Our client is a Security & Compliance Service Growth firm that specializes in transforming security and compliance from a perceived obstacle into a strategic growth enabler. Whether you're pursuing SOC 2, ISO 27001, CMMC, NIST CSF, or another framework, they don't just advise. They execute with precision.
Our valuesThe GRC Engineer is a strategic, high-impact position for someone who can serve as a dependable leader.
This role is built for a proactive professional who independently drives complex compliance initiatives and stays ahead of emerging regulatory trends. You will work across a diverse client base, building rapport with stakeholders to ensure consistent progress on control implementation and audit readiness.
The ideal candidate brings a high degree of technical autonomy and a specialized GRC background with both implementer and auditor experience.
Core RequirementsHands-on implementer and auditor experience: Professional auditing experience, plus experience building a security program on the implementation side.
Framework expertise: Expert, hands-on experience leading Cybersecurity Maturity Model Certification (CMMC) Level 2 projects and standing up ISO 27001 Information Security Management Systems (ISMS) from scratch.
Microsoft GCC High: Direct experience managing and operating within Microsoft GCC High environments to maintain strict compliance standards.
Security engineering aptitude: Technically proficient and comfortable navigating cloud environments, with the agility to serve as a technical backup for broader operational tasks.
Security leadership mindset: A big-picture, risk-based approach to building defensible security programs, with the ability to design and implement programs that are not just compliant, but practical too.
Proactive ownership: A self-starter committed to tracking emerging regulatory trends, executive orders, and framework updates to proactively evolve internal and client policies.
Incident response and security operations: Ability to facilitate and support incident response tabletop exercises, and to create and leverage playbooks for security events.
Compliance Frameworks & Standards
Platforms & Environments
SOC 2
Amazon Web Services (AWS)
ISO 27001
Microsoft Azure
CMMC
Microsoft GCC High
NIST 800-171
GRC automation platforms
What They Offer
Health and dental insurance
401(k) plan and Match
Paid time off
Skills Required
- Professional auditing experience
- Hands-on experience building and implementing a security program
- Expert hands-on experience leading CMMC Level 2 projects
- Experience standing up ISO 27001 ISMS programs from scratch
- Direct experience managing and operating within Microsoft GCC High environments
- Technical proficiency navigating cloud environments
- Ability to design and implement practical, risk-based security programs
- Ability to track regulatory trends, executive orders, and framework updates
- Ability to facilitate incident response tabletop exercises
- Ability to create and leverage security incident playbooks
What We Do
SourceDirect Talent is a talent advisory and recruiting firm serving seed and early-stage startups. It provides AI-powered recruiting solutions to help customers build go-to-market and engineering teams, alongside global people consulting. Its services cover end-to-end recruitment, immigration, HR, and advisory support, using AI talent agents, sourcing frameworks, and data-driven processes to help growing companies scale hiring and improve recruitment capacity.
.jpg)








