GRC Engineer I

Workstreet

United States

On-site

USD 70,000 - 110,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote-First Culture
Career Development
Training reimbursement

Job summary

Workstreet is seeking a highly motivated GRC Engineer I to join our fast-growing team. You will support cybersecurity compliance programs across SOC 2, ISO 27001, and NIST CSF, ensuring alignment with client needs and regulatory requirements.

The role emphasizes strong communication, multi-project coordination, and client-facing engagements with US-based portfolios. You will collaborate with IT, engineering, and operations to strengthen our security posture and expedite evidence collection.

Qualifications

  • Experience with cybersecurity frameworks (SOC 2, ISO 27001, NIST CSF).
  • Strong written and verbal English communication.
  • Ability to manage multiple cybersecurity projects simultaneously.

Responsibilities

  • Support foundational compliance programs by assisting in design, implementation, and maintenance of cybersecurity initiatives aligned to SOC 2, ISO 27001, and regulatory standards.
  • Formulate and update compliance documentation, organize corporate cybersecurity policies, operating procedures, and audit-ready evidence.
  • Identify and track security risks, collaborating with internal and external engineering teams to close gaps and remediate.
  • Coordinate cross-functional project tasks, managing documentation baselines, client tracking matrices, and delivery timelines.
  • Engage directly with client contacts via multi-channel pathways to collect evidence and clarify control requirements.
  • Perform routine control testing and readiness reviews to verify system state configurations and maintain regulatory alignment.
  • Partner with internal IT, engineering, and operations teams to embed corrective configurations and fortify security postures.
  • Absorb mentorship from senior practitioners to improve playbooks and templates.

Skills

Compliance coordination
Client-facing
Technical communication
GRC knowledge
Policy governance
Security operations
Project management

Tools

Vanta

Job description

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting‑edge security and compliance programs. As a fast‑growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.


Get to know the GRC Engineering Team

Our GRC Engineering team is the primary point of contact for Workstreet's clients. We bring deep framework compliance knowledge and program management to each engagement to ensure our clients’ compliance goals are met. Our teammates are trusted advisors not only in the compliance space, but also operationally in the role of vCISO. We deliver quickly using common templates and methodologies and are adept at creative problem‑solving. GRC Engineering Team members also listen for and act as a centralized resource to advise clients on Workstreet's other service offerings to support their compliance, privacy, and information security goals.


The Opportunity

We are seeking a highly motivated and detail-oriented GRC Engineer I to join our fast‑growing team. The ideal candidate will have a solid background in cybersecurity compliance frameworks such as SOC 2, ISO 27001, and NIST CSF.


This role requires strong communication skills and the ability to manage multiple cybersecurity compliance projects simultaneously. The successful candidate will also have experience overseeing or managing a small team, while ensuring client engagements are delivered effectively and aligned with Workstreet’s security objectives.


What You’ll Do


  • Support foundational compliance programs by assisting in the design, implementation, and maintenance of cybersecurity initiatives aligned to SOC 2, ISO 27001, and regulatory standards.

  • Formulate and update compliance documentation, systematically organizing corporate cybersecurity policies, operational procedures, and audit‑ready control evidence.

  • Isolate and track security risks, collaborating with internal and external engineering teams to close technical gaps and implement remediation plans.

  • Coordinate cross‑functional project tasks, managing documentation baselines, client tracking matrices, and delivery timelines under senior engineering guidance.

  • Engage directly with client contacts via multi‑channel pathways to execute rapid evidence collection, clarify control requirements, and deliver transparent status updates.

  • Perform routine control testing and readiness reviews to verify system state configurations and maintain continuous regulatory alignment.

  • Partner with internal IT, engineering, and operations teams to embed corrective configurations and fortify overall corporate security postures.

  • Absorb technical mentorship from senior practitioners to rapidly iterate and improve operational playbooks, compliance templates, and delivery velocity.


Who You Are


  • Disciplined compliance coordinator – Command sharp organizational skills to simultaneously support multiple fast‑moving cybersecurity initiatives while systematically hitting target deadlines.

