with Vanta and Workstreet - building a continuous, automated program for SOC 2 and HIPAA that gives its biopharma and clinical partners the assurance they require before putting sensitive data and regulated workflows on any platform. Its Partners Two organizations, one compliance foundation. Vanta is the leading automated security and compliance platform. It continuously monitors a company's security posture, collects audit evidence in real time, and provides a clear, auditable path to SOC 2 and HIPAA certification. Rather than treating compliance as a one-time audit event, Vanta makes it an always-on, automated capability - reducing manual burden on engineering and operations teams while giving customers and partners continuous visibility into security controls. Workstreet Workstreet is Vanta's largest and most credentialed services partner, home to more Vanta-certified professionals than any other firm. Workstreet advises organizations from initial Vanta implementation through ongoing trust-program management, ensuring teams extract full value from the platform and sustain their SOC 2 and HIPAA posture as they scale. Why It Matters Compliance as a foundation, not an afterthought. BioMate is built for the most sensitive data in science: patient cohort records, proprietary compound libraries, preclinical study results, and unpublished target hypotheses. Its biopharma and clinical partners don't just want powerful AI - they need to know it is secure, auditable, and HIPAA-compliant before the first byte of their data enters the platform. The Vanta partnership delivers continuous, automated evidence collection across its infrastructure - every security control monitored in real time, every audit artefact collected automatically. Workstreet's expertise ensures that implementation is right-sized for where BioMate is today and structured to sustain certification as BioMate grow. What this means for BioMate users Every workflow you run on BioMate already returns cited, QC-audited results. Now the platform layer underneath carries the same standard of rigor: SOC 2 and HIPAA controls, continuously monitored, independently verified - so your compliance team has the documentation they need without asking your science team to stop and produce it. Closing the loop on responsible AI for drug discovery. BioMate's QC-gated workflows are designed from the ground up for audit readiness - every analytical step logged, every finding cited, every parameter traceable to its source. This compliance infrastructure closes the loop at the platform level, ensuring that the system running your research meets the same standards you apply to the research itself. BioMate is grateful to Vanta and Workstreet for the partnership, and BioMate look forward to sharing more milestones as BioMate progress toward certification.