Senior GRC Engineer
Workstreet
Full Time3+ yearsPosted about 8 hours ago
Let the right jobs find you
Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.
Overview
Position Type
Full Time
Experience
3+ years
Job Description
What You'll Do
- Own the client experience for complex accounts - serve as the dedicated primary point of contact for a portfolio of high-complexity, long-term client accounts, ensuring consistent delivery, proactive communication, and strong relationships at every stage.
- Lead client engagements through key milestones - conduct regular client meetings, deliver progress updates, set clear expectations, and guide clients through audits, assessments, and compliance milestones with clarity and confidence.
- Communicate directly with U.S.-based stakeholders - engage directly with U.S. clients via phone, email, and text to address compliance concerns, provide expert guidance, and ensure clients feel supported and informed.
- Handle escalations with a solution-oriented approach - resolve complex client issues swiftly and professionally, applying a composed approach that reinforces client trust and satisfaction.
- Act as a trusted compliance advisor - build long-term relationships by understanding each client's unique business context and delivering practical, relevant, and actionable compliance guidance.
- Manage and develop a pod of junior analysts - provide day-to-day direction, constructive feedback, and professional development support to a small team of analysts, fostering a high-performance culture.
- Drive team delivery and accountability - ensure the pod delivers high-quality work on time across all active client engagements, stepping in to support and coach where needed.
- Interpret and apply complex regulatory frameworks - analyze and execute cybersecurity compliance requirements under SOC 2, ISO 27001, HIPAA, NIST CSF, and related standards.
- Lead multi-threaded compliance projects - oversee multiple client engagements simultaneously, including audits, evidence collection, control mapping, due diligence, and incident response activities.
- Develop robust compliance documentation - create, implement, and maintain cybersecurity policies, procedures, and supporting evidence to meet audit and certification objectives.
- Collaborate on risk management and process improvement - work with internal and external teams to mitigate cybersecurity risks while continually refining standard operating procedures, playbooks, and frameworks.
Who You Are
- Demonstrated client relationship management - you're comfortable owning client engagements, navigating difficult conversations, and serving as the primary point of contact throughout the engagement.
- Exceptional professionalism and communication - you communicate confidently and professionally in all client interactions, with outstanding written and verbal English skills.
- Proven people leadership experience - you bring 3+ years of experience managing or leading a small team, pod, or squad, providing coaching, mentorship, and accountability while fostering a collaborative, high-performing environment.
- Hands-on cybersecurity compliance expertise - you have 3+ years of practical experience working with cybersecurity compliance frameworks such as SOC 2, ISO 27001, and/or NIST CSF, helping organizations implement and maintain effective compliance programs.
- Strong project management skills - you can successfully manage multiple compliance engagements simultaneously, balancing competing priorities while maintaining exceptional quality and client satisfaction.
- Highly organized and adaptable - you thrive in fast-paced startup environments, staying organized, proactive, and flexible as priorities evolve.
- Policy development and governance - you're experienced in creating, maintaining, and enforcing cybersecurity policies that align with regulatory requirements and industry best practices.
- Experience in a cybersecurity-focused technology company - you've worked within a technology organization where security and compliance are core to the business, collaborating closely with technical, operational, and cross-functional teams.
What will help you succeed
- Big 4 advisory or assurance tenure – Prior success directing complex IT compliance audits, data governance assessments, or technical risk advisory workflows inside elite environments like Deloitte, PwC, EY, or KPMG.
- Multi-framework compliance command – Advanced familiarity with specialized, adjacent international frameworks and regulatory bodies, explicitly including HIPAA, PCI DSS, or regional data sovereignty baselines.
- Mastery of compliance automation architectures – Direct backend operational mastery navigating, configuring, and tracking continuous evidence collection inside automated platforms like Vanta.
- Validated industry credentials – Hold active, globally recognized professional security and audit designations such as CISA, CISSP, ISO 27001 Lead Implementer, or CompTIA Security+.
- Advanced audit coordination background – Proven history managing full-lifecycle third-party assessments, audit pathways, and independent examiner walkthroughs.
What We Offer
- Career Development: Clear path with mentorship and training opportunities.
- Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive
- Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
- A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
- Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
- Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.