  • Elite professional communicator – Deliver clear, precise written and verbal English communication, demonstrating the capability to translate complex technical rules into well‑structured documentation.

  • Client‑facing relationship driver – Highly comfortable working directly with US‑based client portfolios, establishing immediate rapport through proactive responsiveness and an uncompromising customer‑first focus.

  • Hands‑on GRC analyst – Bring practical execution experience supporting or implementing core cybersecurity frameworks, explicitly including SOC 2, ISO 27001, or NIST CSF architectures.

  • Policy governance practitioner – Familiar with engineering, maintaining, and reviewing corporate security policies against active operational and business constraints.

  • Domain‑native tech operator – Prior experience working within information security‑focused technology environments, collaborating closely with engineering and cross‑functional teams.

  • High‑velocity startup driver – Excel within fluid, fast‑growth ecosystems, demonstrating the agility to wear multiple hats, pivot priorities on the fly, and assert immediate task ownership.


What Will Help You Succeed


  • Mastery of compliance automation architectures – Practical familiarity navigating automated evidence tracking and continuous control monitoring platforms like Vanta.

  • Multi‑framework compliance command – Supplemental operational knowledge of intersecting international frameworks and regulations, specifically GDPR, HIPAA, or PCI DSS.

  • Validated industry credentials – Progress toward or possession of professional certifications such as ISO 27001 Lead Implementer, CISA, or CompTIA Security+.


What We Offer


  • Career Development: Clear path with mentorship and training opportunities.

  • Role‑Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.

  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit‑based appraisals and bonus opportunities.

  • Growth Opportunity: Early‑stage company with significant room for career advancement.

  • Remote‑First Culture: Flexibility to work from anywhere while collaborating with a global team.


What You’ll Need To Thrive


  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.

  • A reliable, high‑speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.

  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross‑functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time‑sensitive hiring needs.

  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.


Hiring and Selection Process


  • Candidates must participate in live video interviews throughout the hiring process with camera on (non‑negotiable) and be prepared to verify their identity during recruitment and onboarding.

  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.

  • Selected candidates will participate in structured interviews with hiring managers and cross‑functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.

  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.

  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment‑based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J‑1, or any other work‑authorized visa category.


Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.


All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact accommodationsus@workstreet.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, GRC Engineering
Manager, GRC Engineering

Workstreet • Northern (KY)

Hybrid
USD 150,000 - 190,000
Career Development
Role-Related Training
Competitive Compensation
+2
Senior GRC Engineer - GOV (FedRAMP 20x)
Senior GRC Engineer - GOV (FedRAMP 20x)

Workstreet • Northern (KY)

Hybrid
USD 150,000 - 210,000
Career development
Training reimbursement
Competitive compensation
+2
Senior Manager, GRC Engineering
Senior Manager, GRC Engineering

Workstreet, Inc. • United States

On-site
USD 110,000 - 150,000
Career Development
Technical Training
Competitive Compensation
+2
GRC Engineer (NIST)
GRC Engineer (NIST)

Workstreet • Northern (KY)

Hybrid
USD 90,000 - 130,000
Remote-first culture
GRC Engineer (CMMC)
GRC Engineer (CMMC)

Workstreet • Northern (KY)

Hybrid
USD 120,000 - 180,000
Remote-first culture
Career development
Training reimbursement
GRC Engineer (NIST)
GRC Engineer (NIST)

Jobless • Northern (KY)

Hybrid
USD 90,000 - 130,000
Career Development
Role-Related Training
Competitive Compensation
+2
Trust Services Engineer
Trust Services Engineer

Triwill Group • United States

Remote
USD 80,000 - 120,000
Career development
Training reimbursement
Competitive compensation
+2
Marketing Manager
Marketing Manager

Workstreet • Northern (KY)

Hybrid
USD 90,000 - 130,000
Career Development
Competitive Compensation
Growth Opportunities
+1
Marketing Manager
Marketing Manager

Jobless • Northern (KY)

Hybrid
USD 65,000 - 100,000
Remote-First Culture
Career Development
Competitive Compensation
Senior GRC Technical Engineer
Senior GRC Technical Engineer

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 240,000
Healthcare benefits
401(k) match
Career development