Manager, GRC Engineering

Reposted 4 Days Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
Senior level
Artificial Intelligence • Information Technology • Software
The Role
Serve as a virtual CISO for a client portfolio: build executive relationships, lead security program and compliance roadmaps (SOC 2, ISO 27001, NIST, HIPAA, CMMC), guide risk assessments and remediation, represent clients in high-stakes calls, manage 3–5 analysts, leverage GRC platforms (Vanta/Drata/SecureFrame), and support practice development and pre-sales.
Summary Generated by Built In
About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

Get to know the GRC Engineering Team


Our GRC Engineering team is the primary point of contact for Workstreet's clients. We bring deep framework compliance knowledge and program management to each engagement to ensure our clients' compliance goals are met. Our teammates are trusted advisors not only in the compliance space, but also operationally in the role of vCISO.  We deliver quickly using common templates and methodologies and are adept at creative problem-solving. GRC Engineering Team members also listen for and act as a centralized resource to advise clients on Workstreet's other service offerings to support their compliance, privacy, and information security goals.

The Opportunity

We are seeking a Manager, GRC Engineering (vCISO) who leads with a client-first mindset and brings the executive presence, technical depth, and relationship skills to serve as a trusted security leader for a portfolio of clients. The ideal candidate is a seasoned security professional who knows how to build trust with executive stakeholders, speak fluently about complex security architectures, and represent clients confidently on their most important prospect and customer calls.

The successful candidate will be able to come up to speed quickly, integrate into the organization, and take on clients within your first 30 days. You will serve as the dedicated virtual CISO for a portfolio of clients, owning strategic security relationships end-to-end, guiding risk and compliance decisions with authority, and ensuring every client can count on you as a security expert.

What You'll Do
  • Own the vCISO relationship end-to-end - serve as the dedicated virtual CISO for a portfolio of clients, operating with the executive authority, credibility, and trust of an embedded security leader.
  • Lead strategic client engagements and security roadmaps - guide clients from initial risk assessment through certification milestones, providing proactive executive guidance, strategic direction, and risk management aligned to business goals.
  • Represent clients on live prospect and customer calls - join client sales and due diligence calls as their acting CISO, answering technical security questions in real-time with total fluency in their architecture and controls without notes.
  • Handle high-stakes escalations with executive authority - resolve complex security issues and client escalations with urgency and composure, making independent, authoritative security calls without deferring judgment.
  • Deliver contextualized strategic security leadership - deeply understand each client's tech stack, business model, and risk appetite to produce custom architecture recommendations, threat models, policy sets, and executive briefings.
  • Lead comprehensive risk and compliance oversight - conduct risk assessments, maintain registers, and guide programs across frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, CMMC, NIST CSF/800-171, GDPR, CCPA, DORA, and NYDFS.
  • Manage continuous compliance and security operations - facilitate quarterly access reviews, annual pentests, and tabletop IR exercises while leveraging GRC platforms (Vanta, Drata, SecureFrame) for continuous audit readiness.
  • Maintain proactive client mastery - participate in regular syncs, contextualize GRC platform telemetry, track architectural changes, and identify emerging risks before they manifest into operational blockers.
  • Lead, coach, and develop a pod of GRC analysts - manage 3–5 analysts through direct coaching, performance management, and delivery oversight to drive high-quality execution across active client accounts.
  • Drive internal practice development and pre-sales - refine internal vCISO playbooks, mentor junior practice members, and join pre-sales scoping discussions to support proposal development.
Who You Are
  • Extensive information security leadership experience - you bring 8+ years of experience in information security, including at least 3 years in a senior security leadership role, driving security strategy, governance, and risk management across complex environments.
  • Demonstrated client relationship management - you're comfortable owning client engagements, leading difficult conversations, serving as a trusted security advisor, and building long-term relationships with executive stakeholders.
  • Executive-level security communication - you're confident discussing security architecture, compliance posture, and control trade-offs with clients and prospects, translating complex technical concepts into practical business decisions without sacrificing accuracy.
  • Deep expertise in cybersecurity frameworks - you have extensive hands-on knowledge of frameworks and standards such as SOC 2, ISO 27001, NIST CSF, HIPAA, HITRUST, NIST SP 800-171, and/or CMMC, helping organizations build and mature security programs.
  • Strong program and client management skills - you're experienced managing multiple security programs or client engagements simultaneously, ideally within consulting, advisory, or fractional security leadership environments.
  • Exceptional communication skills - you communicate with clarity, confidence, and precision, effectively translating technical risks into business language for executive, technical, and non-technical audiences.
  • Independent decision-maker - you're comfortable owning your client portfolio, exercising sound judgment, and making informed security decisions independently while maintaining accountability for outcomes.
  • Strong technical cloud security expertise - you have practical experience implementing and evaluating security controls across cloud platforms such as AWS, GCP, and Azure, with a solid understanding of cloud security architecture and best practices.
What will help you succeed
  • Active executive security credentials - hold recognized professional certifications such as CISSP, CISM, or CISA.
  • Fractional or vCISO practice tenure - prior experience delivering virtual CISO, fractional security leadership, or advisory services within a managed security service provider (MSSP) environment.
  • Compliance automation platform mastery - hands-on experience leveraging automated GRC platforms such as Vanta, Drata, or Secureframe for continuous posture tracking.
  • Demonstrated delivery of ISO 42001 - recent and hands-on experience as a lead implementor or lead auditor for ISO 42001.
  • Complex certification audit leadership - track record supporting client organizations through formal SOC 2 Type II audits, ISO 27001 certifications, or CMMC assessments.
  • Specialized framework familiarity - exposure to emerging or regulatory frameworks such as ISO 42001 (AI Management), GDPR, CCPA, DORA, or NIST 800-171.
  • Regulated sector domain expertise - industry experience navigating the unique security and regulatory constraints of SaaS, fintech, or healthcare.
What We Offer 
  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive 
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.


All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact [email protected]

Skills Required

  • 8+ years of experience in information security with at least 3 years in a senior security leadership role
  • Demonstrated experience managing client relationships and owning accounts in consulting or advisory contexts
  • Ability to speak fluently about security architecture, controls, and compliance in executive-level conversations
  • Deep working knowledge of security frameworks (SOC 2, ISO 27001, NIST CSF, HIPAA, HITRUST, NIST SP 800-171, CMMC)
  • Proven experience managing multiple security programs or client engagements simultaneously (consulting, fractional, or advisory background)
  • Exceptional written and verbal English communication skills
  • Independent decision-making and ownership of client security decisions
  • Strong knowledge of technical control implementation in cloud platforms (AWS, GCP, Azure)
  • Experience leading risk assessments, risk registers, treatment planning, and oversight of compliance operations (access reviews, pen tests, tabletop exercises)
  • Reliable high-speed internet connection and a quiet professional home office; amenable to working US time zone hours
  • CISSP, CISM, or equivalent certification
  • Prior experience in a vCISO, fractional CISO, or managed security services environment
  • Familiarity with compliance automation platforms such as Drata, Vanta, and SecureFrame
  • Experience supporting clients through SOC 2 Type II audits, ISO 27001 certification, or CMMC assessments
  • Familiarity with additional frameworks (ISO 42001, GDPR, CCPA, DORA, NIST 800-171)
  • Background in SaaS, fintech, healthcare, or defense contracting industries
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
102 Employees
Year Founded: 2023

What We Do

Workstreet is an AI-powered security firm. We deliver full stack solutions that transform security and compliance from operational anchors into growth accelerators. We work with thousands of companies - startups, hypergrowth scalers and enterprises that are at the cutting edge of disruptive innovation. Specifically, we support our customers with the following solutions: • Virtual CISO - dedicated security teams to help our customers build and scale security programs • AI Powered GRC Solutions - turnkey compliance for SOC2, ISO 27001, CMMC and 35+ frameworks • Security Questionnaires - AI powered, human in the loop solution to accelerate GTM teams • Penetration Testing - Penetration testing and vulnerability management for market and security demand • Vanta Implementation - Expert Vanta implementation, integration and migration; we are Vanta's #1 security solutions partner

Similar Jobs

Workstreet Logo Workstreet

Manager, GRC Engineering

Artificial Intelligence • Information Technology • Software
Remote
United States
102 Employees

Workstreet Logo Workstreet

Senior Manager, GRC Engineering (Special Programs)

Artificial Intelligence • Information Technology • Software
Remote
United States
102 Employees

Workstreet Logo Workstreet

Senior Manager, GRC Engineering

Artificial Intelligence • Information Technology • Software
Remote
United States
102 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account