Workstreet Logo

Workstreet

Senior GRC Engineer - GOV (FedRAMP 20x)

Posted 14 Days Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Lead federal compliance engagements for clients pursuing FedRAMP and NIST certifications. Own strategic advisory, gap assessments, FedRAMP 20x readiness, OSCAL/JSON/YAML machine-readable artifacts, CCM continuous monitoring integrations, and third-party assessment orchestration while mentoring a small compliance team and maintaining executive client relationships.
The summary above was generated by AI
About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.  We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.  We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the GRC Engineering (GOV) Team
Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment & Authorization compliance efforts. We act as our clients' trusted guides and primary point of contact end-to-end, leading them through gap assessments, System Security Plans, POA&Ms, and C3PAO/3PAO coordination with clarity, composure, and a genuinely client-first mindset. Beyond the technical depth in RMF, CUI/DFARS requirements, and GovCloud environments, what defines us is how we work: we translate complex requirements into plain language, manage escalations with urgency and care, and take real pride in making every client feel informed, supported, and well-prepared. We're a group that mentors one another, holds a high bar for quality, and thrives in a fast-paced environment where our work directly strengthens the security of the defense industrial base.

The Opportunity

Workstreet is seeking a Senior GRC Engineer (Government) to serve as a high-touch, executive-level strategic partner for organizations navigating federal compliance frameworks. Built around client relationship excellence, this role centers on delivering an exceptional client experience, cultivating trusted advisor relationships, and maintaining account retention across high-stakes engagements. You will guide clients through complex federal certifications while directing a team of primary operators who manage day-to-day execution across CMMC, NIST SP 800-171, NIST SP 800-53, and FedRAMP 20x standards.

The successful candidate will integrate rapidly into the organization and assume active portfolio ownership within their first 15 days. Rather than focusing solely on routine task execution, you will lead end-to-end strategic engagements, handle escalations with composure, and represent clients on executive calls to ensure every partner remains deeply engaged, highly satisfied, and aligned with Workstreet in the long term during U.S. Eastern Time business hours.

What You'll Do
  • Lead federal certification advisory motions - guide clients through FedRAMP 20x, Assessment & Authorization (A&A), and federal compliance lifecycles with clear milestone direction.
  • Deliver executive-level compliance guidance - act as a trusted advisor, translating complex CR26 rules, 46 Key Security Indicators (KSIs), and federal standards into business language across cross-functional units like Legal, People, Engineering, and Finance.
  • Architect cloud-native automated GRC operations - deploy and integrate automated compliance processes within AWS, Azure, or GCP environments and existing client toolstacks.
  • Deploy enterprise security and AI tool integrations - connect GRC workflows with client IAM, vulnerability management, SIEM, and security-based SaaS solutions.
  • Architect Infrastructure and Policy as Code - implement compliance automation using Infrastructure as Code (Terraform, Pulumi), Policy as Code (OPA/Rego), and AI-powered agentic workflows.
  • Direct and develop compliance pods - mentor, coach, and manage a small team of compliance professionals, enforcing quality standards and delivery accountability across engagements.
  • Build machine-readable compliance artifacts - author and maintain Security Decision Records, Security Configuration Guides, and OSCAL/JSON/YAML artifacts conforming to RFC-0024 and OMB M-24-15 mandates.
  • Execute federal gap and readiness reviews - conduct comprehensive gap assessments and control mapping across FedRAMP 20x Class A, Class B, and Class C requirements.
  • Orchestrate third-party assessment activities - guide clients through 3PAO assessments, C3PAO audits, and independent assessor evaluations with speed and technical rigor.
Who You Are
  • Cloud GRC automation architect - possess 5+ years of direct technical experience in AWS, Azure, or GCP, architecting and integrating automated GRC operations directly within cloud environments.
  • Federal compliance leader - bring 5+ years of experience implementing federal compliance, NIST SP 800-53, FedRAMP Rev5, or Risk Management Framework (RMF) standards, including end-to-end program management.
  • End-to-end engagement owner - bring 3+ years of experience leading multi-project client engagements, building long-term executive trust, and managing account retention in consulting settings.
  • Security stack integration specialist - hands-on experience deploying and integrating GRC frameworks with enterprise IAM, vulnerability management, SIEM, and SaaS security tooling.
  • Compliance-as-code and AI practitioner - proficient with Infrastructure as Code (Terraform, Pulumi), Policy as Code (OPA/Rego), and designing AI-powered automation or agentic workflows.
  • 3PAO audit and Rev5 veteran - direct experience interfacing with 3PAO organizations and running end-to-end compliance programs for organizations holding FedRAMP Class C, Class D, or Rev5 certifications.
  • Cross-functional business translator - adept at communicating complex GRC and security concepts to non-technical stakeholders across client Legal, People, Engineering, and Finance teams.
What will help you succeed
  • Active federal security credentials - hold recognized certifications such as CISSP, CISM, CGRC, or Certified Authorization Professional (CAP).
  • Validated cloud architecture credentials - active technical certifications such as AWS Solutions Architect Associate, Azure Security Engineer, or GCP Associate Cloud Engineer.
  • Collaborative continuous monitoring experience - documented history managing FedRAMP certification activities and real-time Continuous Monitoring (CCM) workflows.
  • Hands-on OSCAL schema mastery - practical experience authoring or validating machine-readable SSPs, POA&Ms, or KSI evidence utilizing OSCAL, JSON, or YAML schemas.
What We Offer
  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process 
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.


All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact [email protected] 

Similar Jobs

2 Minutes Ago
In-Office or Remote
275K-320K Annually
Expert/Leader
275K-320K Annually
Expert/Leader
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Cybersecurity • Data Privacy
Lead Rubrik’s global government affairs and public policy strategy focused on data security, cyber resilience, and AI safety. Build relationships with heads of state, legislators, and regulatory agencies; represent the company at congressional hearings and policy summits; shape cybersecurity and AI legislation; and integrate Rubrik’s technical vision into government standards. Partner with public-sector and enterprise sales leaders to expand government procurement and strategic accounts.
Top Skills: Artificial IntelligenceCybersecurityData GovernanceRubrik Security CloudSaaSZero Trust
6 Minutes Ago
Remote or Hybrid
11 Locations
130K-170K Annually
Senior level
130K-170K Annually
Senior level
Other • Professional Services
Own complex software systems and critical workflows end-to-end while ensuring reliability, performance, security, and maintainability. Lead architectural decisions, mentor engineers, manage incident response, improve system health, and communicate effectively with technical and non-technical stakeholders. The role requires extensive Ruby on Rails, AWS or equivalent cloud infrastructure, Linux production operations, frontend development, relational databases, testing, CI/CD, and observability experience.
Top Skills: AWSCi/CdIso 27001JavaScriptJIRALinuxMySQLNginxNistOauthReactRedisRuby On RailsSAMLScrumSoc 2Stimulus
10 Minutes Ago
Remote or Hybrid
178K-264K Annually
Mid level
178K-264K Annually
Mid level
Artificial Intelligence • Information Technology • Machine Learning • Natural Language Processing • Productivity • Software • Generative AI
Sell Superhuman's Go platform and multi-product bundles to commercial accounts (250-4,999 employees). Own full sales cycle, build pipeline, develop executive relationships, navigate complex procurement and legal processes, collaborate with Sales Engineering and Product, and establish the Commercial playbook while maintaining Salesforce CRM discipline and accurate forecasting.
Top Skills: AICodaCRMMeddpiccSalesforceSuperhuman GoSuperhuman Mail

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account