Skip to main content
Workstreet

GRC Engineer (CMMC)

RemoteWorldwide
Published
Role
Security
Experience
Mid
Employment
Full-time
Company size
Startup
Salary not disclosed
Check eligibility

Open to Worldwide. Set where you work from to check your eligibility.

No BS summary

GRC Engineer with 2+ years of experience in FedRAMP, NIST SP 800-53, and CMMC/NIST SP 800-171 compliance. Must have experience authoring federal authorization artifacts and navigating government clouds. Strong client-facing and project management skills required. US work authorization needed.

Core skills

CMMCNIST SP 800-171FedRAMP

Required skills

FedRAMP ModerateFedRAMP HighNIST SP 800-53System Security Plans (SSPs)Plans of Action and Milestones (POA&Ms)AWS GovCloudAzure GovernmentMicrosoft GCC HighDFARSCUI

Optional skills

CISSPCISMCompTIA Security+DFARSCUISPRS

Required languages

English

What you'll do

  • Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to ensure client software architectures align with federal agency requirements.
  • Author and update core federal authorization artifacts , including System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, and SARs.
  • Perform detailed readiness assessments and gap analyses to prepare client environments for Joint Authorization Board (JAB) or Agency ATO validation paths.
  • Architect technical authorization boundaries and scoping profiles across FedRAMP and CMMC environments, mapping data flows, interconnectivity, and shared responsibility models.
  • Execute continuous monitoring (ConMon) cycles , actively tracking monthly vulnerability management logs, incident response reports, and structural change control workflows.
  • Coordinate external assessment pipelines , facilitating critical operational alignment between clients, Cloud Service Providers (CSPs), 3PAOs, and federal stakeholders.
  • Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 controls , translating dense regulatory language into practical, actionable security milestones.
  • Formulate highly structured compliance documentation specifically required for CMMC Level 1 and Level 2 assessment readiness.

What they require

  • 2+ years of direct execution in GRC roles with active exposure driving FedRAMP, NIST SP 800-53, and federal authorization lifecycles.
  • Hands-on experience authoring, evaluating, and maintaining key federal artifacts, explicitly including System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
  • Grounded in the structural requirements of CMMC 2.0 and NIST SP 800-171 baselines as they apply to defense contractors and supply chain data.
  • Familiar with the shared responsibility models, operational constraints, and secure configurations of government clouds like AWS GovCloud, Azure Government, or Microsoft GCC High.
  • Command strong project management mechanics to support multiple fast-moving client compliance initiatives simultaneously while preserving documentation quality.
  • Experienced partnering with B2B SaaS providers, federal contractors, or regulated tech companies to systematically navigate federal security baselines.
  • Excel within fluid consulting or fast-growth startup environments, demonstrating the agility to adapt to shifting client demands and assert immediate task ownership.
  • Direct JAB or Agency ATO execution - Direct history supporting live Joint Authorization Board or federal agency Authority to Operate (ATO) certification tracks.
  • Hold industry-specific defense designations such as CMMC Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA).
  • Active certification through recognized professional bodies, explicitly holding a CISSP, CISM, or CompTIA Security+.
  • Strong foundational knowledge of Controlled Unclassified Information (CUI) protections, DFARS regulatory clauses, and SPRS submission workflows.
  • Prior success working directly side-by-side with 3PAO or C3PAO independent examination teams.
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams.
  • Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future.
  • Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
  • As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals.
  • All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.
  • All employment is decided on the basis of qualifications, merit, and business need.
  • In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact accommodationsus@workstreet.com

Benefits

  • Clear path with mentorship and training opportunities.
  • Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Early-stage company with significant room for career advancement.
  • Flexibility to work from anywhere while collaborating with a global team.

At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

GRCStartup

Details

Visa sponsorshipNo
Salary not disclosed