Senior GRC Engineer - GOV (FedRAMP 20x)

Posted 27 Days Ago
Hiring Remotely in United States
Remote
Senior level
Artificial Intelligence • Information Technology • Software
The Role
Lead federal compliance engagements for clients pursuing FedRAMP and NIST certifications. Own strategic advisory, gap assessments, FedRAMP 20x readiness, OSCAL/JSON/YAML machine-readable artifacts, CCM continuous monitoring integrations, and third-party assessment orchestration while mentoring a small compliance team and maintaining executive client relationships.
Summary Generated by Built In
About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.  We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.  We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the GRC Engineering (GOV) Team
Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment & Authorization compliance efforts. We act as our clients' trusted guides and primary point of contact end-to-end, leading them through gap assessments, System Security Plans, POA&Ms, and C3PAO/3PAO coordination with clarity, composure, and a genuinely client-first mindset. Beyond the technical depth in RMF, CUI/DFARS requirements, and GovCloud environments, what defines us is how we work: we translate complex requirements into plain language, manage escalations with urgency and care, and take real pride in making every client feel informed, supported, and well-prepared. We're a group that mentors one another, holds a high bar for quality, and thrives in a fast-paced environment where our work directly strengthens the security of the defense industrial base.

The Opportunity

Workstreet is seeking a Senior GRC Engineer (Government) to serve as a high-touch, executive-level strategic partner for organizations navigating federal compliance frameworks. Built around client relationship excellence, this role centers on delivering an exceptional client experience, cultivating trusted advisor relationships, and maintaining account retention across high-stakes engagements. You will guide clients through complex federal certifications while directing a team of primary operators who manage day-to-day execution across CMMC, NIST SP 800-171, NIST SP 800-53, and FedRAMP 20x standards.

The successful candidate will integrate rapidly into the organization and assume active portfolio ownership within their first 15 days. Rather than focusing solely on routine task execution, you will lead end-to-end strategic engagements, handle escalations with composure, and represent clients on executive calls to ensure every partner remains deeply engaged, highly satisfied, and aligned with Workstreet in the long term during U.S. Eastern Time business hours.

What You'll Do
  • Lead federal certification advisory motions - guide clients through FedRAMP 20x, Assessment & Authorization (A&A), and federal compliance lifecycles with clear milestone direction.
  • Deliver executive-level compliance guidance - act as a trusted advisor, translating complex CR26 rules, 46 Key Security Indicators (KSIs), and federal standards into business language across cross-functional units like Legal, People, Engineering, and Finance.
  • Architect cloud-native automated GRC operations - deploy and integrate automated compliance processes within AWS, Azure, or GCP environments and existing client toolstacks.
  • Deploy enterprise security and AI tool integrations - connect GRC workflows with client IAM, vulnerability management, SIEM, and security-based SaaS solutions.
  • Architect Infrastructure and Policy as Code - implement compliance automation using Infrastructure as Code (Terraform, Pulumi), Policy as Code (OPA/Rego), and AI-powered agentic workflows.
  • Direct and develop compliance pods - mentor, coach, and manage a small team of compliance professionals, enforcing quality standards and delivery accountability across engagements.
  • Build machine-readable compliance artifacts - author and maintain Security Decision Records, Security Configuration Guides, and OSCAL/JSON/YAML artifacts conforming to RFC-0024 and OMB M-24-15 mandates.
  • Execute federal gap and readiness reviews - conduct comprehensive gap assessments and control mapping across FedRAMP 20x Class A, Class B, and Class C requirements.
  • Orchestrate third-party assessment activities - guide clients through 3PAO assessments, C3PAO audits, and independent assessor evaluations with speed and technical rigor.
Who You Are
  • Cloud GRC automation architect - possess 5+ years of direct technical experience in AWS, Azure, or GCP, architecting and integrating automated GRC operations directly within cloud environments.
  • Federal compliance leader - bring 5+ years of experience implementing federal compliance, NIST SP 800-53, FedRAMP Rev5, or Risk Management Framework (RMF) standards, including end-to-end program management.
  • End-to-end engagement owner - bring 3+ years of experience leading multi-project client engagements, building long-term executive trust, and managing account retention in consulting settings.
  • Security stack integration specialist - hands-on experience deploying and integrating GRC frameworks with enterprise IAM, vulnerability management, SIEM, and SaaS security tooling.
  • Compliance-as-code and AI practitioner - proficient with Infrastructure as Code (Terraform, Pulumi), Policy as Code (OPA/Rego), and designing AI-powered automation or agentic workflows.
  • 3PAO audit and Rev5 veteran - direct experience interfacing with 3PAO organizations and running end-to-end compliance programs for organizations holding FedRAMP Class C, Class D, or Rev5 certifications.
  • Cross-functional business translator - adept at communicating complex GRC and security concepts to non-technical stakeholders across client Legal, People, Engineering, and Finance teams.
What will help you succeed
  • Active federal security credentials - hold recognized certifications such as CISSP, CISM, CGRC, or Certified Authorization Professional (CAP).
  • Validated cloud architecture credentials - active technical certifications such as AWS Solutions Architect Associate, Azure Security Engineer, or GCP Associate Cloud Engineer.
  • Collaborative continuous monitoring experience - documented history managing FedRAMP certification activities and real-time Continuous Monitoring (CCM) workflows.
  • Hands-on OSCAL schema mastery - practical experience authoring or validating machine-readable SSPs, POA&Ms, or KSI evidence utilizing OSCAL, JSON, or YAML schemas.
What We Offer
  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process 
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.


