Skip to main content
Workstreet

GRC Engineer (NIST)

RemoteUTC-5…UTC-5
Published
Role
Security
Experience
Mid
Employment
Full-time
Company size
Startup
Salary not disclosed
Check eligibility

Open to UTC-5…UTC-5. Set where you work from to check your eligibility.

No BS summary

GRC Engineer with 2+ years of experience in NIST SP 800-53, FedRAMP, or RMF lifecycles. Must have experience authoring federal compliance artifacts like SSPs and POA&Ms, and be able to manage multiple projects. Familiarity with government cloud environments (AWS GovCloud, Azure Government) and strong English communication skills are required. Experience with CGRC, CAP, CISSP, or CompTIA Security+ is a plus.

Core skills

NIST SP 800-53FedRAMP

Required skills

NIST Risk Management Framework (RMF)System Security Plans (SSPs)Plans of Action and Milestones (POA&Ms)AWS GovCloudAzure Government

Optional skills

CGRCCAPCISSPCompTIA Security+CMMC 2.0NIST SP 800-171

Required languages

English

What you'll do

  • Execute NIST 800-53 control mappings - analyze and apply NIST SP 800-53 security and privacy controls and control baselines to ensure software architectures meet federal agency standards.
  • Author core authorization documentation - create, update, and maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and supporting A&A artifacts.
  • Conduct readiness and gap assessments - perform technical gap analyses and readiness reviews to prepare clients for federal agency ATO or FedRAMP authorization validation paths.
  • Support continuous monitoring operations - assist with continuous monitoring (ConMon) cycles by tracking monthly vulnerability logs, POA&M updates, and structural change requests.
  • Facilitate external assessment activities - guide clients through the Assessment and Authorization (A&A) process and coordinate operational logistics with 3PAOs and independent assessors.
  • Assist in control remediation efforts - partner with internal and client technical teams to remediate control deficiencies across Low, Moderate, and High baselines.
  • Map authorization boundaries - help document technical security boundaries, interconnectivity agreements, and shared responsibility profiles across cloud environments.
  • Track federal regulatory updates - stay current on evolving NIST SP 800-53 revisions, FedRAMP requirements, and federal policy updates to keep client programs aligned.

What they require

  • 2+ years of direct experience executing GRC deliverables across NIST SP 800-53, FedRAMP, or NIST Risk Management Framework (RMF) lifecycles.
  • Hands-on execution experience creating, evaluating, and maintaining System Security Plans (SSPs), POA&Ms, and technical security narratives.
  • Highly organized practitioner with demonstrated ability to manage multiple federal compliance project tasks simultaneously without losing detail.
  • Familiar with cloud service providers (CSPs) and secure configurations in government clouds like AWS GovCloud or Azure Government.
  • Possesses strong written and verbal English communication skills suited for direct engagement with U.S. client technical leads and assessors.
  • Thrives in dynamic consulting environments, demonstrating high initiative, adaptability, and an eagerness to take task ownership.
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams.
  • Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future.
  • Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
  • As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.
  • All employment is decided on the basis of qualifications, merit, and business need.

Benefits

  • Clear path with mentorship and training opportunities.
  • Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Early-stage company with significant room for career advancement.
  • Flexibility to work from anywhere while collaborating with a global team.

At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

GRCStartup

Details

Visa sponsorshipNo
Salary not disclosed