GRC Engineer (CMMC)
At Workstreet, we help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in GRC (governance, risk, and compliance) services supporting frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture.
About the Team
The GRC engineering team guides defense contractors and federal organizations through CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment & Authorization compliance efforts. We act as trusted guides and primary point of contact, leading clients through gap assessments, System Security Plans, POA&Ms, and C3PAO/3PAO coordination. Beyond technical depth in RMF, CUI/DFARS requirements, and GovCloud environments, we translate complex requirements into plain language, manage escalations with urgency, and ensure clients feel informed and supported.
About the Role
We are seeking a highly motivated, detail-oriented GRC Engineer with foundational knowledge of FedRAMP Moderate and High baseline requirements, and complementary experience supporting CMMC and NIST SP 800-171-based programs. The ideal candidate brings strong client-facing communication skills and the ability to contribute to multiple compliance initiatives simultaneously. This role focuses on guiding clients through federal compliance frameworks, supporting SaaS providers and federal contractors through the FedRAMP authorization lifecycle—including readiness assessment, authorization support, and continuous monitoring—as well as advising defense contractors on CMMC Level 1 and Level 2 compliance.
Responsibilities
- Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to ensure client software architectures align with federal agency requirements.
- Author and update core federal authorization artifacts, including System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, and SARs.
- Perform detailed readiness assessments and gap analyses to prepare client environments for Joint Authorization Board (JAB) or Agency ATO validation paths.
- Architect technical authorization boundaries and scoping profiles across FedRAMP and CMMC environments, mapping data flows, interconnectivity, and shared responsibility models.
- Execute continuous monitoring (ConMon) cycles, actively tracking monthly vulnerability management logs, incident response reports, and structural change control workflows.
- Coordinate external assessment pipelines, facilitating operational alignment between clients, Cloud Service Providers (CSPs), 3PAOs, and federal stakeholders.
- Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 controls, translating regulatory language into practical, actionable security milestones.
- Formulate compliance documentation specifically required for CMMC Level 1 and Level 2 assessment readiness.
Requirements
- 2+ years of direct execution in GRC roles with active exposure driving FedRAMP, NIST SP 800-53, and federal authorization lifecycles.
- Hands-on experience authoring, evaluating, and maintaining key federal artifacts, including System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
- Grounded in the structural requirements of CMMC 2.0 and NIST SP 800-171 baselines as they apply to defense contractors and supply chain data.
- Familiarity with shared responsibility models, operational constraints, and secure configurations of government clouds like AWS GovCloud, Azure Government, or Microsoft GCC High.
- Strong project management skills to support multiple fast-moving client compliance initiatives while preserving documentation quality.
- Experience partnering with B2B SaaS providers, federal contractors, or regulated tech companies to navigate federal security baselines.
- Ability to excel in fluid consulting or fast-growth startup environments, adapting to shifting client demands and asserting immediate task ownership.
Qualifications
- Direct history supporting live Joint Authorization Board or federal agency Authority to Operate (ATO) certification tracks.
- Industry-specific defense designations such as CMMC Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA).
- Active certification through recognized professional bodies, such as CISSP, CISM, or CompTIA Security+.
- Strong foundational knowledge of Controlled Unclassified Information (CUI) protections, DFARS regulatory clauses, and SPRS submission workflows.
- Prior success working directly with 3PAO or C3PAO independent examination teams.
Benefits
- Clear career development path with mentorship and training opportunities.
- Reimbursement for approved role-related training and certification courses.
- Competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Early-stage company with significant room for career advancement.
- Remote-first culture with flexibility to work from anywhere while collaborating with a global team.
Schedule
Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET). Occasional flexibility to adjust working hours is expected to accommodate changing business priorities and global collaboration. Willingness to travel locally for occasional onsite meetings or team gatherings.
Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role.