Senior GRC Engineer (NIST 800-53/FedRAMP)

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
Senior level
Artificial Intelligence • Information Technology • Software
The Role
Lead client-facing federal compliance engagements for NIST SP 800-53 and FedRAMP: perform gap assessments, develop SSPs and POA&Ms, coordinate A&A with 3PAOs, mentor a small compliance team, and drive remediation and continuous monitoring for FedRAMP baselines.
Summary Generated by Built In

About Workstreet
At Workstreet, we're on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of frameworks — including SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP — empowering companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

The Opportunity

We are seeking a Sr. GRC Engineer (Government) who is highly motivated, detail-oriented, and experienced with these compliance frameworks. The ideal candidate will have strong communication skills, proven ability to manage multiple projects, and experience leading or mentoring a small team.

What You'll Do
Client Relationship Management (Primary Focus)
  • Guide Clients Through Federal Authorization Processes: Lead clients through NIST SP 800-53 and FedRAMP compliance initiatives, providing proactive communication, clear milestone guidance, and hands-on support throughout the Assessment and Authorization (A&A) lifecycle.
  • Collaborate Closely with Clients: Partner directly with organizations pursuing federal authorizations to understand their environment, identify security gaps, and drive progress toward achieving and maintaining compliance.
  • Be a Trusted Compliance Advisor: Deliver expert guidance on NIST SP 800-53, FedRAMP requirements, and federal cybersecurity standards in a way that is accessible, actionable, and aligned with each client's unique operational environment.


Team Leadership

  • Lead and Mentor a Compliance Team: Provide direction, feedback, and professional development support to a small team of compliance professionals, maintaining quality standards and accountability across client engagements.
  • Drive Consistent Delivery: Manage and coordinate multiple NIST SP 800-53 and FedRAMP compliance projects across various clients, ensuring milestones and deliverables are met ahead of authorization deadlines.

NIST 800-53 & FedRAMP Compliance Execution

  • Interpret and Apply Security Controls: Analyze and interpret NIST SP 800-53 security and privacy controls and control baselines to ensure client compliance with federal cybersecurity standards.
  • Develop and Maintain Authorization Documentation: Create, implement, and maintain System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and other authorization documentation required for NIST SP 800-53 and FedRAMP.
  • Conduct Gap Assessments: Perform readiness reviews to identify and address control deficiencies for organizations pursuing an Authorization to Operate (ATO) or FedRAMP authorization.
  • Support Assessment Activities: Guide clients through the Assessment and Authorization (A&A) process and coordinate with Third-Party Assessment Organizations (3PAOs) and independent assessors.
  • Collaborate on Remediation Efforts: Work closely with clients to identify and remediate gaps in their security programs to meet NIST SP 800-53 Low, Moderate, and High control baselines.
  • Monitor Regulatory Updates: Stay current on evolving NIST SP 800-53 revisions, FedRAMP requirements, and federal cybersecurity policies and guidance to ensure client programs remain compliant and ahead of changing requirements.
Who You Are
Required
  • Strong organizational skills with the ability to manage multiple NIST SP 800-53 compliance projects concurrently.
  • 5+ years of experience in federal compliance, NIST SP 800-53, FedRAMP, or RMF implementation.
  • 3+ years of leadership experience managing or guiding a small team.
  • Deep understanding of the NIST Risk Management Framework (RMF) and the security and privacy control families within NIST SP 800-53.
  • Experience with NIST SP 800-53 control implementation and assessment.
  • Familiarity with FedRAMP authorization paths and federal agency workflows.
  • Experience working with cloud service providers (CSPs) or organizations pursuing federal authorizations.
  • Knowledge of common FedRAMP-authorized cloud environments such as AWS GovCloud, Azure Government, or GCC High.
  • Thrives in a fast-paced startup environment.
Nice to Have
  • CGRC (Certified in Governance, Risk and Compliance) or CAP (Certified Authorization Professional) certification.
  • Security+ or CISSP certification.
  • Experience with FedRAMP authorization and continuous monitoring (ConMon) activities.
  • Previous experience working directly with 3PAOs or as part of security assessment teams.
What We Offer
  • Career Development: Clear growth path with mentorship and training opportunities
  • Technical Training: Comprehensive onboarding on security and compliance frameworks
  • Competitive Compensation: Competitive base salary with regular performance reviews, merit-based appraisals, and bonus opportunities
  • Growth Opportunity: Early-stage company with significant room for career advancement
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team
Work Environment Requirements
  • Reliable high-speed internet connection
  • Quiet, professional home office setup
  • Must be amenable to working US Eastern Time zone hours
  • Fluency in written and verbal English communication skills

Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.

Employment with Workstreet is contingent upon the successful completion of a background check, which may include verification of employment history, education, and other relevant information, in compliance with applicable laws.


Skills Required

  • 5+ years of experience in federal compliance, NIST SP 800-53, FedRAMP, or RMF implementation
  • 3+ years of leadership experience managing or guiding a small team
  • Deep understanding of the NIST Risk Management Framework (RMF) and NIST SP 800-53 control families
  • Experience with NIST SP 800-53 control implementation and assessment
  • Familiarity with FedRAMP authorization paths and federal agency workflows
  • Experience working with cloud service providers (CSPs) or organizations pursuing federal authorizations
  • Knowledge of FedRAMP-authorized cloud environments such as AWS GovCloud, Azure Government, or GCC High
  • Strong organizational skills and ability to manage multiple NIST SP 800-53 compliance projects concurrently
  • Amenable to working US Eastern Time zone hours
  • Reliable high-speed internet connection and quiet professional home office setup
  • Fluency in written and verbal English communication skills
  • CGRC or CAP certification
  • Security+ or CISSP certification
  • Experience with FedRAMP continuous monitoring (ConMon) activities
  • Previous experience working directly with 3PAOs or as part of security assessment teams
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
102 Employees
Year Founded: 2023

What We Do

Workstreet is an AI-powered security firm. We deliver full stack solutions that transform security and compliance from operational anchors into growth accelerators. We work with thousands of companies - startups, hypergrowth scalers and enterprises that are at the cutting edge of disruptive innovation. Specifically, we support our customers with the following solutions: • Virtual CISO - dedicated security teams to help our customers build and scale security programs • AI Powered GRC Solutions - turnkey compliance for SOC2, ISO 27001, CMMC and 35+ frameworks • Security Questionnaires - AI powered, human in the loop solution to accelerate GTM teams • Penetration Testing - Penetration testing and vulnerability management for market and security demand • Vanta Implementation - Expert Vanta implementation, integration and migration; we are Vanta's #1 security solutions partner

Similar Jobs

BuildOps Logo BuildOps

Manager, PMO

Cloud • Mobile • Software
Easy Apply
Remote or Hybrid
United States
500 Employees

Coinbase Logo Coinbase

Senior Software Engineer

Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Easy Apply
Remote
USA
4700 Employees

Gusto Logo Gusto

Senior Account Executive

Fintech • HR Tech
Easy Apply
Remote or Hybrid
7 Locations
4405 Employees
115K-150K Annually

Nexthink Logo Nexthink

Enterprise Account Executive

Artificial Intelligence • Big Data • Cloud • Information Technology • Machine Learning • Software
Remote or Hybrid
Boston, MA, USA
1200 Employees
150K-360K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account