Manager, GRC Engineering
Workstreet
Full Time8+ yearsPosted about 7 hours ago
Let the right jobs find you
Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.
Overview
Position Type
Full Time
Experience
8+ years
Job Description
What You'll Do
- Own the vCISO relationship end-to-end - serve as the dedicated virtual CISO for a portfolio of clients, operating with the executive authority, credibility, and trust of an embedded security leader.
- Lead strategic client engagements and security roadmaps - guide clients from initial risk assessment through certification milestones, providing proactive executive guidance, strategic direction, and risk management aligned to business goals.
- Represent clients on live prospect and customer calls - join client sales and due diligence calls as their acting CISO, answering technical security questions in real-time with total fluency in their architecture and controls without notes.
- Handle high-stakes escalations with executive authority - resolve complex security issues and client escalations with urgency and composure, making independent, authoritative security calls without deferring judgment.
- Deliver contextualized strategic security leadership - deeply understand each client's tech stack, business model, and risk appetite to produce custom architecture recommendations, threat models, policy sets, and executive briefings.
- Lead comprehensive risk and compliance oversight - conduct risk assessments, maintain registers, and guide programs across frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, CMMC, NIST CSF/800-171, GDPR, CCPA, DORA, and NYDFS.
- Manage continuous compliance and security operations - facilitate quarterly access reviews, annual pentests, and tabletop IR exercises while leveraging GRC platforms (Vanta, Drata, SecureFrame) for continuous audit readiness.
- Maintain proactive client mastery - participate in regular syncs, contextualize GRC platform telemetry, track architectural changes, and identify emerging risks before they manifest into operational blockers.
- Lead, coach, and develop a pod of GRC analysts - manage 3–5 analysts through direct coaching, performance management, and delivery oversight to drive high-quality execution across active client accounts.
- Drive internal practice development and pre-sales - refine internal vCISO playbooks, mentor junior practice members, and join pre-sales scoping discussions to support proposal development.
Who You Are
- Extensive information security leadership experience - you bring 8+ years of experience in information security, including at least 3 years in a senior security leadership role, driving security strategy, governance, and risk management across complex environments.
- Demonstrated client relationship management - you're comfortable owning client engagements, leading difficult conversations, serving as a trusted security advisor, and building long-term relationships with executive stakeholders.
- Executive-level security communication - you're confident discussing security architecture, compliance posture, and control trade-offs with clients and prospects, translating complex technical concepts into practical business decisions without sacrificing accuracy.
- Deep expertise in cybersecurity frameworks - you have extensive hands-on knowledge of frameworks and standards such as SOC 2, ISO 27001, NIST CSF, HIPAA, HITRUST, NIST SP 800-171, and/or CMMC, helping organizations build and mature security programs.
- Strong program and client management skills - you're experienced managing multiple security programs or client engagements simultaneously, ideally within consulting, advisory, or fractional security leadership environments.
- Exceptional communication skills - you communicate with clarity, confidence, and precision, effectively translating technical risks into business language for executive, technical, and non-technical audiences.
- Independent decision-maker - you're comfortable owning your client portfolio, exercising sound judgment, and making informed security decisions independently while maintaining accountability for outcomes.
- Strong technical cloud security expertise - you have practical experience implementing and evaluating security controls across cloud platforms such as AWS, GCP, and Azure, with a solid understanding of cloud security architecture and best practices.
What will help you succeed
- Active executive security credentials - hold recognized professional certifications such as CISSP, CISM, or CISA.
- Fractional or vCISO practice tenure - prior experience delivering virtual CISO, fractional security leadership, or advisory services within a managed security service provider (MSSP) environment.
- Compliance automation platform mastery - hands-on experience leveraging automated GRC platforms such as Vanta, Drata, or Secureframe for continuous posture tracking.
- **Demonstrated delivery of ISO 42001 ** - recent and hands-on experience as a lead implementor or lead auditor for ISO 42001.
- Complex certification audit leadership - track record supporting client organizations through formal SOC 2 Type II audits, ISO 27001 certifications, or CMMC assessments.
- Specialized framework familiarity - exposure to emerging or regulatory frameworks such as ISO 42001 (AI Management), GDPR, CCPA, DORA, or NIST 800-171.
- Regulated sector domain expertise - industry experience navigating the unique security and regulatory constraints of SaaS, fintech, or healthcare.
What We Offer
- Career Development: Clear path with mentorship and training opportunities.
- Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive
- Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
- A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
- Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
- Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.