Workstreet Logo

Workstreet

Compliance Manager (Government)

Reposted 4 Hours Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
The Government Compliance Manager leads federal compliance engagements, manages client relationships, oversees NIST and FedRAMP implementations, and mentors teams in a consulting environment.
The summary above was generated by AI
About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of frameworks—including SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP—empowering companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

The Opportunity

We are seeking a Government Compliance Manager who is highly motivated, delivery-focused, and brings deep expertise in NIST SP 800-53, FedRAMP (Moderate and High), GovRAMP, and the emerging FedRAMP 20x initiative. The ideal candidate has a proven track record leading federal compliance engagements, managing client relationships, and driving teams toward authorization milestones in a fast-paced consulting environment.

This role is focused on guiding clients through federal cloud and state-level compliance frameworks, leading SaaS providers and government-adjacent organizations through the full FedRAMP and GovRAMP authorization lifecycle—including readiness assessment, authorization support, and continuous monitoring. The Manager will also serve as a subject matter expert on NIST SP 800-53 control implementation and the evolving FedRAMP 20x automation-first authorization model. The successful candidate will own client relationships, lead delivery teams, and position Workstreet at the forefront of next-generation federal compliance consulting.


What You'll Do

  • Lead NIST SP 800-53 Control Implementation:
    Own and oversee the interpretation, mapping, and implementation of NIST SP 800-53 Rev 5 controls across Moderate and High baseline engagements, ensuring control narratives are accurate, defensible, and aligned to agency expectations.
  • Own and Review FedRAMP/GovRAMP Authorization Documentation:
    Direct the development, quality review, and maintenance of System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, SARs, CISOs, and continuous monitoring artifacts for FedRAMP and GovRAMP programs.
  • Lead FedRAMP and GovRAMP Readiness Assessments:
    Lead gap analyses and readiness reviews that prepare clients for Agency ATO pathways, GovRAMP authorization, and the FedRAMP 20x continuous authorization model. Translate findings into actionable remediation roadmaps aligned to authorization milestones.
  • Manage Authorization and Assessment Coordination:
    Serve as the primary engagement lead coordinating with Third-Party Assessment Organizations (3PAOs), Authorizing Officials (AOs), cloud service providers, and state agency stakeholders throughout the FedRAMP and GovRAMP authorization lifecycle.
  • Boundary Definition & System Scoping:
    Lead FedRAMP and GovRAMP authorization boundary definition and system scoping activities, including in-scope component identification, interconnections, data flows, shared responsibility models, and leveraged authorization packages, ensuring alignment with FedRAMP PMO guidance and agency-specific requirements.
  • Oversee Continuous Monitoring Programs:
    Direct and quality-assure monthly, quarterly, and annual FedRAMP and GovRAMP continuous monitoring requirements, including vulnerability management, incident response reporting, significant change requests, and annual assessment planning. Advise clients on automation tooling and OSCAL adoption aligned to FedRAMP 20x objectives.
  • Drive FedRAMP 20x Readiness and Positioning:
    Serve as Workstreet’s internal subject matter expert on FedRAMP 20x, including machine-readable authorization packages (OSCAL), continuous authorization models, and emerging PMO pilot guidance. Educate clients and internal teams on implications and readiness pathways.
  • Manage Client Relationships and Engagement Delivery:
    Own client-facing communication, milestone tracking, and escalation management across multiple concurrent FedRAMP, GovRAMP, and NIST 800-53 engagements. Ensure consistent delivery quality across the portfolio and serve as the primary point of escalation for client issues.
  • Support Business Development and Solutioning:
    Contribute to proposals, scoping calls, and sales conversations for FedRAMP, GovRAMP, and NIST 800-53 opportunities. Help shape Workstreet’s go-to-market positioning for state and federal government compliance services.
  • Lead, Coach, and Develop GRC Engineers:
    Directly manage and mentor a team of Senior and Junior GRC Engineers supporting federal compliance engagements. Provide hands-on technical coaching on NIST SP 800-53 control implementation, FedRAMP documentation standards, and 3PAO coordination. Conduct regular 1:1s, set performance expectations, review work products for quality and accuracy, and actively develop team members’ careers through structured feedback, stretch assignments, and knowledge-sharing sessions. Partner with Workstreet leadership on hiring, onboarding, and capacity planning as the federal practice grows.

