Senior GRC Engineer

Workstreet

United States

Remote

USD 120,000 - 170,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Career development
Technical training
Competitive compensation
Growth opportunities
Remote-first culture

Job summary

Workstreet is seeking a Sr. GRC Engineer to manage a portfolio of high-complexity client engagements focused on cybersecurity compliance across SOC 2, ISO 27001, HIPAA, and NIST CSF.

You will lead a pod of analysts, deliver audits and evidence collection, and act as a trusted advisor to drive practical compliance outcomes. You will coordinate audits, map controls, and develop security programs while maintaining exceptional client experience and professional communication.

Qualifications

  • Must have client relationship management experience with direct ownership of accounts.
  • Excellent written and verbal English communication skills.
  • 3+ years in leading a small team (pod/squad).
  • ≥3 years in cybersecurity compliance (SOC 2, ISO 27001, or NIST CSF).
  • Ability to manage multiple compliance projects concurrently without compromising quality.

Responsibilities

  • Own the client experience for a portfolio of high-complexity, long-term accounts.
  • Lead client engagements, conduct regular meetings, provide progress updates and audits.
  • Interact with US-based clients via phone, email, and text to address compliance concerns.
  • Manage escalations with a solution-oriented approach to preserve client trust.
  • Build trusted advisor relationships by delivering practical, actionable compliance guidance.
  • Manage and develop a pod of analysts to ensure timely, high-quality work.
  • Oversee audits, evidence collection, control mapping, and due diligence activities.
  • Develop cybersecurity policies, procedures, and documentation to meet audit objectives.

Skills

Client relationship mgmt
English communication
Team leadership
Cybersecurity compliance
SOC 2 / ISO 27001 / NIST CSF
Policy development
Startup mindset

Job description

The Opportunity

We are seeking a highly motivated, client-focused Sr. GRC Engineer to join our fast-growing team. The ideal candidate is a seasoned client relationship manager who brings deep expertise in cybersecurity compliance and a proven track record of leading high-complexity client engagements with professionalism and care. This role is first and foremost about delivering an exceptional client experience — managing accounts, building trust, and driving successful outcomes — while overseeing a pod of analysts and applying expertise across frameworks such as SOC 2, ISO 27001, and NIST CSF.

The successful candidate will be able to come up to speed quickly, integrate into the organization, and take on clients within your first 15 days. You will serve as the primary point of contact for a portfolio of clients, leading engagements end-to-end, managing escalations with composure and urgency, and ensuring every client interaction reflects the highest standard of service.

What You'll Do

Client Relationship Management (Primary Focus)

  • Own the Client Experience: Serve as the dedicated primary contact for a portfolio of high-complexity, long-term client accounts, ensuring consistent delivery, proactive communication, and strong relationships at every stage of the engagement.
  • Lead Client Engagements: Conduct regular client meetings, deliver progress updates, set expectations, and guide clients through audits, assessments, and compliance milestones with clarity and confidence.
  • Communicate with Care: Engage directly with U.S.-based clients via phone, email, and text to address compliance concerns, provide expert guidance, and ensure clients always feel supported and informed.
  • Handle Escalations: Resolve complex client issues swiftly and professionally, applying a solution-oriented approach that reinforces client trust and satisfaction.
  • Be a Trusted Advisor: Build long-term relationships by understanding each client’s unique business context and delivering compliance guidance that is practical, relevant, and actionable.

Team Leadership

  • Manage and Develop a Pod of Analysts: Provide day-to-day direction, constructive feedback, and professional development support to a small team of junior analysts, fostering a high-performance and collaborative culture.
  • Drive Accountability: Ensure the pod delivers high-quality work on time across all active client engagements, stepping in to support and coach where needed.

