Full-Time

Senior GRC Engineer

Gov, FedRAMP 20x

Updated on 9/16/2026

Workstreet

Workstreet

51-200 employees

AI-powered security, GRC, and testing services

No salary listed

No H1B Sponsorship

Remote in USA

Remote

Must work standard business hours in the Eastern (ET) time zone. Occasional local onsite travel is required.

Category
Cybersecurity (1)
Required Skills
FedRAMP
Microsoft Azure
Infrastructure as Code (IaC)
Vulnerability Analysis
SOC 2
AWS
Terraform
Google Cloud Platform

Get referred to Workstreet

See people who can refer or advise you

Requirements
  • At least 5 years of direct technical experience in AWS, Azure, or GCP, architecting and integrating automated GRC operations within cloud environments.
  • At least 5 years of experience implementing federal compliance, NIST SP 800-53, FedRAMP Revision 5, or Risk Management Framework standards, including end-to-end program management.
  • At least 3 years of experience leading multi-project client engagements, building long-term executive trust, and managing account retention in consulting settings.
  • Hands-on experience deploying and integrating GRC frameworks with enterprise identity and access management, vulnerability management, security information and event management, and software-as-a-service security tooling.
  • Proficiency with Infrastructure as Code using Terraform or Pulumi, Policy as Code using Open Policy Agent/Rego, and AI-powered or agentic workflows.
  • Direct experience interfacing with third-party assessment organizations and running end-to-end compliance programs for organizations holding FedRAMP Class C, Class D, or Revision 5 certifications.
  • Ability to communicate complex governance, risk, compliance, and security concepts to nontechnical stakeholders across Legal, People, Engineering, and Finance teams.
  • Strong written and verbal English communication skills.
  • A reliable, high-speed internet connection and a professional home office environment suitable for confidential conversations and uninterrupted collaboration.
  • Authorization to work in the United States without current or future visa sponsorship.
  • Successful identity verification and background screening, where permitted by law.
Responsibilities
  • Lead federal certification advisory engagements through FedRAMP 20x, Assessment and Authorization, and federal compliance lifecycles.
  • Provide executive-level compliance guidance and translate CR26 rules, 46 Key Security Indicators, and federal standards into business language for cross-functional stakeholders.
  • Deploy and integrate automated compliance processes within AWS, Azure, or GCP environments and client tool stacks.
  • Connect GRC workflows with client identity and access management, vulnerability management, security information and event management, and security software-as-a-service solutions.
  • Implement compliance automation using Infrastructure as Code, Policy as Code, and AI-powered agentic workflows.
  • Direct, mentor, coach, and manage a small team of compliance professionals while enforcing quality standards and delivery accountability.
  • Author and maintain Security Decision Records, Security Configuration Guides, and OSCAL, JSON, and YAML artifacts conforming to RFC-0024 and OMB M-24-15 mandates.
  • Conduct federal gap assessments and readiness reviews, including control mapping across FedRAMP 20x Class A, Class B, and Class C requirements.
  • Guide clients through third-party assessment organization assessments, C3PAO audits, and independent assessor evaluations.
  • Own an active client portfolio and lead end-to-end strategic engagements, escalations, executive calls, client relationships, and account retention.
  • Work a standard schedule of 8:00 AM to 5:00 PM Eastern Time, with occasional flexibility for global collaboration and time-sensitive priorities.
  • Travel locally for occasional onsite meetings, team gatherings, or business activities.
  • Participate in live video interviews with camera on and verify identity during recruitment and onboarding.
Desired Qualifications
  • Recognized federal security certifications such as CISSP, CISM, CGRC, or Certified Authorization Professional.
  • Active technical cloud certifications such as AWS Solutions Architect Associate, Azure Security Engineer, or GCP Associate Cloud Engineer.
  • Documented experience managing FedRAMP certification activities and real-time Continuous Monitoring workflows.
  • Practical experience authoring or validating machine-readable system security plans, plans of action and milestones, or Key Security Indicator evidence using OSCAL, JSON, or YAML schemas.

Workstreet provides AI-powered security and compliance services that turn security into a growth driver for startups, hypergrowth firms, and enterprises. Its offerings include Virtual CISO teams, AI-powered GRC for SOC 2, ISO 27001, CMMC and 35+ frameworks, AI-assisted security questionnaires with human review, penetration testing, and Vanta implementation as a top partner. It works by combining AI tooling with expert security professionals to automate risk assessments, policy creation, evidence collection, and ongoing compliance workflows within customer operations. The goal is to help customers build scalable security and compliance programs that unlock trust, market access, and sustainable growth.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

San Francisco, California

Founded

2023

Get referred to Workstreet

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Workstreet says it serves over 1,000 customers, signaling strong market pull.
  • BioMate’s 2026 partnership shows demand for regulated biotech compliance delivery.
  • Coalesce funding should expand talent, technology, and go-to-market before 2027.

