Full-Time

Senior GRC Engineer

Government, FedRAMP 20x

Updated on 8/23/2026

Workstreet

Workstreet

51-200 employees

AI-powered security, GRC, and testing services

No salary listed

No H1B Sponsorship

Remote in USA

Remote

Must work standard hours in the U.S. Eastern Time zone; occasional local travel for onsite meetings may be required.

Category
IT & Security (1)
Required Skills
FedRAMP
Microsoft Azure
Python
Infrastructure as Code (IaC)
SOC 2
AWS
Google Cloud Platform

Get referred to Workstreet

See people who can refer or advise you

Requirements
  • At least 5 years of direct experience implementing federal compliance, NIST SP 800-53, FedRAMP, or Risk Management Framework standards.
  • At least 3 years of experience leading multi-project client engagements, building long-term executive trust, and managing account retention.
  • Deep familiarity with FedRAMP 20x Program Certifications for Classes A, B, and C and Rev5 Agency Certifications for Class D and High.
  • Hands-on experience across AWS, Azure, and Google Cloud Platform, specifically within AWS GovCloud or Azure Government regions.
  • Working ability with scripting languages and policy-as-code tooling, including Python, Open Policy Agent/Rego, and infrastructure as code, to build and inspect automated evidence pipelines.
  • Practical experience working with or for a Third-Party Assessment Organization, participating on security assessment teams, or conducting formal evidence adjudication.
  • Excellent written and verbal English communication skills for engaging with candidates, hiring managers, business leaders, and global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Ability to work a standard schedule from 8:00 AM to 5:00 PM U.S. Eastern Time, with occasional flexibility for changing priorities, global collaboration, and time-sensitive work.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities.
  • Authorization to work in the United States without current or future visa sponsorship.
  • Successful identity verification and background screening, where permitted by law.
Responsibilities
  • Lead federal certification advisory engagements through FedRAMP 20x, Assessment and Authorization, and federal compliance lifecycles with clear milestone direction.
  • Provide executive-level compliance guidance by translating CR26 rules, the 46 Key Security Indicators, and federal standards into business language.
  • Direct and develop compliance pods by mentoring and coaching team members, enforcing quality standards, and maintaining delivery accountability across engagements.
  • Author and maintain Security Decision Records, Security Configuration Guides, and OSCAL, JSON, and YAML artifacts conforming to RFC-0024 and OMB M-24-15 mandates.
  • Connect Cloud Security Posture Management and Governance, Risk, and Compliance platforms into agency pipelines under the FedRAMP Collaborative Continuous Monitoring model.
  • Conduct comprehensive gap assessments and control mapping across FedRAMP 20x Class A, Class B, and Class C requirements.
  • Guide clients through Third-Party Assessment Organization assessments, Certified Third-Party Assessment Organization audits, and independent assessor evaluations.
  • Monitor Consolidated Rules, Significant Change Notifications, and the Rev5-to-20x transition timeline to maintain client compliance.
  • Own an active client portfolio from the first 15 days and lead end-to-end strategic engagements, escalations, executive calls, client satisfaction, and account retention.
Desired Qualifications
  • Recognized federal security credentials such as CISSP, CISM, CGRC, or Certified Authorization Professional.
  • Active technical cloud certifications such as AWS Solutions Architect Associate, Azure Security Engineer, or Google Cloud Associate Cloud Engineer.
  • Documented experience managing FedRAMP certification activities and real-time Collaborative Continuous Monitoring workflows.
  • Practical experience authoring or validating machine-readable System Security Plans, Plans of Action and Milestones, or Key Security Indicator evidence using OSCAL, JSON, or YAML schemas.

Workstreet provides AI-powered security and compliance services that turn security into a growth driver for startups, hypergrowth firms, and enterprises. Its offerings include Virtual CISO teams, AI-powered GRC for SOC 2, ISO 27001, CMMC and 35+ frameworks, AI-assisted security questionnaires with human review, penetration testing, and Vanta implementation as a top partner. It works by combining AI tooling with expert security professionals to automate risk assessments, policy creation, evidence collection, and ongoing compliance workflows within customer operations. The goal is to help customers build scalable security and compliance programs that unlock trust, market access, and sustainable growth.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

San Francisco, California

Founded

2023

Get referred to Workstreet

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Coalesce Capital’s July 23, 2026 investment funds talent, technology, and go-to-market expansion.
  • BioMate partnered with Workstreet in 2026, validating demand in biotech compliance.
  • Vanta highlighted Workstreet as its top MSP, showing durable channel pull and credibility.