GRC & Compliance Execution

  • Interpret Regulatory Frameworks: Analyze and apply cybersecurity compliance requirements under SOC 2, ISO 27001, HIPAA, NIST CSF, and related standards.
  • Lead Compliance Projects: Oversee multiple client engagements simultaneously, including audits, evidence collection, control mapping, and due diligence or incident response activities.
  • Develop Compliance Programs: Create, implement, and maintain cybersecurity policies, procedures, and supporting documentation to meet audit and certification objectives.
  • Collaborate on Risk Management: Work with internal and external teams to identify, assess, and mitigate cybersecurity and compliance risks.
  • Drive Process Improvement: Enhance standard operating procedures, playbooks, and compliance frameworks to strengthen operational effectiveness.
Who You Are

Required

  • Demonstrated experience managing client relationships directly — you are comfortable owning accounts, navigating difficult conversations, and being the face of the engagement
  • Exceptional professionalism in all client-facing communication, with outstanding written and verbal English skills
  • 3+ years of experience managing or leading a small team (pod, squad, or similar structure)
  • 3+ years of experience in cybersecurity compliance, including hands-on work with SOC 2, ISO 27001, or NIST CSF frameworks
  • Proven ability to manage multiple compliance projects concurrently without sacrificing quality or client experience
  • Strong organizational skills and the ability to thrive in a fast-paced startup environment
  • Familiarity with creating and enforcing cybersecurity policies
  • Experience working in a tech company with a cybersecurity focus
Nice to Have
  • Experience at a Big 4 firm (e.g., Deloitte, PwC, EY, KPMG) in an advisory or assurance capacity
  • Experience with HIPAA, PCI DSS, or additional compliance frameworks
  • Familiarity with Vanta or similar compliance automation platforms
  • Certifications such as CISA, CISSP, ISO 27001 Lead Implementer, or Security+
  • Prior experience handling audit coordination or third-party assessments
What We Offer
  • Career Development: Clear growth path with mentorship and training opportunities
  • Technical Training: Comprehensive onboarding on security and compliance frameworks
  • Competitive Compensation: Competitive base salary with regular performance reviews, merit-based appraisals, and bonus opportunities
  • Growth Opportunity: Early-stage company with significant room for career advancement
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team
Work Environment Requirements
  • Reliable high-speed internet connection.
  • Quiet, professional home office setup.
  • Must be amenable to work US Eastern Time zone hours.
  • Fluency in written and verbal English communication skills.
Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Manager, GRC Engineering
Senior Manager, GRC Engineering

Workstreet, Inc. • United States

On-site
USD 110,000 - 150,000
Career Development
Technical Training
Competitive Compensation
+2
Senior GRC Engineer (Special Programs)
Senior GRC Engineer (Special Programs)

workstreet • United States

Remote
USD 140,000 - 190,000
Career development
Remote-first culture
Competitive compensation
Senior Manager, GRC Engineering
Senior Manager, GRC Engineering

workstreet • United States

Remote
USD 180,000 - 260,000
Career development
Role training
Competitive pay
+2
Manager, GRC Engineering
Manager, GRC Engineering

Workstreet • Northern (KY)

On-site
USD 150,000 - 190,000
Career Development
Role-Related Training
Competitive Compensation
+2
GRC Engineer I
GRC Engineer I

Workstreet • United States

Remote
USD 85,000 - 120,000
Career Development
Role-Related Training
Competitive Compensation
+2
Senior GRC Engineer - GOV (FedRAMP 20x)
Senior GRC Engineer - GOV (FedRAMP 20x)

Workstreet • Northern (KY)

On-site
USD 150,000 - 210,000
Career development
Training reimbursement
Competitive compensation
+2
GRC Engineer (CMMC)
GRC Engineer (CMMC)

Workstreet • Northern (KY)

On-site
USD 120,000 - 180,000
Remote-first culture
Career development
Training reimbursement
Trust Services Engineer
Trust Services Engineer

Workstreet • United States

Remote
USD 95,000 - 130,000
Career Development
Technical Training
Competitive Compensation
+2
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
Senior GRC Engineer - Client-Focused, Multi-Framework
Senior GRC Engineer - Client-Focused, Multi-Framework

Workstreet, Inc. • United States

On-site
USD 120,000 - 180,000
Remote‑First Culture
Career Development
Competitive Compensation