What critics are saying

  • Vanta can internalize services and crush Workstreet’s partner-driven moat quickly.
  • Service margins erode if rival consultancies copy AI workflows and undercut pricing.
  • Coalesce’s growth mandate raises execution pressure; missed targets trigger retrenchment or layoffs.

What makes Workstreet unique

  • Workstreet is Vanta’s largest services partner, with more certified specialists.
  • Its AI-native GRC stack spans 35 frameworks and 100-plus services.
  • Coalesce Capital invested July 23, 2026, backing experienced cybersecurity-services scaling.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
FinSMEs
Jul 23rd, 2026
Workstreet receives investment from Coalesce Capital.

Workstreet receives investment from Coalesce Capital. July 23, 2026 Workstreet, a San Francisco, CA-based provider of AI-native compliance and cybersecurity solutions, received an investment from Coalesce Capital. The amount of the deal was not disclosed. The company intends to use the fund expand operations and its development efforts. Led by CEO Romeen Sheth, Workstreet is an AI-native security and compliance firm that helps companies build security and compliance programs that scale. Its solutions include full cybersecurity support across compliance, security, and privacy. Today, the company partners with more than 1,000 customers to turn security and compliance into a driver of growth. Don't just read the news. Own the data. Stop manually tracking deals. Access this round and over 100 others this week - in our structured Master Database (XML) + Weekly Intelligence PDF. [Access FinSMEs Intelligence Hub] 23/07/2026

PR Newswire
Jul 23rd, 2026
Coalesce Capital Announces Strategic Growth Investment in Workstreet, a Global Leader in AI-Native Cybersecurity and Compliance Services

/PRNewswire/ -- Coalesce Capital ("Coalesce"), a private equity firm focused on investing in next-generation technology-enabled services companies, today...

PE Hub
Jul 23rd, 2026
Exclusive: Coalesce buys Workstreet as cybersecurity challenges proliferate in age of AI | PE Hub

'Workstreet fits at the intersection of two powerful trends: the expansion of cybersecurity spending, as well as the growing complexity of regulatory compliance,' Coalesce Capital founder Stephanie Geveda tells PE Hub.

BioMate AI
Jul 21st, 2026
BioMate partners with Vanta and Workstreet on SOC 2 & HIPAA compliance.

BioMate partners with Vanta and Workstreet on SOC 2 & HIPAA compliance. BioMate is strengthening its security and compliance posture through partnerships with Vanta and Workstreet - building a continuous, automated program for SOC 2 and HIPAA that gives its biopharma and clinical partners the assurance they require before putting sensitive data and regulated workflows on any platform. Its Partners Two organizations, one compliance foundation. Vanta is the leading automated security and compliance platform. It continuously monitors a company's security posture, collects audit evidence in real time, and provides a clear, auditable path to SOC 2 and HIPAA certification. Rather than treating compliance as a one-time audit event, Vanta makes it an always-on, automated capability - reducing manual burden on engineering and operations teams while giving customers and partners continuous visibility into security controls. Workstreet Workstreet is Vanta's largest and most credentialed services partner, home to more Vanta-certified professionals than any other firm. Workstreet advises organizations from initial Vanta implementation through ongoing trust-program management, ensuring teams extract full value from the platform and sustain their SOC 2 and HIPAA posture as they scale. Why It Matters Compliance as a foundation, not an afterthought. BioMate is built for the most sensitive data in science: patient cohort records, proprietary compound libraries, preclinical study results, and unpublished target hypotheses. Its biopharma and clinical partners don't just want powerful AI - they need to know it is secure, auditable, and HIPAA-compliant before the first byte of their data enters the platform. The Vanta partnership delivers continuous, automated evidence collection across its infrastructure - every security control monitored in real time, every audit artefact collected automatically. Workstreet's expertise ensures that implementation is right-sized for where BioMate is today and structured to sustain certification as BioMate grow. What this means for BioMate users Every workflow you run on BioMate already returns cited, QC-audited results. Now the platform layer underneath carries the same standard of rigor: SOC 2 and HIPAA controls, continuously monitored, independently verified - so your compliance team has the documentation they need without asking your science team to stop and produce it. Closing the loop on responsible AI for drug discovery. BioMate's QC-gated workflows are designed from the ground up for audit readiness - every analytical step logged, every finding cited, every parameter traceable to its source. This compliance infrastructure closes the loop at the platform level, ensuring that the system running your research meets the same standards you apply to the research itself. BioMate is grateful to Vanta and Workstreet for the partnership, and BioMate look forward to sharing more milestones as BioMate progress toward certification.