Skip to main content
Workstreet

Senior GRC Engineer - GOV (FedRAMP 20x)

RemoteUTC-5…UTC-4
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Startup
Salary not disclosed
Check eligibility

Open to UTC-5…UTC-4. Set where you work from to check your eligibility.

No BS summary

Senior GRC Engineer with 5+ years of federal compliance experience (NIST SP 800-53, FedRAMP, RMF) and 3+ years leading client engagements. Must have hands-on experience with cloud platforms (AWS GovCloud/Azure Government) and compliance-as-code tooling (Python, OPA/Rego). Experience with 3PAO assessments and OSCAL is required. Role is remote within the US, requiring standard US Eastern Time business hours.

Core skills

NIST SP 800-53FedRAMPGRC

Required skills

NIST SP 800-171Risk Management Framework (RMF)AWSAzureGCPPythonOPA/RegoOSCALJSONYAML

Optional skills

CISSPCISMCGRCCertified Authorization Professional (CAP)AWS Solutions Architect AssociateAzure Security EngineerGCP Associate Cloud EngineerCollaborative Continuous Monitoring (CCM)

Required languages

English

What you'll do

  • Lead federal certification advisory motions - guide clients through FedRAMP 20x, Assessment & Authorization (A&A), and federal compliance lifecycles with clear milestone direction.
  • Deliver executive-level compliance guidance - act as a trusted advisor, translating complex CR26 rules, 46 Key Security Indicators (KSIs), and federal standards into business language.
  • Direct and develop compliance pods - mentor, coach, and manage a small team of compliance professionals, enforcing quality standards and delivery accountability across engagements.
  • Build machine-readable compliance artifacts - author and maintain Security Decision Records, Security Configuration Guides, and OSCAL/JSON/YAML artifacts conforming to RFC-0024 and OMB M-24-15 mandates.
  • Implement continuous monitoring tooling - connect CSPM and GRC platforms into agency pipelines under FedRAMP’s Collaborative Continuous Monitoring (CCM) model to replace point-in-time ConMon reporting.
  • Execute federal gap and readiness reviews - conduct comprehensive gap assessments and control mapping across FedRAMP 20x Class A, Class B, and Class C requirements.
  • Orchestrate third-party assessment activities - guide clients through 3PAO assessments, C3PAO audits, and independent assessor evaluations with speed and technical rigor.
  • Track evolving federal regulatory updates - monitor Consolidated Rules (CR26), Significant Change Notifications (SCNs), and the Rev5-to-20x transition timeline to maintain client compliance.

What they require

  • 5+ years of direct experience implementing federal compliance, NIST SP 800-53, FedRAMP, or Risk Management Framework (RMF) standards.
  • 3+ years of experience leading multi-project client engagements, building long-term executive trust, and managing account retention.
  • Deeply familiar with FedRAMP 20x Program Certifications (Class A/B/C) and Rev5 Agency Certifications (Class D/High) to advise clients on strategy.
  • Hands-on execution experience across major cloud platforms (AWS, Azure, GCP), specifically within AWS GovCloud or Azure Government regions.
  • Working ability with scripting languages and policy-as-code tooling (Python, OPA/Rego, IaC) to build and inspect automated evidence pipelines.
  • Practical experience working with or for a 3PAO, participating on security assessment teams, or conducting formal evidence adjudication.
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams.
  • Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future.
  • Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.

Benefits

  • Clear path with mentorship and training opportunities.
  • Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Early-stage company with significant room for career advancement.
  • Flexibility to work from anywhere while collaborating with a global team.

At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

GRCStartup

Details

Visa sponsorshipNo
Salary not disclosed