GRC Engineer
United States · Remote · Full-time
- Posted 2w ago
- From Workstreet’s careers page
- Location
- United States
- Work mode
- Remote
- Type
- Full-time
- Level
- Senior
- Experience
- 3+ years
- Department
- Information Technology
Opens the listing on ats.rippling.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
The Opportunity
We are seeking a highly motivated, client-focused Sr. GRC Engineer to join our fast-growing team. The ideal candidate is a seasoned client relationship manager who brings deep expertise in cybersecurity compliance and a proven track record of leading high-complexity client engagements with professionalism and care. This role is first and foremost about delivering an exceptional client experience — managing accounts, building trust, and driving successful outcomes — while overseeing a pod of analysts and applying expertise across frameworks such as SOC 2, ISO 27001, and NIST CSF.
The successful candidate will be able to come up to speed quickly, integrate into the organization, and take on clients within your first 15 days. You will serve as the primary point of contact for a portfolio of clients, leading engagements end-to-end, managing escalations with composure and urgency, and ensuring every client interaction reflects the highest standard of service.
What You'll Do
- Own the client relationship lifecycle as the dedicated primary contact for a portfolio of high-complexity, long-term accounts, ensuring premium delivery, milestone tracking, and proactive account management.
- Lead end-to-end compliance engagements, directing routine milestone check-ins, delivering progress logs, and steering tech clients confidently through dense audit lifecycles.
- Execute direct client communications, partnering closely with US-based client executives, DevOps leads, and technology founders via multi-channel pathways to provide tailored risk guidance.
- Resolve complex account escalations swiftly and professionally, applying a clinical, solution-oriented approach that solidifies long-term retention, customer satisfaction, and trust.
- Supervise, mentor, and upscale a pod of junior analysts, managing day-to-day operations, implementing constructive feedback loops, and driving rigorous delivery standards.
- Analyze and apply global cybersecurity frameworks, mapping technical environments and corporate architectures against SOC 2, ISO 27001, HIPAA, and NIST CSF baselines.
- Formulate and maintain enterprise compliance programs, authoring foundational security policies, operational procedures, and audit-ready control documentation.
- Partner cross-functionally with internal and external teams to systematically isolate, evaluate, and mitigate operational cybersecurity and data compliance risks.
- Drive continuous process improvement, modifying standard operating procedures, technical playbooks, and internal assessment frameworks to optimize team execution velocity.
Who You Are
- Proven client relationship manager – Command a documented history of independently owning high-consequence client accounts, successfully navigating difficult risk conversations, and building trusted advisor status with C-suite stakeholders.
- Elite corporate communicator – Deliver flawless written and verbal English communication capable of confidently breaking down complex technical parameters for US-based tech founders and cross-functional business units.
- Scale-oriented team leader – Bring 3+ years of experience managing, upskilling, and leading a technical pod, squad, or small team, with a verifiable track record of driving accountability and project results.
- Hands-on GRC program architect – Bring 3+ years of practical experience constructing, implementing, and defending robust compliance programs under SOC 2, ISO 27001, or NIST CSF architectures.
- Disciplined portfolio manager – Command sharp project management mechanics to successfully orchestrate multiple multi-threaded compliance engagements simultaneously without losing delivery quality.
- High-velocity startup operator – Excel within fluid, fast-growth technology environments, possessing the immediate operational agility to fully integrate into an organization and absorb complex client portfolios within your first 15 days.
- Policy governance architect – Experienced engineering, maintaining, and enforcing enterprise cybersecurity policies that seamlessly align strict regulatory criteria with business growth targets.
- Domain-native tech professional – Verifiable tenure operating within cybersecurity-focused technology organizations where security governance, risk assessment, and technical compliance serve as core business differentiators.
What will help you succeed
- Big 4 advisory or assurance tenure – Prior success directing complex IT compliance audits, data governance assessments, or technical risk advisory workflows inside elite environments like Deloitte, PwC, EY, or KPMG.
- Multi-framework compliance command – Advanced familiarity with specialized, adjacent international frameworks and regulatory bodies, explicitly including HIPAA, PCI DSS, or regional data sovereignty baselines.
- Mastery of compliance automation architectures – Direct backend operational mastery navigating, configuring, and tracking continuous evidence collection inside automated platforms like Vanta.
- Validated industry credentials – Hold active, globally recognized professional security and audit designations such as CISA, CISSP, ISO 27001 Lead Implementer, or CompTIA Security+.
- Advanced audit coordination background – Proven history managing full-lifecycle third-party assessments, audit pathways, and independent examiner walkthroughs.
What we offer
- Career Development: Clear path with mentorship and training opportunities.
- Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
Skills they ask for
Pick one to see other roles that ask for it.
About Workstreet
Cybersecurity and compliance for growing companiesWorkstreet provides cybersecurity and compliance support for growing companies, including security programs, virtual CISO services, penetration testing, and questionnaire automation.
See all 16 roles at WorkstreetMore roles at Workstreet
See all 16- Human Resources AdministratorGurugram · Entry Level · On-siteHuman Resources · Entry Level · On-siteGurugram, India2d
- Account ExecutiveUnited States · Entry Level · RemoteSales · Entry Level · RemoteUnited States2d
- Vulnerability Management EngineerGurugram · Senior · RemoteInformation Technology · Senior · RemoteGurugram, India2d
- Senior GRC EngineerUnited States · Senior · RemoteInformation Technology · Senior · RemoteUnited States2d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.