Full-Time

Senior GRC Engineer

Posted on 2/20/2026

Workstreet

Workstreet

No salary listed

No H1B Sponsorship

Remote in USA

Remote

Must be amenable to US Eastern Time zone hours.

US Citizenship, US Top Secret Clearance, Canada Citizenship, Canada Top Secret Clearance, UK Citizenship, UK Top Secret Clearance Required

Category
IT & Security (1)
Required Skills
Fedramp
Requirements
  • 5+ years of experience in Governance, Risk, and Compliance (GRC), with deep exposure to FedRAMP, NIST SP 800-53, and federal compliance programs
  • Working knowledge of CMMC 2.0 and NIST SP 800-171 requirements
  • 3+ years of experience leading or mentoring a small team
  • Experience authoring and reviewing System Security Plans (SSPs), Plan of Actions and Milestones (POA&Ms), and assessment artifacts
  • Experience working with SaaS providers, federal contractors, or regulated technology organizations
  • Strong organizational and project management skills with the ability to manage multiple FedRAMP-focused engagements concurrently
  • Ability to thrive in a fast-paced, consulting or startup environment
  • Strong client-facing communication skills
  • Familiarity with federal cloud environments (Amazon Web Services GovCloud, Microsoft Azure Government, GCC High)
  • Must be amenable to work United States Eastern Time zone hours
  • Fluency in written and verbal English communication skills
Responsibilities
  • Interpret and apply FedRAMP requirements by analyzing and applying NIST SP 800-53 controls, FedRAMP baselines, and agency-specific requirements to ensure client compliance
  • Develop and maintain FedRAMP documentation including System Security Plans (SSPs), control implementation narratives, Plans of Action and Milestones (POA&Ms), Security Assistance Programs (SAPs), Security Assessment Reports (SARs), and continuous monitoring artifacts
  • Conduct FedRAMP readiness assessments including gap analyses and readiness reviews to prepare organizations for Joint Authorization Board (JAB) or Agency Authorization to Operate (ATO) pathways
  • Support authorization and assessment activities by coordinating with Third-Party Assessment Organizations (3PAOs), cloud service providers, and government stakeholders throughout the FedRAMP lifecycle
  • Boundary definition and scoping activities including identification of in-scope components, interconnections, data flows, and shared responsibility models to ensure alignment with FedRAMP Program Management Office (PMO) and agency expectations
  • Manage continuous monitoring programs including monthly, quarterly, and annual FedRAMP continuous monitoring requirements, vulnerability management, incident response reporting, and change control
  • Lead FedRAMP engagements by managing multiple concurrent client projects, ensuring milestones, deliverables, and quality standards are consistently met or exceeded
  • Support CMMC and NIST SP 800-171 compliance efforts for defense contractors by interpreting CMMC 2.0 and NIST SP 800-171 controls and implementing compliant security programs
  • Develop CMMC documentation including SSPs, POA&Ms, and supporting artifacts required for CMMC Level 1 and Level 2 readiness
Desired Qualifications
  • FedRAMP-specific experience supporting Joint Authorization Board (JAB) or Agency Authorization to Operate (ATO)s
  • CMMC Registered Practitioner (RP), Certified CMMC Professional (CCP), or Certified CMMC Assessor (CCA) certification
  • Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Security+ certification
  • Experience with Defence Federal Acquisition Regulation Supplement (DFARS) clauses and Controlled Unclassified Information (CUI) handling requirements
  • Familiarity with Supplier Performance Risk System (SPRS) reporting and Department of Defense assessment workflows
  • Prior experience working directly with Third-Party Assessment Organizations (3PAOs) or Cloud Security Assessment Organizations (C3PAOs)

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

Simplify Jobs

Simplify's Take

What believers are saying

  • Romeen Sheth and Ryan Rich lead Workstreet as AI-first security firm.
  • Workstreet partners with Sensiba supporting high-growth tech frameworks.
  • Virtual CISO offerings drive outsized client impact for tech companies.

What critics are saying

  • NowSecure erodes Workstreet's penetration testing market share in 6-12 months.
  • Drata captures high-growth clients with AI-driven GRC in 12-18 months.
  • Philippines engineers attrition at 20% disrupts services in 12 months.

What makes Workstreet unique

  • Workstreet partners with Vanta for MSSP efficiency in saturated markets.
  • Workstreet rebranded AI-powered services serve over 1,000 tech companies.
  • Workstreet blends Big 4 rigor with SaaS security for trust programs.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

Remote Work Options

INACTIVE