Manager, GRC Engineering

🏢 Workstreet · all Workstreet jobs
📍 United States
📅 Posted 2026-07-19 · via Himalayas
🏷 GRC-Program-Manager,GRC-Engineering,VCISO-Services,Compliance-Management,Security-Governance,GRC-Manager,GRC-Technical-Lead,Cybersecurity-and-Compliance,Engineering-Manager
Apply on original site ↗

About Workstreet

At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of frameworks—including SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP—empowering companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
The Opportunity

We are seeking a Manager, GRC Engineering (vCISO) who leads with a client-first mindset and brings the executive presence, technical depth, and relationship skills to serve as a trusted security leader for a portfolio of clients. The ideal candidate is a seasoned security professional who knows how to build trust with executive stakeholders, speak fluently about complex security architectures, and represent clients confidently on their most important prospect and customer calls.

The successful candidate will be able to come up to speed quickly, integrate into the organization, and take on clients within your first 30 days. You will serve as the dedicated virtual CISO for a portfolio of clients, owning strategic security relationships end-to-end, guiding risk and compliance decisions with authority, and ensuring every client can count on you as a security expert.

What You'll Do
Client Relationship Management

-
Own the vCISO Relationship: Serve as the dedicated virtual CISO for a portfolio of clients, building deep, trusted relationships and operating with the authority and credibility of an embedded security executive.

-
Lead Client Engagements: Guide clients through security program development and compliance initiatives end-to-end, from initial assessment through certification, providing strategic direction, proactive risk guidance, and executive-level communication at every milestone.

-
Represent Clients on Prospect and Customer Calls: Join your clients’ sales and due diligence calls as their CISO, answering technical security questions in real-time with specificity and confidence. You must be able to speak fluently about their architecture, controls, and compliance posture without notes.

-
Handle Escalations with Professionalism: Resolve complex client issues and escalations with urgency and composure, owning decisions and making security calls independently without deferring every judgment call.

-
Be a Trusted Advisor: Understand each client’s business, technology, risk appetite, and compliance drivers deeply enough to deliver specific, contextualized security guidance, not generic recommendations.

-
Maintain Client Mastery: Attend every weekly sync, review GRC platform results in business context, track architecture changes and upcoming projects, and proactively identify emerging risks before they surface in routine discussions.

vCISO Service Delivery

-
Provide Strategic Security Leadership: Develop and maintain each client’s security program roadmap, aligned to their business objectives and applicable compliance frameworks. Advise C-suite and board-level stakeholders on security posture, risk tolerance, and investment priorities.

-
Lead Risk & Compliance Oversight: Lead risk assessments, risk register development, and treatment planning. Guide clients through SOC 2 (Type I/II), ISO 27001, ISO 42001, HIPAA, CMMC, NIST CSF/800-171, GDPR, CCPA, DORA, NYDFS, and other applicable frameworks.

-
Develop Client Security Programs: Build and mature security programs for early-stage clients and optimize existing programs for more mature organizations. Develop customized policies, controls, and compliance roadmaps that reflect each client’s actual technology and business model.

-
Deliver Advanced Security Strategy: Produce architecture recommendation memoranda with trade-off analysis, vulnerability disclosure assessments, threat modeling exercises, and executive security briefings. Support security hire interviews, contract reviews, and bug bounty SOP

← All remote jobs