Jobs · Engineering

Senior Manager, GRC Engineering (Special Programs)

Workstreet · United States · 1 wk ago
RemoteRemoteEngineeringFull-time

At Workstreet, we are on a mission to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of frameworks, including SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP, empowering companies to meet regulatory requirements and strengthen their cybersecurity posture from day one.

About the Special Programs Team

The Special Programs team delivers high-impact, fast-paced services that help organizations accelerate their compliance journey. Unlike our standard offerings, Special Programs are purpose-built engagements designed to solve specific customer challenges, from establishing a compliance foundation in 30 days to migrating organizations onto new GRC platforms, supporting audits, and delivering other specialized compliance services. For many customers, Special Programs represent their first experience working with Workstreet. Because of that, we are laser-focused on speed, quality, and an exceptional customer experience that builds trust from day one. We support hundreds of organizations, from early-stage startups to global enterprises, across nearly every industry.

Responsibilities

  • Assume end-to-end program ownership - take total accountability for Special Programs delivery health, client satisfaction metrics, and cross-functional team execution.
  • Lead executive-level escalation resolution - serve as the primary escalation authority for high-risk engagements, partnering with managers to resolve complex issues and restore client trust.
  • Maintain delivery and timeline tracking - monitor portfolio-wide engagement milestones, identify slipping schedules early, and proactively unblock teams to protect project deadlines.
  • Enforce operational delivery standards - uphold established quality benchmarks and engagement playbooks across all teams, holding managers accountable to consistent execution.
  • Manage capacity and resource allocation - track workload distribution across direct reports, flag bandwidth risks to executive leadership early, and ensure optimal staffing across engagements.
  • Direct and develop first-line managers - coach and mentor 4 to 5 direct-report managers to foster a culture of strict accountability, ownership, and operational consistency.
  • Drive team performance management - establish clear delivery expectations, conduct performance evaluations, recognize high performers, and address execution gaps directly.
  • Oversee quality assurance and risk mitigation - review client deliverables and communications across key accounts to guarantee accuracy, technical rigor, and alignment with client business objectives.

Requirements

  • Senior client relationship leader - bring extensive experience managing executive client relationships, navigating complex accounts, and handling high-stakes escalations with composure.
  • Experienced manager of managers - possess 5+ years of experience leading mid-sized teams, including direct experience developing, managing, and holding first-line managers accountable.
  • Deep compliance domain authority - hold 8+ years of cybersecurity compliance expertise across SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, HITRUST, and NIST 800-171 or CMMC frameworks.
  • Policy framework architect - demonstrate 8+ years of hands-on experience authoring, implementing, and enforcing enterprise cybersecurity policies.
  • Disciplined operational operator - prove sound judgment under pressure with a bias toward taking immediate ownership and solving issues independently rather than escalating upward.
  • High-velocity startup performer - thrive in fast-paced cybersecurity environments, possessing the organizational discipline to manage multiple concurrent compliance programs seamlessly.
  • Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
  • Reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
  • Commitment to working a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners.
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
  • Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future.

Preferred Qualifications

  • Big 4 advisory tenure - background in management consulting, assurance, or advisory practice within Big 4 or top-tier consulting firms.
  • MSSP or GRC leadership experience - proven track record managing GRC delivery functions within a managed security service provider or specialized consulting organization.
  • Advanced security certifications - active professional certifications such as CISA, CISSP, CISM, ISO 27001 Lead Implementer, or CRISC.
  • GRC automation platform mastery - practical exposure to configuring and managing automated compliance platforms such as Vanta, Drata, or Secureframe.
  • Multi-framework audit expertise - deep familiarity with risk management frameworks and complex audit methodologies across diverse regulatory standards.

Benefits

  • Career Development: Clear growth path with mentorship and training opportunities.
  • Technical Training: Comprehensive onboarding on security and compliance frameworks.
  • Competitive Compensation: Competitive base salary with regular performance reviews, merit-based appraisals, and bonus opportunities.
  • Growth Opportunity: Early-stage company with significant room for career advancement.
  • Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team.

Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding. Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.

Similar jobs

Senior GRC Engineer

AircallNew York, NY· 1 mo ago
Engineering$163k–$220k/yrapply on job-boards.greenhouse.io

Senior GRC Engineer

WorkstreetUnited States· 1 mo ago
RemoteEngineeringapply on ats.rippling.com

Senior GRC Engineer

Nexus Venture PartnersSan Francisco, CA· 1 mo ago
Engineering$180k–$200k/yrapply on job-boards.greenhouse.io

Senior GRC Engineer

PostmanSan Francisco, CA· 1 mo ago
Engineering$180k–$200k/yrapply on job-boards.greenhouse.io