All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact [email protected] 

Skills Required

  • 5+ years of direct experience implementing federal compliance (NIST SP 800-53, FedRAMP, or RMF)
  • 3+ years leading multi-project client engagements and managing account retention
  • Deep familiarity with FedRAMP 20x program certifications and Rev5 agency certifications
  • Hands-on cloud security experience across AWS, Azure, and GCP, including AWS GovCloud or Azure Government
  • Working ability with scripting and policy-as-code tooling (Python, OPA/Rego, IaC)
  • Practical experience with 3PAO/C3PAO assessments or as part of security assessment teams
  • Experience authoring or validating machine-readable SSPs, POA&Ms, or KSI evidence using OSCAL/JSON/YAML
  • Excellent written and verbal English communication skills
  • Ability to work standard 8:00 AM-5:00 PM US Eastern Time and participate in live video interviews with camera on
  • Authorized to work in the U.S. without visa sponsorship (employer does not sponsor visas)
  • Reliable high-speed internet and professional home office environment
  • Willingness/ability to travel locally for occasional onsite meetings or team gatherings
  • Active federal security certifications (CISSP, CISM, CGRC, CAP)
  • Cloud architecture certifications (AWS Solutions Architect, Azure Security Engineer, GCP Associate Cloud Engineer)
  • Documented continuous monitoring (CCM) and FedRAMP certification lifecycle management experience
  • Practical OSCAL schema mastery and history authoring machine-readable compliance artifacts
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
102 Employees
Year Founded: 2023

What We Do

Workstreet is an AI-powered security firm. We deliver full stack solutions that transform security and compliance from operational anchors into growth accelerators. We work with thousands of companies - startups, hypergrowth scalers and enterprises that are at the cutting edge of disruptive innovation. Specifically, we support our customers with the following solutions: • Virtual CISO - dedicated security teams to help our customers build and scale security programs • AI Powered GRC Solutions - turnkey compliance for SOC2, ISO 27001, CMMC and 35+ frameworks • Security Questionnaires - AI powered, human in the loop solution to accelerate GTM teams • Penetration Testing - Penetration testing and vulnerability management for market and security demand • Vanta Implementation - Expert Vanta implementation, integration and migration; we are Vanta's #1 security solutions partner

Similar Jobs

NBCUniversal Logo NBCUniversal

Security Engineer

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
New York, NY, USA
125K-155K Annually

NBCUniversal Logo NBCUniversal

Director, Technical Operations Finance

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
New York, NY, USA
130K-165K Annually

Atlassian Logo Atlassian

Product Design Intern, 2027 Summer U.S.

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
San Francisco, CA, USA
11000 Employees
41-56 Hourly

Atlassian Logo Atlassian

Senior Machine Learning Engineer

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
In-Office or Remote
San Francisco, CA, USA
11000 Employees
171K-269K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account