Senior GRC Engineer (Special Programs)
Quick Summary
About Workstreet At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup,
At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
The Special Programs team delivers high-impact, fast-paced services that help organizations accelerate their compliance journey. Unlike our standard offerings, Special Programs are purpose-built engagements designed to solve specific customer challenges, from establishing a compliance foundation in 30 days to migrating organizations onto new GRC platforms, supporting audits, and delivering other specialized compliance services.
For many customers, Special Programs represent their first experience working with Workstreet. Because of that, we are laser-focused on speed, quality, and an exceptional customer experience that builds trust from day one. We support hundreds of organizations, from early-stage startups to global enterprises, across nearly every industry.
Workstreet is seeking a highly motivated, client-focused Senior GRC Engineer to join our fast-growing team. Acting as a seasoned client relationship manager, this role centers on delivering exceptional client experiences, building trust across complex accounts, and leading successful program outcomes. In this capacity, you will oversee a pod of analysts while applying deep expertise across frameworks such as SOC 2, ISO 27001, and NIST CSF.
The successful candidate will integrate quickly into the organization and manage active client accounts within their first 15 days. You will serve as the dedicated primary point of contact for a portfolio of accounts, guiding engagements end-to-end, resolving complex escalations with composure, and ensuring every interaction reflects the highest standard of service.
Responsibilities
~1 min read- →Own primary account relationship management - act as the dedicated primary contact for complex, long-term client accounts, driving proactive communication, milestone updates, and executive trust.
- →Lead client meetings - lead client meetings for yourself and your team, including client kickoff meetings and milestone review meetings; demonstrate compliance expertise through structured discussions designed to convey the value that our team brings to the table.
- →Lead end-to-end client compliance engagements - guide clients through audits, risk assessments, evidence collection, and milestone reviews with clarity and control.
- →Manage complex account escalations - resolve high-stakes client challenges swiftly and professionally, utilizing solution-oriented approaches to reinforce long-term client retention.
- →Direct and develop analyst pods - provide daily operational leadership, constructive feedback, and mentorship to a team of junior analysts to drive delivery accountability.
- →Execute multi-framework compliance architectures - analyze, interpret, and implement technical security controls aligned with SOC 2, ISO 27001, HIPAA, and NIST CSF.
- →Author and enforce security policies - design, roll out, and maintain enterprise cybersecurity policies, procedures, and documentation required for client certification readiness.
- →Drive GRC process optimization - continuously refine internal playbooks, standard operating procedures, and delivery frameworks to increase operational effectiveness
- Experienced client relationship lead - direct experience owning high-complexity accounts, facilitating difficult conversations, and serving as the primary face of technical engagements.
- Proven pod team leader - bring 3+ years of experience directing small analyst pods, delegating deliverables, and driving team performance in high-velocity settings.
- Technical compliance engineer - hold 3+ years of direct cybersecurity compliance experience with practical execution across SOC 2, ISO 27001, or NIST CSF frameworks.
- Concurrent project operator - demonstrated track record of managing multiple complex compliance projects simultaneously without compromising quality or client experience.
- Policy framework practitioner - skilled at creating, implementing, and enforcing corporate security policies within tech-focused or cybersecurity organizations.
- Startup-ready communicator - highly organized professional with exceptional written and verbal English skills, thriving in fast-paced startup environments.
- Big 4 advisory background - experience conducting assurance, risk, or technical advisory services within Big 4 or top-tier consulting firms.
- Expanded framework versatility - practical exposure to HIPAA, PCI DSS, or complementary regulatory compliance frameworks.
- Automated GRC platform mastery - hands-on proficiency leveraging compliance automation solutions such as Vanta, Drata, or similar tools.
- Active industry credentials - holder of recognized certifications such as CISA, CISSP, ISO 27001 Lead Implementer, or Security+.
- Third-party audit coordination - prior experience leading external audit processes, third-party risk assessments, and auditor evaluations.
What We Offer
~1 min read- Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
- A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
- Commitment to working a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners while ensuring timely communication and support.
- Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
- Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
- Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
- Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
- Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
- Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.
Location & Eligibility
Listing Details
- First seen
- September 28, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 66%
- Scored at
- September 28, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.