About Workstreet
At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the GRC Engineering Team
Our GRC Engineering team is the primary point of contact for Workstreet's clients. We bring deep framework compliance knowledge and program management to each engagement to ensure our clients' compliance goals are met. Our teammates are trusted advisors not only in the compliance space, but also operationally in the role of vCISO. We deliver quickly using common templates and methodologies and are adept at creative problem-solving. GRC Engineering Team members also listen for and act as a centralized resource to advise clients on Workstreet's other service offerings to support their compliance, privacy, and information security goals.
The Opportunity
We are seeking a highly motivated, client-focused Sr. GRC Engineer to join our fast-growing team. The ideal candidate is a seasoned client relationship manager who brings deep expertise in cybersecurity compliance and a proven track record of leading high-complexity client engagements with professionalism and care. This role is first and foremost about delivering an exceptional client experience — managing accounts, building trust, and driving successful outcomes — while overseeing a pod of analysts and applying expertise across frameworks such as SOC 2, ISO 27001, and NIST CSF.
The successful candidate will be able to come up to speed quickly, integrate into the organization, and take on clients within your first 15 days. You will serve as the primary point of contact for a portfolio of clients, leading engagements end-to-end, managing escalations with composure and urgency, and ensuring every client interaction reflects the highest standard of service.
What You'll Do
- Own the client relationship lifecycle as the dedicated primary contact for a portfolio of high-complexity, long-term accounts, ensuring premium delivery, milestone tracking, and proactive account management.
- Lead end-to-end compliance engagements, directing routine milestone check-ins, delivering progress logs, and steering tech clients confidently through dense audit lifecycles.
- Execute direct client communications, partnering closely with US-based client executives, DevOps leads, and technology founders via multi-channel pathways to provide tailored risk guidance.
- Resolve complex account escalations swiftly and professionally, applying a clinical, solution-oriented approach that solidifies long-term retention, customer satisfaction, and trust.
- Supervise, mentor, and upscale a pod of junior analysts, managing day-to-day operations, implementing constructive feedback loops, and driving rigorous delivery standards.
- Analyze and apply global cybersecurity frameworks, mapping technical environments and corporate architectures against SOC 2, ISO 27001, HIPAA, and NIST CSF baselines.
- Formulate and maintain enterprise compliance programs, authoring foundational security policies, operational procedures, and audit-ready control documentation.
- Partner cross-functionally with internal and external teams to systematically isolate, evaluate, and mitigate operational cybersecurity and data compliance risks.
- Drive continuous process improvement, modifying standard operating procedures, technical playbooks, and internal assessment frameworks to optimize team execution velocity.
Who You Are
- Proven client relationship manager – Command a documented history of independently owning high-consequence client accounts, successfully navigating difficult risk conversations, and building trusted advisor status with C-suite stakeholders.
- Elite corporate communicator – Deliver flawless written and verbal English communication capable of confidently breaking down complex technical parameters for US-based tech founders and cross-functional business units.
- Scale-oriented team leader – Bring 3+ years of experience managing, upskilling, and leading a technical pod, squad, or small team, with a verifiable track record of driving accountability and project results.
- Hands-on GRC program architect – Bring 3+ years of practical experience constructing, implementing, and defending robust compliance programs under SOC 2, ISO 27001, or NIST CSF architectures.
- Disciplined portfolio manager – Command sharp project management mechanics to successfully orchestrate multiple multi-threaded compliance engagements simultaneously without losing delivery quality.
- High-velocity startup operator – Excel within fluid, fast-growth technology environments, possessing the immediate operational agility to fully integrate into an organization and absorb complex client portfolios within your first 15 days.
- Policy governance architect – Experienced engineering, maintaining, and enforcing enterprise cybersecurity policies that seamlessly align strict regulatory criteria with business growth targets.
- Domain-native tech professional – Verifiable tenure operating within cybersecurity-focused technology organizations where security governance, risk assessment, and technical compliance serve as core business differentiators.
What will help you succeed
- Big 4 advisory or assurance tenure – Prior success directing complex IT compliance audits, data governance assessments, or technical risk advisory workflows inside elite environments like Deloitte, PwC, EY, or KPMG.
- Multi-framework compliance command – Advanced familiarity with specialized, adjacent international frameworks and regulatory bodies, explicitly including HIPAA, PCI DSS, or regional data sovereignty baselines.
- Mastery of compliance automation architectures – Direct backend operational mastery navigating, configuring, and tracking continuous evidence collection inside automated platforms like Vanta.
- Validated industry credentials – Hold active, globally recognized professional security and audit designations such as CISA, CISSP, ISO 27001 Lead Implementer, or CompTIA Security+.
- Advanced audit coordination background – Proven history managing full-lifecycle third-party assessments, audit pathways, and independent examiner walkthroughs.
What we offer
- Career Development: Clear path with mentorship and training opportunities.
- Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
What you'll need to thrive
- Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
- A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
- Commitment to working a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners while ensuring timely communication and support.
- Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process
- Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
- Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
- Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
- Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
Workstreet Is An Equal Opportunity Employer
As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.