Workstreet Logo

Workstreet

Senior GRC Engineer - GOV (FedRAMP 20x)

Posted 27 Days Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Lead federal compliance engagements for clients pursuing FedRAMP and NIST certifications. Own strategic advisory, gap assessments, FedRAMP 20x readiness, OSCAL/JSON/YAML machine-readable artifacts, CCM continuous monitoring integrations, and third-party assessment orchestration while mentoring a small compliance team and maintaining executive client relationships.
The summary above was generated by AI
About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.  We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.  We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the GRC Engineering (GOV) Team
Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment & Authorization compliance efforts. We act as our clients' trusted guides and primary point of contact end-to-end, leading them through gap assessments, System Security Plans, POA&Ms, and C3PAO/3PAO coordination with clarity, composure, and a genuinely client-first mindset. Beyond the technical depth in RMF, CUI/DFARS requirements, and GovCloud environments, what defines us is how we work: we translate complex requirements into plain language, manage escalations with urgency and care, and take real pride in making every client feel informed, supported, and well-prepared. We're a group that mentors one another, holds a high bar for quality, and thrives in a fast-paced environment where our work directly strengthens the security of the defense industrial base.

The Opportunity

Workstreet is seeking a Senior GRC Engineer (Government) to serve as a high-touch, executive-level strategic partner for organizations navigating federal compliance frameworks. Built around client relationship excellence, this role centers on delivering an exceptional client experience, cultivating trusted advisor relationships, and maintaining account retention across high-stakes engagements. You will guide clients through complex federal certifications while directing a team of primary operators who manage day-to-day execution across CMMC, NIST SP 800-171, NIST SP 800-53, and FedRAMP 20x standards.

The successful candidate will integrate rapidly into the organization and assume active portfolio ownership within their first 15 days. Rather than focusing solely on routine task execution, you will lead end-to-end strategic engagements, handle escalations with composure, and represent clients on executive calls to ensure every partner remains deeply engaged, highly satisfied, and aligned with Workstreet in the long term during U.S. Eastern Time business hours.

What You'll Do
  • Lead federal certification advisory motions - guide clients through FedRAMP 20x, Assessment & Authorization (A&A), and federal compliance lifecycles with clear milestone direction.
  • Deliver executive-level compliance guidance - act as a trusted advisor, translating complex CR26 rules, 46 Key Security Indicators (KSIs), and federal standards into business language across cross-functional units like Legal, People, Engineering, and Finance.
  • Architect cloud-native automated GRC operations - deploy and integrate automated compliance processes within AWS, Azure, or GCP environments and existing client toolstacks.
  • Deploy enterprise security and AI tool integrations - connect GRC workflows with client IAM, vulnerability management, SIEM, and security-based SaaS solutions.
  • Architect Infrastructure and Policy as Code - implement compliance automation using Infrastructure as Code (Terraform, Pulumi), Policy as Code (OPA/Rego), and AI-powered agentic workflows.
  • Direct and develop compliance pods - mentor, coach, and manage a small team of compliance professionals, enforcing quality standards and delivery accountability across engagements.
  • Build machine-readable compliance artifacts - author and maintain Security Decision Records, Security Configuration Guides, and OSCAL/JSON/YAML artifacts conforming to RFC-0024 and OMB M-24-15 mandates.
  • Execute federal gap and readiness reviews - conduct comprehensive gap assessments and control mapping across FedRAMP 20x Class A, Class B, and Class C requirements.
  • Orchestrate third-party assessment activities - guide clients through 3PAO assessments, C3PAO audits, and independent assessor evaluations with speed and technical rigor.
Who You Are
  • Cloud GRC automation architect - possess 5+ years of direct technical experience in AWS, Azure, or GCP, architecting and integrating automated GRC operations directly within cloud environments.
  • Federal compliance leader - bring 5+ years of experience implementing federal compliance, NIST SP 800-53, FedRAMP Rev5, or Risk Management Framework (RMF) standards, including end-to-end program management.
  • End-to-end engagement owner - bring 3+ years of experience leading multi-project client engagements, building long-term executive trust, and managing account retention in consulting settings.
  • Security stack integration specialist - hands-on experience deploying and integrating GRC frameworks with enterprise IAM, vulnerability management, SIEM, and SaaS security tooling.
  • Compliance-as-code and AI practitioner - proficient with Infrastructure as Code (Terraform, Pulumi), Policy as Code (OPA/Rego), and designing AI-powered automation or agentic workflows.
  • 3PAO audit and Rev5 veteran - direct experience interfacing with 3PAO organizations and running end-to-end compliance programs for organizations holding FedRAMP Class C, Class D, or Rev5 certifications.
  • Cross-functional business translator - adept at communicating complex GRC and security concepts to non-technical stakeholders across client Legal, People, Engineering, and Finance teams.
What will help you succeed
  • Active federal security credentials - hold recognized certifications such as CISSP, CISM, CGRC, or Certified Authorization Professional (CAP).
  • Validated cloud architecture credentials - active technical certifications such as AWS Solutions Architect Associate, Azure Security Engineer, or GCP Associate Cloud Engineer.
  • Collaborative continuous monitoring experience - documented history managing FedRAMP certification activities and real-time Continuous Monitoring (CCM) workflows.
  • Hands-on OSCAL schema mastery - practical experience authoring or validating machine-readable SSPs, POA&Ms, or KSI evidence utilizing OSCAL, JSON, or YAML schemas.
What We Offer
  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process 
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.


All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact [email protected] 

Workstreet Oak Creek, Colorado, USA Office

Oak Creek, CO, United States

Similar Jobs

An Hour Ago
Remote or Hybrid
189K-290K Annually
Expert/Leader
189K-290K Annually
Expert/Leader
Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Leads the technical strategy, architecture, and delivery of scalable hardware-in-the-loop software platforms for autonomous vehicle validation. Designs reliable, observable platform services, APIs, automation, CI/CD, testing, and deployment capabilities spanning AV software, AI models, vehicle hardware, and infrastructure. Resolves complex cross-team technical challenges, improves performance and cost efficiency, mentors engineers, establishes standards, and influences architecture across the AV organization.
Top Skills: APIsBazelC++Ci/CdHardware-In-The-Loop (Hil)LinuxPlatform As A Service (Paas)PythonRosSoftware-In-The-Loop (Sil)SQL
An Hour Ago
Remote or Hybrid
125K-155K Annually
Senior level
125K-155K Annually
Senior level
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Designs and evaluates secure enterprise technology deployments through end-to-end security and threat analysis. Partners with business, IT, and cybersecurity teams on network, application, cloud, and enterprise security controls. Develops security guidance and mitigation requirements, communicates cybersecurity programs to stakeholders, documents best practices, and provides technical mentorship across concurrent initiatives.
Top Skills: CcpaCis Critical Security ControlsCloud Security MatrixCwe/Sans Top 25Endpoint Detection And Response (Edr)GdprHipaaIaasMitre Att&CkNist CsfOwasp Top 10PaasPci DssSaaSSox
An Hour Ago
Remote or Hybrid
130K-165K Annually
Senior level
130K-165K Annually
Senior level
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Serve as financial and strategic partner to technical leadership, owning budgeting, forecasting, variance analysis, and financial reporting for Product, AI, and Engineering. Support ERP modernization, develop financial tools and processes, lead core finance rhythms, prepare monthly operating reviews, coach junior staff, and collaborate with adjacent units to drive efficiencies, balance-sheet stewardship, and long-range planning.
Top Skills: Erp

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account