Workstreet Logo

Workstreet

GRC Engineer (CMMC)

Posted One Month Ago
Remote
Hiring Remotely in United States
Junior
Remote
Hiring Remotely in United States
Junior
Guide SaaS providers, federal organizations, and defense contractors through FedRAMP, CMMC, and NIST compliance initiatives. Responsibilities include analyzing controls, authoring SSPs and POA&Ms, conducting readiness assessments and gap analyses, defining authorization boundaries, managing continuous monitoring, coordinating CSPs and assessment teams, and advising clients on CUI, DFARS, and federal authorization requirements.
The summary above was generated by AI

About Workstreet

At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP.  We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.

Get to know the GRC Engineering (GOV) Team
Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment & Authorization compliance efforts. We act as our clients' trusted guides and primary point of contact end-to-end, leading them through gap assessments, System Security Plans, POA&Ms, and C3PAO/3PAO coordination with clarity, composure, and a genuinely client-first mindset. Beyond the technical depth in RMF, CUI/DFARS requirements, and GovCloud environments, what defines us is how we work: we translate complex requirements into plain language, manage escalations with urgency and care, and take real pride in making every client feel informed, supported, and well-prepared. We're a group that mentors one another, holds a high bar for quality, and thrives in a fast-paced environment where our work directly strengthens the security of the defense industrial base.

The Opportunity

We are seeking a GRC Engineer who is highly motivated, detail-oriented, and has foundational knowledge of FedRAMP Moderate and High baseline requirements, with complementary experience supporting CMMC and NIST SP 800-171-based programs. The ideal candidate brings strong client-facing communication skills and the ability to contribute to multiple compliance initiatives simultaneously. This role is focused on guiding clients through federal compliance frameworks, supporting both SaaS providers and federal contractors through the FedRAMP authorization lifecycle—including readiness assessment, authorization support, and continuous monitoring—as well as advising defense contractors on CMMC Level 1 and Level 2 compliance and related NIST 800-171 requirements. The successful candidate will play a critical role in helping clients achieve and sustain federal and DoD compliance while leading high-quality delivery across all engagements.

What You'll Do
  • Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to ensure client software architectures align with federal agency requirements.
  • Author and update core federal authorization artifacts, including System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, and SARs.
  • Perform detailed readiness assessments and gap analyses to prepare client environments for Joint Authorization Board (JAB) or Agency ATO validation paths.
  • Architect technical authorization boundaries and scoping profiles across FedRAMP and CMMC environments, mapping data flows, interconnectivity, and shared responsibility models.
  • Execute continuous monitoring (ConMon) cycles, actively tracking monthly vulnerability management logs, incident response reports, and structural change control workflows.
  • Coordinate external assessment pipelines, facilitating critical operational alignment between clients, Cloud Service Providers (CSPs), 3PAOs, and federal stakeholders.
  • Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 controls, translating dense regulatory language into practical, actionable security milestones.
  • Formulate highly structured compliance documentation specifically required for CMMC Level 1 and Level 2 assessment readiness.
Who You Are
  • Proven federal compliance analyst - Bring 2+ years of direct execution in GRC roles with active exposure driving FedRAMP, NIST SP 800-53, and federal authorization lifecycles.
  • Federal documentation practitioner - Hands-on experience authoring, evaluating, and maintaining key federal artifacts, explicitly including System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
  • CMMC and NIST framework generalist - Grounded in the structural requirements of CMMC 2.0 and NIST SP 800-171 baselines as they apply to defense contractors and supply chain data.
  • Sovereign cloud environment navigator - Familiar with the shared responsibility models, operational constraints, and secure configurations of government clouds like AWS GovCloud, Azure Government, or Microsoft GCC High.
  • Disciplined portfolio coordinator - Command strong project management mechanics to support multiple fast-moving client compliance initiatives simultaneously while preserving documentation quality.
  • Regulated technology consultant - Experienced partnering with B2B SaaS providers, federal contractors, or regulated tech companies to systematically navigate federal security baselines.
  • High-velocity startup operator - Excel within fluid consulting or fast-growth startup environments, demonstrating the agility to adapt to shifting client demands and assert immediate task ownership.
What will help you succeed
  • Direct JAB or Agency ATO execution - Direct history supporting live Joint Authorization Board or federal agency Authority to Operate (ATO) certification tracks.
  • Credentialed compliance professional - Hold industry-specific defense designations such as CMMC Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA).
  • Validated information security markers - Active certification through recognized professional bodies, explicitly holding a CISSP, CISM, or CompTIA Security+.
  • Command of DFARS and CUI data lifecycles - Strong foundational knowledge of Controlled Unclassified Information (CUI) protections, DFARS regulatory clauses, and SPRS submission workflows.
  • Collaborative assessment history - Prior success working directly side-by-side with 3PAO or C3PAO independent examination teams.
What We Offer
  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What You'll Need to Thrive
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process 
  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.
Workstreet Is An Equal Opportunity Employer

As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.


All employment is decided on the basis of qualifications, merit, and business need. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, Title I of the Americans with Disabilities Act of 1990, and any other applicable federal, state or local laws, applicants who require reasonable accommodation in the job application process may contact [email protected]


HQ

Workstreet San Francisco, California, USA Office

San Francisco, CA, United States, 94118

Similar Jobs

25 Minutes Ago
In-Office or Remote
100K-130K Annually
Senior level
100K-130K Annually
Senior level
Fintech
Leads product design initiatives for Retirement & Wealth digital products from discovery through delivery. Conducts user research and usability testing, creates wireframes, flows, prototypes, and high-fidelity designs, and partners with Product, Engineering, Content, QA, and business stakeholders. Maintains scalable design systems, component libraries, and Storybook documentation while improving design-to-development workflows. Uses AI-assisted tools responsibly to accelerate ideation and execution, influences product direction, and advocates for consistent, user-centered experiences.
Top Skills: AgileAi Design ToolsDesign TokensFigmaScrumStorybook
56 Minutes Ago
Remote
United States
200K-210K Annually
Expert/Leader
200K-210K Annually
Expert/Leader
Information Technology • Software • Cybersecurity
Leads and scales the global Sales Engineering team while serving as Field CTO and the company’s external technical voice. Owns technical sales methodology, demos, evaluations, proof-of-value cycles, solution design, deployment handoffs, executive engagements, competitive positioning, market content, and field-driven product feedback. The role is a player-coach position requiring deep cybersecurity expertise, executive presence, public speaking, and significant travel.
Top Skills: AIAstEndpoint SecurityMalware AnalysisOt/IcsPacket CaptureScaSoc OperationsSoftware Supply Chain SecuritySpectraThreat Intelligence
59 Minutes Ago
Remote or Hybrid
120K-150K Annually
Senior level
120K-150K Annually
Senior level
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Leads automotive functional safety development and reviews under ISO 26262. Develops safety concepts, architectures, requirements, analyses, safety cases, and compliance assessments for embedded software, hardware, and vehicle systems. Advises customers, leads workshops and training, conducts technical reviews and gap assessments, and supports safety evaluations across ADAS, electrified vehicles, battery systems, and other safety-critical technologies. Limited client travel may be required.
Top Skills: AdasAutomated Driving SystemsAutomotive SoftwareBattery Management SystemsDfaElectronic SystemsEmbedded SoftwareFmeaFtaHaraIec 62508Iso 21434Iso 21448Iso 26262Iso 42001Iso/Pas 8800Power ElectronicsStpa

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account