GRC Engineer I
About Workstreet
At Workstreet , weβre on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the GRC Engineering Team
Our GRC Engineering team is the primary point of contact for Workstreet 's clients. We bring deep framework compliance knowledge and program management to each engagement to ensure our clients' compliance goals are met. Our teammates are trusted advisors not only in the compliance space, but also operationally in the role of vCISO. We deliver quickly using common templates and methodologies and are adept at creative problem-solving. GRC Engineering Team members also listen for and act as a centralized resource to advise clients on Workstreet 's other service offerings to support their compliance, privacy, and information security goals.
The Opportunity
We are seeking a highly motivated and detail-oriented GRC Engineer I to join our fast-growing team. The ideal candidate will have a solid background in cybersecurity compliance frameworks such as SOC 2, ISO 27001, and NIST CSF.
This role requires strong communication skills and the ability to manage multiple cybersecurity compliance projects simultaneously. The successful candidate will also have experience overseeing or managing a small team, while ensuring client engagements are delivered effectively and aligned with Workstreet βs security objectives.
What You'll Do
-
Support foundational compliance programs by assisting in the design, implementation, and maintenance of cybersecurity initiatives aligned to SOC 2, ISO 27001, and regulatory standards.
-
Formulate and update compliance documentation , systematically organizing corporate cybersecurity policies, operational procedures, and audit-ready control evidence.
-
Isolate and track security risks , collaborating with internal and external engineering teams to close technical gaps and implement remediation plans.
-
Coordinate cross-functional project tasks , managing documentation baselines, client tracking matrices, and delivery timelines under senior engineering guidance.
-
Engage directly with client contacts via multi-channel pathways to execute rapid evidence collection, clarify control requirements, and deliver transparent status updates.
-
Perform routine control testing and readiness reviews to verify system state configurations and maintain continuous regulatory alignment.
-
Partner with internal IT, engineering, and operations teams to embed corrective configurations and fortify overall corporate security postures.
-
Absorb technical mentorship from senior practitioners to rapidly iterate and improve operational playbooks, compliance templates, and delivery velocity.
Who You Are
-
Disciplined compliance coordinator β Command sharp organizational skills to simultaneously support multiple fast-moving cybersecurity initiatives while systematically hitting target deadlines.
-
Elite professional communicator β Deliver clear, precise written and verbal English communication, demonstrating the capability to translate complex technical rules into well-structured documentation.
-
Client-facing relationship driver β Highly comfortable working directly with US-based client portfolios, establishing immediate rapport through proactive responsiveness and an uncompromising customer-first focus.
-
Hands-on GRC analyst β Bring practical execution experience supporting or implementing core cybersecurity frameworks, explicitly including SOC 2, ISO 27001, or NIST CSF architectures.
-
Policy governance practitioner β Familiar with engineering, maintaining, and reviewi