What critics are saying

  • Coalesce ownership pushes growth demands that strain service quality during 2026-2027 scaling.
  • Workstreet’s moat depends on Vanta; platform changes compress partner economics fast.
  • A compliance-services commoditization wave destroys pricing power and makes Workstreet replaceable by 2027.

What makes Workstreet unique

  • July 23, 2026 Coalesce backed Workstreet’s AI-native compliance and cybersecurity stack.
  • Workstreet is Vanta’s largest and only Platinum partner, updated July 15, 2026.
  • Workstreet supports 35-plus GRC frameworks and over 1,000 customers across regulated industries.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

Remote Work Options

Company News

FinSMEs
Jul 23rd, 2026
Workstreet receives investment from Coalesce Capital.

Workstreet receives investment from Coalesce Capital. July 23, 2026 Workstreet, a San Francisco, CA-based provider of AI-native compliance and cybersecurity solutions, received an investment from Coalesce Capital. The amount of the deal was not disclosed. The company intends to use the fund expand operations and its development efforts. Led by CEO Romeen Sheth, Workstreet is an AI-native security and compliance firm that helps companies build security and compliance programs that scale. Its solutions include full cybersecurity support across compliance, security, and privacy. Today, the company partners with more than 1,000 customers to turn security and compliance into a driver of growth. Don't just read the news. Own the data. Stop manually tracking deals. Access this round and over 100 others this week - in our structured Master Database (XML) + Weekly Intelligence PDF. [Access FinSMEs Intelligence Hub] 23/07/2026

PR Newswire
Jul 23rd, 2026
Coalesce Capital Announces Strategic Growth Investment in Workstreet, a Global Leader in AI-Native Cybersecurity and Compliance Services

/PRNewswire/ -- Coalesce Capital ("Coalesce"), a private equity firm focused on investing in next-generation technology-enabled services companies, today...

PE Hub
Jul 23rd, 2026
Exclusive: Coalesce buys Workstreet as cybersecurity challenges proliferate in age of AI | PE Hub

'Workstreet fits at the intersection of two powerful trends: the expansion of cybersecurity spending, as well as the growing complexity of regulatory compliance,' Coalesce Capital founder Stephanie Geveda tells PE Hub.

BioMate AI
Jul 21st, 2026
BioMate partners with Vanta and Workstreet on SOC 2 & HIPAA compliance.

BioMate partners with Vanta and Workstreet on SOC 2 & HIPAA compliance. BioMate is strengthening its security and compliance posture through partnerships with Vanta and Workstreet - building a continuous, automated program for SOC 2 and HIPAA that gives its biopharma and clinical partners the assurance they require before putting sensitive data and regulated workflows on any platform. Its Partners Two organizations, one compliance foundation. Vanta is the leading automated security and compliance platform. It continuously monitors a company's security posture, collects audit evidence in real time, and provides a clear, auditable path to SOC 2 and HIPAA certification. Rather than treating compliance as a one-time audit event, Vanta makes it an always-on, automated capability - reducing manual burden on engineering and operations teams while giving customers and partners continuous visibility into security controls. Workstreet Workstreet is Vanta's largest and most credentialed services partner, home to more Vanta-certified professionals than any other firm. Workstreet advises organizations from initial Vanta implementation through ongoing trust-program management, ensuring teams extract full value from the platform and sustain their SOC 2 and HIPAA posture as they scale. Why It Matters Compliance as a foundation, not an afterthought. BioMate is built for the most sensitive data in science: patient cohort records, proprietary compound libraries, preclinical study results, and unpublished target hypotheses. Its biopharma and clinical partners don't just want powerful AI - they need to know it is secure, auditable, and HIPAA-compliant before the first byte of their data enters the platform. The Vanta partnership delivers continuous, automated evidence collection across its infrastructure - every security control monitored in real time, every audit artefact collected automatically. Workstreet's expertise ensures that implementation is right-sized for where BioMate is today and structured to sustain certification as BioMate grow. What this means for BioMate users Every workflow you run on BioMate already returns cited, QC-audited results. Now the platform layer underneath carries the same standard of rigor: SOC 2 and HIPAA controls, continuously monitored, independently verified - so your compliance team has the documentation they need without asking your science team to stop and produce it. Closing the loop on responsible AI for drug discovery. BioMate's QC-gated workflows are designed from the ground up for audit readiness - every analytical step logged, every finding cited, every parameter traceable to its source. This compliance infrastructure closes the loop at the platform level, ensuring that the system running your research meets the same standards you apply to the research itself. BioMate is grateful to Vanta and Workstreet for the partnership, and BioMate look forward to sharing more milestones as BioMate progress toward certification.