Trust Services Engineer
About Workstreet
At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the Trust Services Team
In addition to GRC services, we also have a Trust Services team. We move at a fast, focused, and reliable pace – completing deliverables within 1 to 3 business days for customers with 5 clients and customers with 500 clients. We work directly with our customers’ security and sales points of contact, meaning clarity, teamwork, and problem-solving are at the forefront of everything we do to help our customers drive sales and renewals by using security and compliance as differentiators. If you want to be part of a team that builds the bridge between sales and security, you’re in the right place.
The Opportunity
Workstree t is looking for a results-oriented Trust Services Engineer to support our Trust Services team. Your primary responsibility will be to complete customer security questionnaires and other due diligence requests. Your work will be reviewed by Senior Engineers and Managers, giving you exposure to on-the-job feedback. This role is primarily focused on efficiently and accurately entering information from our customers’ existing compliance resources into standardized responses.
What you’ll do
-
Complete and submit security questionnaires - serve as the primary responder for customer due diligence requests, leveraging established response frameworks, internal policy documentation, and compliance control libraries to deliver accurate, on-time submissions.
-
Research and validate responses - dig into client-specific questions that fall outside standard frameworks, sourcing supporting evidence from compliance platforms and coordinating with internal security and compliance teams to verify accuracy before submission.
-
Maintain consistency and quality across all deliverables - ensure every response reflects current, approved language and aligns with the customer’s broader security posture; flag gaps or outdated documentation when identified.
-
Collaborate with internal teams - coordinate with compliance and security teams to verify information and ensure consistency across all submissions.
Who You Are
-
High-velocity SLA executor - Driven by time-sensitive deliverables and compressed turnaround targets, executing rapid data entry and technical responses without compromising quality.
-
Decisive risk navigator - Handles ambiguous security queries by making definitive, justifiable choices, utilizing sharp communication to escalate critical data gaps rather than operating on guesswork.
-
Proactive workflow coordinator - Commands strong workload prioritization instincts, systematically tracking assigned tasks and communicating blockers early to keep production lines moving.
-
Precision process guardian - Applies exceptional attention to detail and absolute structural discipline when executing established response workflows and data entry procedures.
-
Technical policy parser - Sharp ability to deconstruct dense corporate security policies, internal control libraries, and technical documentation to extract precise, accurate answers for client portfolios.
-
Third-party risk specialist - Directly processes specialized vendor security questionnaires across custom Excel matrices and cloud portals, mapping responses accurately against control domains, risk tiering, and subprocessor ecosystems.
-
Foundational GRC analyst - Grounded in core information security frameworks (SOC 2, ISO 27001, HIPAA, GDPR), data definitions (PII vs. PHI), and technical security controls like