GRC Engineer (NIST)
About the Role
Workstreet is seeking a highly motivated, detail-oriented GRC Engineer with foundational knowledge of NIST SP 800-53 and FedRAMP Moderate and High baseline requirements. As a key technical contributor within our government delivery practice, you will support client-facing compliance initiatives, author authorization artifacts, and execute gap assessments across the Assessment and Authorization (A&A) lifecycle. This role involves partnering directly with organizations pursuing federal authorizations, assisting with 3PAO assessment preparation, and helping clients achieve and sustain compliance across government clouds during U.S. Eastern Time business hours.
Responsibilities
- Execute NIST 800-53 control mappings—analyze and apply NIST SP 800-53 security and privacy controls and control baselines to ensure software architectures meet federal agency standards.
- Author core authorization documentation—create, update, and maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and supporting A&A artifacts.
- Conduct readiness and gap assessments—perform technical gap analyses and readiness reviews to prepare clients for federal agency ATO or FedRAMP authorization validation paths.
- Support continuous monitoring operations—assist with continuous monitoring (ConMon) cycles by tracking monthly vulnerability logs, POA&M updates, and structural change requests.
- Facilitate external assessment activities—guide clients through the Assessment and Authorization (A&A) process and coordinate operational logistics with 3PAOs and independent assessors.
- Assist in control remediation efforts—partner with internal and client technical teams to remediate control deficiencies across Low, Moderate, and High baselines.
- Map authorization boundaries—help document technical security boundaries, interconnectivity agreements, and shared responsibility profiles across cloud environments.
- Track federal regulatory updates—stay current on evolving NIST SP 800-53 revisions, FedRAMP requirements, and federal policy updates to keep client programs aligned.
Requirements
- 2+ years of direct experience executing GRC deliverables across NIST SP 800-53, FedRAMP, or NIST Risk Management Framework (RMF) lifecycles.
- Hands-on experience creating, evaluating, and maintaining System Security Plans (SSPs), POA&Ms, and technical security narratives.
- Demonstrated ability to manage multiple federal compliance project tasks simultaneously without losing detail.
- Familiarity with cloud service providers (CSPs) and secure configurations in government clouds like AWS GovCloud or Azure Government.
- Strong written and verbal English communication skills suited for direct engagement with U.S. client technical leads and assessors.
- Ability to thrive in dynamic consulting environments, demonstrating high initiative, adaptability, and eagerness to take task ownership.
Qualifications
- Active security credentials such as CGRC, CAP, CISSP, or CompTIA Security+.
- Practical history supporting live agency Authority to Operate (ATO) certifications or working directly alongside 3PAO assessment teams.
- Experience executing automated or manual FedRAMP Continuous Monitoring (ConMon) workflows.
- Complementary exposure to CMMC 2.0 or NIST SP 800-171 baselines for defense industrial base contractors.
Benefits
- Career Development: Clear path with mentorship and training opportunities.
- Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- Growth Opportunity: Early-stage company with significant room for career advancement.
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.
Schedule
Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support clients and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities and global collaboration. Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Workstreet does not provide employment-based visa sponsorship or transfers for this role.