Senior GRC Engineer (Special Programs)

Workstreet

• $110K — $130K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years of client relationship management in complex accounts.
  • 3+ years of direct experience with SOC 2, ISO 27001, or NIST CSF frameworks.
  • Experience leading teams of analysts in high-velocity environments.
  • Proficiency in creating and enforcing cybersecurity policies.
  • Demonstrated ability to handle multiple compliance projects simultaneously.

Responsibilities

  • Manage primary client relationships and drive proactive communication.
  • Lead and facilitate client meetings, ensuring clarity and compliance expertise.
  • Guide clients through audits and compliance engagements effectively.
  • Resolve complex account escalations with professionalism and swift solutions.
  • Direct and provide mentorship to a team of junior analysts.
  • Implement and analyze security controls across multiple compliance frameworks.
  • Develop and maintain corporate security policies for client readiness.

Benefits

  • Opportunities for career development with mentorship.
  • Reimbursement for relevant training and certification courses.
  • Remote-first culture allowing flexible work arrangements.
  • Room for significant career advancement in an early-stage company.
  • Competitive compensation structure with merit-based reviews and bonuses.
Full Job Description
The Opportunity

Workstreet is seeking a highly motivated, client-focused Senior GRC Engineer to join our fast-growing team. Acting as a seasoned client relationship manager, this role centers on delivering exceptional client experiences, building trust across complex accounts, and leading successful program outcomes. In this capacity, you will oversee a pod of analysts while applying deep expertise across frameworks such as SOC 2, ISO 27001, and NIST CSF.

The successful candidate will integrate quickly into the organization and manage active client accounts within their first 15 days. You will serve as the dedicated primary point of contact for a portfolio of accounts, guiding engagements end-to-end, resolving complex escalations with composure, and ensuring every interaction reflects the highest standard of service.

What You'll Do

  • Own primary account relationship management - act as the dedicated primary contact for complex, long-term client accounts, driving proactive communication, milestone updates, and executive trust.
  • Lead client meetings - lead client meetings for yourself and your team, including client kickoff meetings and milestone review meetings; demonstrate compliance expertise through structured discussions designed to convey the value that our team brings to the table.
  • Lead end-to-end client compliance engagements - guide clients through audits, risk assessments, evidence collection, and milestone reviews with clarity and control.
  • Manage complex account escalations - resolve high-stakes client challenges swiftly and professionally, utilizing solution-oriented approaches to reinforce long-term client retention.
  • Direct and develop analyst pods - provide daily operational leadership, constructive feedback, and mentorship to a team of junior analysts to drive delivery accountability.
  • Execute multi-framework compliance architectures - analyze, interpret, and implement technical security controls aligned with SOC 2, ISO 27001, HIPAA, and NIST CSF.
  • Author and enforce security policies - design, roll out, and maintain enterprise cybersecurity policies, procedures, and documentation required for client certification readiness.
  • Drive GRC process optimization - continuously refine internal playbooks, standard operating procedures, and delivery frameworks to increase operational effectiveness

Who You Are

  • Experienced client relationship lead - direct experience owning high-complexity accounts, facilitating difficult conversations, and serving as the primary face of technical engagements.
  • Proven pod team leader - bring 3+ years of experience directing small analyst pods, delegating deliverables, and driving team performance in high-velocity settings.
  • Technical compliance engineer - hold 3+ years of direct cybersecurity compliance experience with practical execution across SOC 2, ISO 27001, or NIST CSF frameworks.
  • Concurrent project operator - demonstrated track record of managing multiple complex compliance projects simultaneously without compromising quality or client experience.
  • Policy framework practitioner - skilled at creating, implementing, and enforcing corporate security policies within tech-focused or cybersecurity organizations.
  • Startup-ready communicator - highly organized professional with exceptional written and verbal English skills, thriving in fast-paced startup environments.

What will help you succeed

  • Big 4 advisory background - experience conducting assurance, risk, or technical advisory services within Big 4 or top-tier consulting firms.
  • Expanded framework versatility - practical exposure to HIPAA, PCI DSS, or complementary regulatory compliance frameworks.
  • Automated GRC platform mastery - hands-on proficiency leveraging compliance automation solutions such as Vanta, Drata, or similar tools.
  • Active industry credentials - holder of recognized certifications such as CISA, CISSP, ISO 27001 Lead Implementer, or Security+.
  • Third-party audit coordination - prior experience leading external audit processes, third-party risk assessments, and auditor evaluations.

What We Offer

  • Career Development: Clear path with mentorship and training opportunities.
  • Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
  • Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.

What You'll Need to Thrive

  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM-5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners while ensuring timely communication and support.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.

Hiring and Selection Process

  • Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
  • Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
  • Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet's operating principles.
  • Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role, including H-1B, L-1, TN, O-1, E-3, H-1B1, F-1 (OPT/CPT), J-1, or any other work-authorized visa category.

Similar Jobs

More Jobs at Workstreet

More Information Technology Jobs

Find similar Senior GRC Engineer (Special Programs) jobs: