Senior GRC Engineer

Workstreet

Full Time5+ yearsPosted about 7 hours ago

Let the right jobs find you

Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.

Overview

Position Type

Full Time

Experience

5+ years

Job Description

The Opportunity

Workstreet is seeking a Senior GRC Engineer (Government) to serve as a high-touch, executive-level strategic partner for organizations navigating federal compliance frameworks. Built around client relationship excellence, this role centers on delivering an exceptional client experience, cultivating trusted advisor relationships, and maintaining account retention across high-stakes engagements. You will guide clients through complex federal certifications while directing a team of primary operators who manage day-to-day execution across CMMC, NIST SP 800-171, NIST SP 800-53, and FedRAMP 20x standards.

The successful candidate will integrate rapidly into the organization and assume active portfolio ownership within their first 15 days. Rather than focusing solely on routine task execution, you will lead end-to-end strategic engagements, handle escalations with composure, and represent clients on executive calls to ensure every partner remains deeply engaged, highly satisfied, and aligned with Workstreet in the long term during U.S. Eastern Time business hours.

What You'll Do

  • Lead federal certification advisory motions - guide clients through FedRAMP 20x, Assessment & Authorization (A&A), and federal compliance lifecycles with clear milestone direction.
  • Deliver executive-level compliance guidance - act as a trusted advisor, translating complex CR26 rules, 46 Key Security Indicators (KSIs), and federal standards into business language across cross-functional units like Legal, People, Engineering, and Finance.
  • Architect cloud-native automated GRC operations - deploy and integrate automated compliance processes within AWS, Azure, or GCP environments and existing client toolstacks.
  • Deploy enterprise security and AI tool integrations - connect GRC workflows with client IAM, vulnerability management, SIEM, and security-based SaaS solutions.
  • Architect Infrastructure and Policy as Code - implement compliance automation using Infrastructure as Code (Terraform, Pulumi), Policy as Code (OPA/Rego), and AI-powered agentic workflows.
  • Direct and develop compliance pods - mentor, coach, and manage a small team of compliance professionals, enforcing quality standards and delivery accountability across engagements.
  • Build machine-readable compliance artifacts - author and maintain Security Decision Records, Security Configuration Guides, and OSCAL/JSON/YAML artifacts conforming to RFC-0024 and OMB M-24-15 mandates.
  • Execute federal gap and readiness reviews - conduct comprehensive gap assessments and control mapping across FedRAMP 20x Class A, Class B, and Class C requirements.
  • Orchestrate third-party assessment activities - guide clients through 3PAO assessments, C3PAO audits, and independent assessor evaluations with speed and technical rigor.

Who You Are

  • Cloud GRC automation architect - possess 5+ years of direct technical experience in AWS, Azure, or GCP, architecting and integrating automated GRC operations directly within cloud environments.
  • Federal compliance leader - bring 5+ years of experience implementing federal compliance, NIST SP 800-53, FedRAMP Rev5, or Risk Management Framework (RMF) standards, including end-to-end program management.
  • End-to-end engagement owner - bring 3+ years of experience leading multi-project client engagements, building long-term executive trust, and managing account retention in consulting settings.
  • Security stack integration specialist - hands-on experience deploying and integrating GRC frameworks with enterprise IAM, vulnerability management, SIEM, and SaaS security tooling.
  • Compliance-as-code and AI practitioner - proficient with Infrastructure as Code (Terraform, Pulumi), Policy as Code (OPA/Rego), and designing AI-powered automation or agentic workflows.
  • 3PAO audit and Rev5 veteran - direct experience interfacing with 3PAO organizations and running end-to-end compliance programs for organizations holding FedRAMP Class C, Class D, or Rev5 certifications.
  • Cross-functional business translator - adept at communicating complex GRC and security concepts to non-technical stakeholders across client Legal, People, Engineering, and Finance teams.

What will help you succeed

  • Active federal security credentials - hold recognized certifications such as CISSP, CISM, CGRC, or Certified Authorization Professional (CAP).
  • Validated cloud architecture credentials - active technical certifications such as AWS Solutions Architect Associate, Azure Security Engineer, or GCP Associate Cloud Engineer.
  • Collaborative continuous monitoring experience - documented history managing FedRAMP certification activities and real-time Continuous Monitoring (CCM) workflows.
  • Hands-on OSCAL schema mastery - practical experience authoring or validating machine-readable SSPs, POA&Ms, or KSI evidence utilizing OSCAL, JSON, or YAML schemas.

What We Offer

  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.

Required Skills

GrcFed RampNist 800 171Nist Sp 800 53CmmcCloud AutomationIbc Code ComplianceAiTerraformPulumiOpa RegoSecurity IntegrationCross Functional Business Translator

About the Company

Workstreet

United States

Share This Job