Who You Are

  • Strong organizational and project management skills with the ability to manage multiple engagements concurrently
  • 2+ years of experience directly managing or mentoring GRC engineers or compliance consultants, with a track record of raising team performance through coaching, feedback, and structured development
  • 5+ years of experience in GRC consulting or federal compliance, with deep hands-on expertise in FedRAMP, NIST SP 800-53, and/or GovRAMP programs
  • Demonstrated ability to independently manage complex federal compliance engagements, including client-facing ownership of milestones, deliverables, and issue escalation
  • Proven experience leading and quality-reviewing SSPs, POA&Ms, CISOs, SARs, and other FedRAMP/GovRAMP authorization artifacts
  • Strong working knowledge of federal cloud environments and shared responsibility models (AWS GovCloud, Azure Government, GCC High, Oracle GovCloud)
  • Experience working with SaaS providers, cloud service providers, or technology organizations seeking federal or state government authorization
  • Ability to thrive in a fast-paced, consulting, or startup environment

Nice To Have

  • Hands-on experience supporting Agency ATOs and/or FedRAMP PMO interactions
  • Familiarity with FedRAMP 20x concepts, including OSCAL-based SSPs, machine-readable authorization packages, and continuous authorization frameworks
  • CISSP, CISM, or Security+ certification
  • Experience with GovRAMP (state-level FedRAMP equivalents) programs, including Texas DIR, StateRAMP, or similar frameworks
  • Experience with GRC or automation platforms used in FedRAMP engagements (e.g., Drata, Vanta, Comply.ai, RegScale, or similar)
  • Prior experience directly working with 3PAOs throughout the assessment lifecycle, and/or managing junior GRC consultants or analysts


Work Environment Requirements

  • Reliable high-speed internet connection.
  • Quiet, professional home office setup.
  • Must be amenable to work US Eastern Time zone hours.
  • Fluency in written and verbal English communication skills
What We Offer
  • Career Development: Clear path with mentorship and training opportunities.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.


Workstreet Is An Equal Opportunity Employer

We are proud to be an equal opportunity employer. Workstreet does not discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, age, disability, national origin, veteran status or any other basis covered by appropriate law. All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact [email protected]


Employment with Workstreet is contingent upon the successful completion of a background check, which may include verification of employment history, education, and other relevant information, in compliance with applicable laws.

HQ

Workstreet San Francisco, California, USA Office

San Francisco, CA, United States, 94118

Similar Jobs

6 Days Ago
Remote
United States
80K-100K Annually
Senior level
80K-100K Annually
Senior level
Financial Services
Lead government accounting operations, ensuring compliance with regulations, managing a remote team of accountants, and optimizing processes for operational efficiency.
Top Skills: Bill.ComCostpointDeltekExcelHubdocMicrosoft Office SuiteQuickbooks
2 Hours Ago
Remote
United States
100K-160K Annually
Entry level
100K-160K Annually
Entry level
Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
Perform hands-on application and system security assessments: discover and validate vulnerabilities, develop proof-of-concepts and custom tooling, conduct threat modeling and architecture reviews, and communicate clear remediation guidance to clients while contributing to security research.
Top Skills: AslrCC++CfiDepGoJavaScriptPythonRustTypescript
2 Hours Ago
Remote or Hybrid
140K-165K Annually
Senior level
140K-165K Annually
Senior level
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Create reusable "paved paths" (documentation, reference architectures, IaC modules, code templates, and tools) to simplify building on enterprise platforms. Partner with architects and platform teams, develop and maintain templates and AI-assisted developer workflows, gather feedback from application teams, and iterate to maximize usability and adoption across a large, federated engineering organization.
Top Skills: Agent-Based ToolsAWSAzureCi/CdCloudformation (Cft)GCPInfrastructure As Code (Iac)Internal Developer AssistantsPrompt EngineeringPulumiTerraform

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account