Workstreet Logo

Workstreet

Senior Manager, GRC Engineering

Reposted 11 Days Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
The role involves overseeing cybersecurity compliance projects, managing teams, ensuring quality standards, and engaging with clients on compliance matters.
The summary above was generated by AI

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

Get to know the GRC Engineering Team


Our GRC Engineering team is the primary point of contact for Workstreet's clients. We bring deep framework compliance knowledge and program management to each engagement to ensure our clients' compliance goals are met. Our teammates are trusted advisors not only in the compliance space, but also operationally in the role of vCISO.  We deliver quickly using common templates and methodologies and are adept at creative problem-solving. GRC Engineering Team members also listen for and act as a centralized resource to advise clients on Workstreet's other service offerings to support their compliance, privacy, and information security goals.

The Opportunity

We are seeking a Senior Manager, GRC Engineering who leads with a client-first philosophy and brings a proven track record of managing high-stakes client relationships with professionalism, care, and strategic insight. The ideal candidate is an experienced client relationship leader who understands that exceptional service is the foundation of everything we do — and who pairs that client focus with 8+ years of deep expertise in cybersecurity compliance frameworks such as SOC 2, ISO 27001, and NIST CSF.

Integrating quickly into the business within their first 15 days, the successful candidate will act as a high-level executive strategic partner to own account growth and long-term retention across a dedicated portfolio. In this role, you will serve as the trusted executive interface, driving proactive engagement and holistic account health while directing an operational pod that manages day-to-day delivery. You will handle escalations with urgency and poise, keeping clients continuously engaged, valued, and retained through high-impact strategic partnership.

What You'll Do
  • Own executive-level client relationships as the senior strategic point of contact for a high-priority portfolio, building deep trust, driving retention, and resolving high-stakes client escalations with absolute composure and urgency.
  • Provide overarching program governance across multiple compliance engagements, ensuring tech-sector clients remain fully prepared, informed, and calibrated throughout complex audits and certification lifecycles.
  • Supervise, mentor, and upscale a high-performing team of subordinate managers and GRC analysts, embedding a performance-driven culture focused on strict operational accountability and clear professional growth.
  • Drive departmental resource and capacity strategy, directing hiring, target profiles, and optimized workload allocation models to seamlessly support the business as it scales.
  • Establish and enforce rigorous quality benchmarks across the delivery team, verifying that every piece of technical documentation and client communication reflects the highest standard of execution.
  • Engage directly with US-based client executives and technology founders, executing proactive multi-channel communications to dismantle complex compliance roadblocks and provide tailored risk advisory.
  • Develop, execute, and maintain enterprise-grade security policies and procedures, translating dense global regulations (including SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, HiTRUST, and NIST/CMMC) into scalable, operational controls.
  • Partner cross-functionally with internal and external teams to systematically isolate, evaluate, and remediate technical cybersecurity risks and framework deficiencies.
Who You Are
  • Executive portfolio commander - Command high-complexity client engagements, dismantle high-stakes structural escalations at the leadership tier, and confidently influence senior C-suite stakeholders to preserve long-term loyalty.
  • Elite corporate communicator - Assert flawless, authoritative written and verbal English communication capable of effortlessly translating dense technical risk data into clear business value for diverse audiences.
  • Scale-oriented enterprise people leader - Bring 5+ years of dedicated experience leading, upskilling, and managing mid-sized technical or professional services teams, explicitly demonstrating the capability to lead through subordinate people managers.
  • Cybersecurity compliance authority - Command 8+ years of direct, hands-on execution designing, implementing, and defending mature compliance programs across global frameworks (including SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, HiTRUST, and NIST/CMMC).
  • Policy governance architect - Bring 8+ years of experience engineering and enforcing technical security policies that seamlessly align rigorous regulatory mandates with fluid business growth objectives.
  • High-velocity startup operator - Thrive within volatile, fast-growth technology ecosystems, possessing the immediate operational agility to fully integrate into an organization and absorb strategic client accounts within your first 15 days.
  • Disciplined program navigator - Command macro-level organization and program management mechanics to oversee multiple concurrent compliance engagements simultaneously without degrading delivery quality or missing deadlines.
  • Domain-native technology strategist - Verifiable tenure operating within cybersecurity-focused SaaS or technology corporations where security governance, risk assessment, and technical compliance serve as core business differentiators.
What will help you succeed
  • Big 4 advisory or assurance tenure - Prior success directing technical IT compliance audits, data governance assessments, or complex risk assurance workflows inside elite environments like Deloitte, PwC, EY, or KPMG.
  • GRC consultancy lifecycle execution - Direct history managing compliance engineering functions or vCISO delivery tracks within a high-volume managed security services provider (MSSP) or specialized security consulting practice.
  • Validated industry credentials - Hold active, globally recognized professional security and audit designations such as CISA, CISSP, CISM, ISO 27001 Lead Implementer, or CRISC.
  • Mastery of compliance automation architectures - Direct backend operational mastery navigating, configuring, and tracking continuous evidence collection inside automated platforms like Vanta, Drata, or Secureframe.
  • Multi-framework audit orchestration - Deep practical exposure designing, mapping, and defending data-driven risk management methodologies across a diverse spectrum of intersecting international regulations.
What We Offer
  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive 
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.

All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact [email protected]

Similar Jobs

2 Days Ago
Remote
United States
Senior level
Senior level
Artificial Intelligence • Information Technology • Software
Lead operational delivery for Special Programs, managing 30–40 consultants via 4–5 managers. Own program health, timelines, quality standards, capacity planning, escalations, and executive client relationships. Coach first-line managers, perform performance management, review deliverables for technical rigor, and mitigate delivery risks to ensure client satisfaction across multiple compliance frameworks.
Top Skills: CmmcDrataFedrampGdprHipaaHitrustIso 27001Nist 800-171Nist 800-53Pci DssSecureframeSoc 2Vanta
6 Minutes Ago
Remote or Hybrid
OH, USA
130K-175K Annually
Expert/Leader
130K-175K Annually
Expert/Leader
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead enterprise account strategy and close new business across the Columbus region. Manage and expand relationships with CIO/CSO-level executives, coordinate cross-functional teams, use Salesforce.com for pipeline management, and travel up to 50% to meet quota and drive revenue growth for cybersecurity SaaS solutions.
Top Skills: AICloudCybersecuritySaaSSalesforce
6 Minutes Ago
In-Office or Remote
92K-164K Annually
Senior level
92K-164K Annually
Senior level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Supervise 1–3 analysts and oversee recurring financial reporting, reconciliations, healthcare data analysis, and decision support. Develop reporting systems and processes, ensure timely external data loads, coordinate analytical support across business departments, partner with Business Intelligence to automate reporting, and present findings and recommendations to executives and internal or external stakeholders.
Top Skills: Ansi 5010 837ClarityCrystal ReportsEpicMicrosoft AccessMinitabRSASSpssSQL

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account