Full-Time

Senior GRC Engineer

Compliance, Cybersecurity

Posted on 9/17/2025

Workstreet

Workstreet

No salary listed

No H1B Sponsorship

United States

In Person

Must be located in the United States; available for occasional travel to client sites within the US (estimated 10-20%).

US Citizenship Required

Category
IT & Security (1)
Requirements
  • 5+ years of experience in defense contractor compliance, CMMC, NIST 800-171, NIST 800-53, or FedRAMP implementation.
  • 3+ years of leadership experience managing or guiding a small team.
  • Deep understanding of CUI handling requirements and DFARS clauses (252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021).
  • Experience with NIST SP 800-171 control implementation and assessment.
  • Familiarity with DoD supply chain requirements and defense contractor workflows.
  • Experience working with small to mid-sized defense contractors.
  • Knowledge of common GCC High, Azure Government, or AWS GovCloud environments.
  • Experience thriving in a fast-paced startup environment.
Responsibilities
  • Analyze and interpret CMMC requirements and NIST SP 800-171 controls to ensure client compliance with Department of Defense cybersecurity standards.
  • Develop, implement, and maintain System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and other CMMC-required documentation.
  • Conduct gap assessments and readiness reviews for organizations pursuing CMMC certification.
  • Collaborate with defense contractors to identify and remediate gaps in their cybersecurity programs to meet CMMC Level 1 and Level 2 requirements.
  • Guide clients through the CMMC assessment process and coordinate with Certified Third-Party Assessment Organizations (C3PAOs).
  • Manage and coordinate multiple CMMC compliance projects across various defense contractors, ensuring timely completion before contract deadlines.
  • Lead and mentor a small team of compliance professionals to effectively deliver on CMMC objectives.
  • Stay current with evolving CMMC requirements, CMMC 2.0 rulemaking, and DoD cybersecurity policies.
Desired Qualifications
  • CMMC Registered Practitioner (RP), CMMC Certified Professional (CCP), or CMMC Certified Assessor (CCA) certification.
  • Security+ or CISSP certification.
  • Experience with SPRS reporting and maintaining scores of 110.
  • Familiarity with ITAR compliance requirements.
  • Ability to obtain U.S public trust security clearance.
  • Previous experience working directly with C3PAOs or as part of assessment teams.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

Simplify Jobs

Simplify's Take

What believers are saying

  • Romeen Sheth and Ryan Rich lead Workstreet as AI-first security firm.
  • Workstreet partners with Sensiba supporting high-growth tech frameworks.
  • Virtual CISO offerings drive outsized client impact for tech companies.

What critics are saying

  • NowSecure erodes Workstreet's penetration testing market share in 6-12 months.
  • Drata captures high-growth clients with AI-driven GRC in 12-18 months.
  • Philippines engineers attrition at 20% disrupts services in 12 months.

What makes Workstreet unique

  • Workstreet partners with Vanta for MSSP efficiency in saturated markets.
  • Workstreet rebranded AI-powered services serve over 1,000 tech companies.
  • Workstreet blends Big 4 rigor with SaaS security for trust programs.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

Remote Work Options

INACTIVE