Workstreet Logo

Workstreet

GRC Engineer (CMMC/FedRAMP)

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Mid level
Remote
Hiring Remotely in United States
Mid level
As a GRC Engineer, you'll support clients in compliance with FedRAMP and CMMC, conduct assessments, develop documentation, and manage multiple projects.
The summary above was generated by AI

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of frameworks—including SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP—empowering companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

The Opportunity 

We are seeking a GRC Engineer who is highly motivated, detail-oriented, and has foundational knowledge of FedRAMP Moderate and High baseline requirements, with complementary experience supporting CMMC and NIST SP 800-171-based programs. The ideal candidate brings strong client-facing communication skills and the ability to contribute to multiple compliance initiatives simultaneously.

This role is focused on guiding clients through federal compliance frameworks, supporting both SaaS providers and federal contractors through the FedRAMP authorization lifecycle—including readiness assessment, authorization support, and continuous monitoring—as well as advising defense contractors on CMMC Level 1 and Level 2 compliance and related NIST 800-171 requirements. The successful candidate will play a critical role in helping clients achieve and sustain federal and DoD compliance while leading high-quality delivery across all engagements.

What You'll Do
  • Interpret and Apply FedRAMP Requirements:
    Analyze and apply NIST SP 800-53 controls, FedRAMP baselines, and agency-specific requirements to ensure client compliance.
  • Develop and Maintain FedRAMP Documentation:
    Develop and maintain System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, SARs, and continuous monitoring artifacts.
  • Conduct FedRAMP Readiness Assessments:
    Perform gap analyses and readiness reviews to prepare organizations for JAB or Agency ATO pathways.
  • Support Authorization and Assessment Activities:
    Coordinate with Third-Party Assessment Organizations (3PAOs), cloud service providers, and government stakeholders throughout the FedRAMP lifecycle.
  • Boundary Definition & Scoping:
    Perform CMMC/FedRAMP authorization boundary definition and system scoping activities, including identification of in-scope components, interconnections, data flows, and shared responsibility models to ensure alignment with FedRAMP PMO and agency expectations.
  • Support Continuous Monitoring Programs:
    Conduct monthly, quarterly, and annual FedRAMP continuous monitoring requirements, including vulnerability management, incident response reporting, and change control.
  • Support FedRAMP Engagements:
    Assist on multiple concurrent client projects, ensuring milestones, deliverables, and quality standards are consistently met or exceeded.
  • Support CMMC and NIST 800-171 Compliance Efforts:
    Assist defense contractors with interpreting CMMC 2.0 and NIST SP 800-171 controls and implementing compliant security programs.
  • Develop CMMC Documentation:
    Contribute to SSPs, POA&Ms, and supporting artifacts required for CMMC Level 1 and Level 2 readiness.
Who You Are
  • Strong organizational and project management skills with the ability to manage multiple engagements concurrently
  • 2+ years of experience in GRC, with exposure to FedRAMP, NIST SP 800-53, and federal compliance programs
  • Working knowledge of CMMC 2.0 and NIST SP 800-171 requirements
  • Experience authoring and reviewing SSPs, POA&Ms, and assessment artifacts
  • Familiarity with federal cloud environments (AWS GovCloud, Azure Government, GCC High)
  • Experience working with SaaS providers, federal contractors, or regulated technology organizations
  • Ability to thrive in a fast-paced, consulting, or startup environment
Nice to Have 
  • FedRAMP-specific experience supporting JAB or Agency ATOs
  • CMMC Registered Practitioner (RP), CCP, or CCA certification
  • CISSP, CISM, or Security+ certification
  • Experience with DFARS clauses and CUI handling requirements
  • Familiarity with SPRS reporting and DoD assessment workflows
  • Prior experience working directly with 3PAOs or C3PAOs
Work Environment Requirements
  • Reliable high-speed internet connection.
  • Quiet, professional home office setup.
  • Must be amenable to work US Eastern Time zone hours.
  • Fluency in written and verbal English communication skills.
Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.

Top Skills

Aws Govcloud
Azure Government
Cmmc
Fedramp
Gcc High
Nist 800-53

Workstreet Oak Creek, Colorado, USA Office

Oak Creek, CO, United States

Similar Jobs

45 Minutes Ago
Easy Apply
Remote or Hybrid
Ohio, USA
Easy Apply
90K-110K Annually
Senior level
90K-110K Annually
Senior level
AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
The Senior Marketing Strategist develops and manages marketing strategies and programs across multiple channels, ensuring campaign execution aligns with business objectives and compliance standards.
Top Skills: ExcelMicrosoft Powerpoint
45 Minutes Ago
Remote or Hybrid
2 Locations
95K-115K Annually
Mid level
95K-115K Annually
Mid level
AdTech • Consumer Web • Digital Media • eCommerce • Marketing Tech
The Account Executive develops client relationships, drives advertising sales, manages a sales territory, and exceeds revenue goals through strategic business development efforts.
Top Skills: Advertising SolutionsDigital Media Products
51 Minutes Ago
In-Office or Remote
Chicago, IL, USA
100K-150K Annually
Mid level
100K-150K Annually
Mid level
Fintech
Looking for an experienced electronic options trader to manage risk across multiple products and collaborate with engineers and traders.

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account