About Workstreet
At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of frameworks—including SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP—empowering companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
The Opportunity
We are seeking a Government Compliance Manager who is highly motivated, delivery-focused, and brings deep expertise in NIST SP 800-53, FedRAMP (Moderate and High), GovRAMP, and the emerging FedRAMP 20x initiative. The ideal candidate has a proven track record leading federal compliance engagements, managing client relationships, and driving teams toward authorization milestones in a fast-paced consulting environment.
This role is focused on guiding clients through federal cloud and state-level compliance frameworks, leading SaaS providers and government-adjacent organizations through the full FedRAMP and GovRAMP authorization lifecycle—including readiness assessment, authorization support, and continuous monitoring. The Manager will also serve as a subject matter expert on NIST SP 800-53 control implementation and the evolving FedRAMP 20x automation-first authorization model. The successful candidate will own client relationships, lead delivery teams, and position Workstreet at the forefront of next-generation federal compliance consulting.
What You'll Do
- Lead NIST SP 800-53 Control Implementation:
Own and oversee the interpretation, mapping, and implementation of NIST SP 800-53 Rev 5 controls across Moderate and High baseline engagements, ensuring control narratives are accurate, defensible, and aligned to agency expectations. - Own and Review FedRAMP/GovRAMP Authorization Documentation:
Direct the development, quality review, and maintenance of System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, SARs, CISOs, and continuous monitoring artifacts for FedRAMP and GovRAMP programs. - Lead FedRAMP and GovRAMP Readiness Assessments:
Lead gap analyses and readiness reviews that prepare clients for Agency ATO pathways, GovRAMP authorization, and the FedRAMP 20x continuous authorization model. Translate findings into actionable remediation roadmaps aligned to authorization milestones. - Manage Authorization and Assessment Coordination:
Serve as the primary engagement lead coordinating with Third-Party Assessment Organizations (3PAOs), Authorizing Officials (AOs), cloud service providers, and state agency stakeholders throughout the FedRAMP and GovRAMP authorization lifecycle. - Boundary Definition & System Scoping:
Lead FedRAMP and GovRAMP authorization boundary definition and system scoping activities, including in-scope component identification, interconnections, data flows, shared responsibility models, and leveraged authorization packages, ensuring alignment with FedRAMP PMO guidance and agency-specific requirements. - Oversee Continuous Monitoring Programs:
Direct and quality-assure monthly, quarterly, and annual FedRAMP and GovRAMP continuous monitoring requirements, including vulnerability management, incident response reporting, significant change requests, and annual assessment planning. Advise clients on automation tooling and OSCAL adoption aligned to FedRAMP 20x objectives. - Drive FedRAMP 20x Readiness and Positioning:
Serve as Workstreet’s internal subject matter expert on FedRAMP 20x, including machine-readable authorization packages (OSCAL), continuous authorization models, and emerging PMO pilot guidance. Educate clients and internal teams on implications and readiness pathways. - Manage Client Relationships and Engagement Delivery:
Own client-facing communication, milestone tracking, and escalation management across multiple concurrent FedRAMP, GovRAMP, and NIST 800-53 engagements. Ensure consistent delivery quality across the portfolio and serve as the primary point of escalation for client issues. - Support Business Development and Solutioning:
Contribute to proposals, scoping calls, and sales conversations for FedRAMP, GovRAMP, and NIST 800-53 opportunities. Help shape Workstreet’s go-to-market positioning for state and federal government compliance services. - Lead, Coach, and Develop GRC Engineers:
Directly manage and mentor a team of Senior and Junior GRC Engineers supporting federal compliance engagements. Provide hands-on technical coaching on NIST SP 800-53 control implementation, FedRAMP documentation standards, and 3PAO coordination. Conduct regular 1:1s, set performance expectations, review work products for quality and accuracy, and actively develop team members’ careers through structured feedback, stretch assignments, and knowledge-sharing sessions. Partner with Workstreet leadership on hiring, onboarding, and capacity planning as the federal practice grows.
Who You Are
- Strong organizational and project management skills with the ability to manage multiple engagements concurrently
- 2+ years of experience directly managing or mentoring GRC engineers or compliance consultants, with a track record of raising team performance through coaching, feedback, and structured development
- 5+ years of experience in GRC consulting or federal compliance, with deep hands-on expertise in FedRAMP, NIST SP 800-53, and/or GovRAMP programs
- Demonstrated ability to independently manage complex federal compliance engagements, including client-facing ownership of milestones, deliverables, and issue escalation
- Proven experience leading and quality-reviewing SSPs, POA&Ms, CISOs, SARs, and other FedRAMP/GovRAMP authorization artifacts
- Strong working knowledge of federal cloud environments and shared responsibility models (AWS GovCloud, Azure Government, GCC High, Oracle GovCloud)
- Experience working with SaaS providers, cloud service providers, or technology organizations seeking federal or state government authorization
- Ability to thrive in a fast-paced, consulting, or startup environment
Nice To Have
- Hands-on experience supporting Agency ATOs and/or FedRAMP PMO interactions
- Familiarity with FedRAMP 20x concepts, including OSCAL-based SSPs, machine-readable authorization packages, and continuous authorization frameworks
- CISSP, CISM, or Security+ certification
- Experience with GovRAMP (state-level FedRAMP equivalents) programs, including Texas DIR, StateRAMP, or similar frameworks
- Experience with GRC or automation platforms used in FedRAMP engagements (e.g., Drata, Vanta, Comply.ai, RegScale, or similar)
- Prior experience directly working with 3PAOs throughout the assessment lifecycle, and/or managing junior GRC consultants or analysts
Work Environment Requirements
- Reliable high-speed internet connection.
- Quiet, professional home office setup.
- Must be amenable to work US Eastern Time zone hours.
- Fluency in written and verbal English communication skills
What We Offer
- Career Development: Clear path with mentorship and training opportunities.
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
Workstreet Is An Equal Opportunity Employer
As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.
Employment with Workstreet is contingent upon the successful completion of a background check, which may include verification of employment history, education, and other relevant information, in compliance with applicable laws.