Workstreet Logo

Workstreet

Senior GRC Engineer - GOV (FedRAMP 20x)

Posted 27 Days Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Lead federal compliance engagements for clients pursuing FedRAMP and NIST certifications. Own strategic advisory, gap assessments, FedRAMP 20x readiness, OSCAL/JSON/YAML machine-readable artifacts, CCM continuous monitoring integrations, and third-party assessment orchestration while mentoring a small compliance team and maintaining executive client relationships.
The summary above was generated by AI
About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.  We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.  We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the GRC Engineering (GOV) Team
Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment & Authorization compliance efforts. We act as our clients' trusted guides and primary point of contact end-to-end, leading them through gap assessments, System Security Plans, POA&Ms, and C3PAO/3PAO coordination with clarity, composure, and a genuinely client-first mindset. Beyond the technical depth in RMF, CUI/DFARS requirements, and GovCloud environments, what defines us is how we work: we translate complex requirements into plain language, manage escalations with urgency and care, and take real pride in making every client feel informed, supported, and well-prepared. We're a group that mentors one another, holds a high bar for quality, and thrives in a fast-paced environment where our work directly strengthens the security of the defense industrial base.

The Opportunity

Workstreet is seeking a Senior GRC Engineer (Government) to serve as a high-touch, executive-level strategic partner for organizations navigating federal compliance frameworks. Built around client relationship excellence, this role centers on delivering an exceptional client experience, cultivating trusted advisor relationships, and maintaining account retention across high-stakes engagements. You will guide clients through complex federal certifications while directing a team of primary operators who manage day-to-day execution across CMMC, NIST SP 800-171, NIST SP 800-53, and FedRAMP 20x standards.

The successful candidate will integrate rapidly into the organization and assume active portfolio ownership within their first 15 days. Rather than focusing solely on routine task execution, you will lead end-to-end strategic engagements, handle escalations with composure, and represent clients on executive calls to ensure every partner remains deeply engaged, highly satisfied, and aligned with Workstreet in the long term during U.S. Eastern Time business hours.

What You'll Do
  • Lead federal certification advisory motions - guide clients through FedRAMP 20x, Assessment & Authorization (A&A), and federal compliance lifecycles with clear milestone direction.
  • Deliver executive-level compliance guidance - act as a trusted advisor, translating complex CR26 rules, 46 Key Security Indicators (KSIs), and federal standards into business language across cross-functional units like Legal, People, Engineering, and Finance.
  • Architect cloud-native automated GRC operations - deploy and integrate automated compliance processes within AWS, Azure, or GCP environments and existing client toolstacks.
  • Deploy enterprise security and AI tool integrations - connect GRC workflows with client IAM, vulnerability management, SIEM, and security-based SaaS solutions.
  • Architect Infrastructure and Policy as Code - implement compliance automation using Infrastructure as Code (Terraform, Pulumi), Policy as Code (OPA/Rego), and AI-powered agentic workflows.
  • Direct and develop compliance pods - mentor, coach, and manage a small team of compliance professionals, enforcing quality standards and delivery accountability across engagements.
  • Build machine-readable compliance artifacts - author and maintain Security Decision Records, Security Configuration Guides, and OSCAL/JSON/YAML artifacts conforming to RFC-0024 and OMB M-24-15 mandates.
  • Execute federal gap and readiness reviews - conduct comprehensive gap assessments and control mapping across FedRAMP 20x Class A, Class B, and Class C requirements.
  • Orchestrate third-party assessment activities - guide clients through 3PAO assessments, C3PAO audits, and independent assessor evaluations with speed and technical rigor.
Who You Are
  • Cloud GRC automation architect - possess 5+ years of direct technical experience in AWS, Azure, or GCP, architecting and integrating automated GRC operations directly within cloud environments.
  • Federal compliance leader - bring 5+ years of experience implementing federal compliance, NIST SP 800-53, FedRAMP Rev5, or Risk Management Framework (RMF) standards, including end-to-end program management.
  • End-to-end engagement owner - bring 3+ years of experience leading multi-project client engagements, building long-term executive trust, and managing account retention in consulting settings.
  • Security stack integration specialist - hands-on experience deploying and integrating GRC frameworks with enterprise IAM, vulnerability management, SIEM, and SaaS security tooling.
  • Compliance-as-code and AI practitioner - proficient with Infrastructure as Code (Terraform, Pulumi), Policy as Code (OPA/Rego), and designing AI-powered automation or agentic workflows.
  • 3PAO audit and Rev5 veteran - direct experience interfacing with 3PAO organizations and running end-to-end compliance programs for organizations holding FedRAMP Class C, Class D, or Rev5 certifications.
  • Cross-functional business translator - adept at communicating complex GRC and security concepts to non-technical stakeholders across client Legal, People, Engineering, and Finance teams.
What will help you succeed
  • Active federal security credentials - hold recognized certifications such as CISSP, CISM, CGRC, or Certified Authorization Professional (CAP).
  • Validated cloud architecture credentials - active technical certifications such as AWS Solutions Architect Associate, Azure Security Engineer, or GCP Associate Cloud Engineer.
  • Collaborative continuous monitoring experience - documented history managing FedRAMP certification activities and real-time Continuous Monitoring (CCM) workflows.
  • Hands-on OSCAL schema mastery - practical experience authoring or validating machine-readable SSPs, POA&Ms, or KSI evidence utilizing OSCAL, JSON, or YAML schemas.
What We Offer
  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process 
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.


All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact [email protected] 

Similar Jobs

2 Minutes Ago
Remote
US
Senior level
Senior level
Artificial Intelligence • Cybersecurity
Own new business across North American betting and gaming, generating pipeline, winning new logos, and managing sales processes through close. Build relationships with operators and platform providers, sell fraud prevention, AML, and identity solutions, maintain accurate CRM forecasting, and collaborate with marketing, product, partnerships, and customer success. Serve as the internal voice of the vertical while staying informed on regulatory and competitive developments.
Top Skills: AmlCRMFraud PreventionIdentity VerificationSaaS
7 Minutes Ago
Remote
Florida, USA
43K-78K Annually
Junior
43K-78K Annually
Junior
Other • Utilities
Prospect and acquire small and medium-sized business customers within an assigned territory. Generate leads through cold calling, networking, and other prospecting methods; assess customer needs; recommend wireless products and services; negotiate and close deals; manage sales funnels and forecasts; and grow the customer base while meeting or exceeding sales quotas.
Top Skills: Sales Force AutomationWireless Telecommunications
59 Minutes Ago
Remote
United States
20-150K Annually
Entry level
20-150K Annually
Entry level
Software • Database • Facilities Maintenance
Full-cycle enterprise sales role responsible for prospecting, developing, qualifying, and closing deals with large, multi-stakeholder organizations. The position sells FacilitiesLink, a facilities information platform for planning, building, and operating large-scale campus environments. Compensation includes 50% commission, a $20-per-hour guaranteed draw, and on-target earnings starting at $150,000 annually. Flexible work arrangements are available, with occasional travel required.
Top Skills: Enterprise DatabasesFacilities Information SystemsFacilitieslink

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account