Manager, GRC Engineering

Workstreet

$110K — $130K *
US-AnywhereRemote in United States
Business Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in GRC engineering leadership
  • Proven experience in client relationship management
  • Technical expertise in SOC 2 and ISO 27001 compliance frameworks
  • Hands-on knowledge of security controls for AWS, GCP, Azure
  • Bachelor's degree in IT, Cybersecurity, or related field

Responsibilities

  • Own executive client account management as primary contact
  • Lead end-to-end compliance engagements from kickoff to certification
  • Manage complex account escalations with urgency and composure
  • Deliver strategic compliance guidance as a trusted advisor
  • Direct and develop engineering pods, mentoring 3-5 analysts
  • Architect GRC frameworks across multiple compliance standards
  • Execute multi-cloud certification projects for enterprise environments
  • Leverage compliance automation platforms to track metrics

Benefits

  • Career development with mentorship and training opportunities
  • Reimbursement for job-related training and certifications
  • Competitive compensation with performance-based reviews
  • Growth opportunities in an early-stage company
  • Remote-first culture allowing flexible working arrangements
Full Job Description
The Opportunity

Workstreet is seeking a Manager, GRC Engineering who leads with a client-first mindset and brings exceptional relationship management skills to every engagement. The ideal candidate is an experienced client manager who knows how to build trust, navigate complex accounts, and deliver an outstanding client experience while bringing deep expertise in cybersecurity compliance frameworks such as SOC 2, ISO 27001, and NIST CSF.

The successful candidate will come up to speed quickly, integrate into the organization, and take on active clients within their first 15 days. You will serve as the primary point of contact for a portfolio of clients, leading engagements end-to-end, managing escalations with composure and urgency, and ensuring every interaction reflects the highest standard of service during U.S. Pacific Time business hours.

What You'll Do

  • Own executive client account management - act as the primary point of contact across client portfolios, cultivating trusted executive relationships and ensuring continuous delivery alignment.
  • Lead end-to-end compliance engagements - guide clients seamlessly through complete compliance lifecycles from initial kickoff to final certification with proactive communication.
  • Manage complex account escalations - resolve high-stakes client issues with urgency and composure, applying structured solutions that safeguard retention and confidence.
  • Deliver strategic compliance guidance - act as a trusted advisor, interpreting complex regulatory criteria into actionable, business-aligned technical controls.
  • Direct and develop engineering pods - manage, mentor, and coach a dedicated pod of 3 to 5 analysts to enforce accountability and maintain strict delivery standards.
  • Architect technical GRC frameworks - author and align corporate security policies, procedures, and technical controls across SOC 2, ISO 27001, HIPAA, and PCI DSS.
  • Execute multi-cloud certification projects - lead complex SOC 2 and ISO 27001 implementation motions across enterprise AWS, GCP, and Azure environments.
  • Leverage modern compliance automation - utilize enterprise automation platforms such as Drata, Vanta, and Secureframe to track readiness metrics and maintain continuous audit posture.

Who You Are

  • Proven client relationship manager - background in direct account ownership, adept at facilitating high-stakes client meetings and navigating challenging conversations with poise.
  • Experienced GRC engineering leader - bring 5+ years of direct experience leading technical teams, managing pod throughput, and coaching individual performers.
  • Technical compliance expert - hands-on execution history building and managing enterprise compliance programs aligned with SOC 2 and ISO 27001 frameworks.
  • Cloud control architect - strong practical knowledge implementing technical security controls within AWS, GCP, or Azure environments.
  • Multi-project delivery operator - proven track record of managing multiple concurrent technical compliance engagements without sacrificing execution quality or client satisfaction.
  • Autonomous technical operator - self-directed practitioner holding a Bachelor's degree in IT, Cybersecurity, or a related technical discipline, operating with exceptional initiative.

What will help you succeed

  • Big 4 consulting tenure - background in risk advisory, technical assurance, or security consulting at a Big 4 or elite professional services firm.
  • Active industry certifications - credentialed professional holding active CISA, CISSP, CISM, or equivalent security designations.
  • Specialized GRC advisory history - documented success managing external technical clients within specialized cybersecurity consulting environments.
  • Expanded framework mastery - deep operational familiarity with additional regulatory and security standards including HITRUST, PCI DSS, NIST, GDPR, and HIPAA.

What We Offer

  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.

What You'll Need to Thrive

  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM-5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners while ensuring timely communication and support.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.

Hiring and Selection Process

  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet's operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.

Similar Jobs

More Jobs at Workstreet

More Business Services Jobs

Find similar Manager, GRC Engineering jobs: