GRC Engineer (CMMC/FedRAMP)
Workstreet
About Workstreet At Workstreet, we're on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of frameworks-including SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP-empowering companies to meet regulatory requirements and enhance their cybersecurity posture from day one. The Opportunity We are seeking a GRC Engineer who is highly motivated, detail-oriented, and has foundational knowledge of FedRAMP Moderate and High baseline requirements, with complementary experience supporting CMMC and NIST SP 800-171-based programs. The ideal candidate brings strong client-facing communication skills and the ability to contribute to multiple compliance initiatives simultaneously. This role is focused on guiding clients through federal compliance frameworks, supporting both SaaS providers and federal contractors through the FedRAMP authorization lifecycle-including readiness assessment, authorization support, and continuous monitoring-as well as advising defense contractors on CMMC Level 1 and Level 2 compliance and related NIST 800-171 requirements. The successful candidate will play a critical role in helping clients achieve and sustain federal and DoD compliance while leading high-quality delivery across all engagements. What You'll Do
Workstreet Is An Equal Opportunity Employer As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law. Employment with Workstreet is contingent upon the successful completion of a background check, which may include verification of employment history, education, and other relevant information, in compliance with applicable laws.
- Interpret and Apply FedRAMP Requirements:
Analyze and apply NIST SP 800-53 controls, FedRAMP baselines, and agency-specific requirements to ensure client compliance. - Develop and Maintain FedRAMP Documentation:
Develop and maintain System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, SARs, and continuous monitoring artifacts. - Conduct FedRAMP Readiness Assessments:
Perform gap analyses and readiness reviews to prepare organizations for JAB or Agency ATO pathways. - Support Authorization and Assessment Activities:
Coordinate with Third-Party Assessment Organizations (3PAOs), cloud service providers, and government stakeholders throughout the FedRAMP lifecycle. - Boundary Definition & Scoping:
Perform CMMC/FedRAMP authorization boundary definition and system scoping activities, including identification of in-scope components, interconnections, data flows, and shared responsibility models to ensure alignment with FedRAMP PMO and agency expectations. - Support Continuous Monitoring Programs:
Conduct monthly, quarterly, and annual FedRAMP continuous monitoring requirements, including vulnerability management, incident response reporting, and change control. - Support FedRAMP Engagements:
Assist on multiple concurrent client projects, ensuring milestones, deliverables, and quality standards are consistently met or exceeded. - Support CMMC and NIST 800-171 Compliance Efforts:
Assist defense contractors with interpreting CMMC 2.0 and NIST SP 800-171 controls and implementing compliant security programs. - Develop CMMC Documentation:
Contribute to SSPs, POA&Ms, and supporting artifacts required for CMMC Level 1 and Level 2 readiness.
- Strong organizational and project management skills with the ability to manage multiple engagements concurrently
- 2+ years of experience in GRC, with exposure to FedRAMP, NIST SP 800-53, and federal compliance programs
- Working knowledge of CMMC 2.0 and NIST SP 800-171 requirements
- Experience authoring and reviewing SSPs, POA&Ms, and assessment artifacts
- Familiarity with federal cloud environments (AWS GovCloud, Azure Government, GCC High)
- Experience working with SaaS providers, federal contractors, or regulated technology organizations
- Ability to thrive in a fast-paced, consulting, or startup environment
- FedRAMP-specific experience supporting JAB or Agency ATOs
- CMMC Registered Practitioner (RP), CCP, or CCA certification
- CISSP, CISM, or Security+ certification
- Experience with DFARS clauses and CUI handling requirements
- Familiarity with SPRS reporting and DoD assessment workflows
- Prior experience working directly with 3PAOs or C3PAOs
- Reliable high-speed internet connection.
- Quiet, professional home office setup.
- Must be amenable to work US Eastern Time zone hours.
- Fluency in written and verbal English communication skills.
Workstreet Is An Equal Opportunity Employer As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law. Employment with Workstreet is contingent upon the successful completion of a background check, which may include verification of employment history, education, and other relevant information, in compliance with applicable laws.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the GRC Engineer (CMMC/FedRAMP) in United States vacancy
- ...A fast-growing startup in the United States is seeking a GRC Engineer to support clients in achieving federal compliance through FedRAMP and NIST frameworks. The ideal candidate will have over 2 years of experience in GRC, demonstrating strong project management and organizational...Suggested
- ...Sr. GRC Engineer Opportunity At Workstreet, we're on an exciting journey to help businesses scale securely by designing... ...of frameworks—including SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP—empowering companies to meet regulatory requirements...SuggestedRemote workHome office
- ...IonQ is looking for a Governance, Risk, and Compliance Engineer to enhance its cybersecurity posture. You'll be responsible for implementing CMMC controls and ensuring audit readiness. Ideal candidates have 2-4 years in cybersecurity with experience in NIST SP 800-171...SuggestedRemote work
$130k - $170k
...decisions. The founding team of Stanford engineers was named Forbes 2019 30 under 30 and is... ...Ventures and Footwork VC. As the FedRAMP & CMMC Compliance Lead, you will own our compliance... ...System Security Plan. Proficiency with GRC platforms (Drata, Vanta, eMASS, or similar...SuggestedFor contractorsWork at office- ...Sr. GRC Engineer (Government) At Workstreet, we're on an exciting journey to help businesses scale securely by designing... ...-growing startup, we specialize in frameworks such as CMMC, NIST 800-171, NIST 800-53, FedRAMP, enabling companies to meet regulatory requirements...SuggestedPermanent employmentContract workFor contractorsHome office
$130k - $160k
...compliance and certification program, involving SOC 2, ISO 27001, and FedRAMP certifications. You will enhance control frameworks and manage... ...closely with various teams. A minimum of 3 years in GRC is required along with foundational knowledge of security compliance...$95k - $110k
...Blackkite is looking for a Senior GRC Analyst to oversee compliance efforts and support customer security assessments in the United... ...compliance platform, respond to customer inquiries, and contribute to FedRAMP reporting. The expected salary range is $95,000-$110,000 per...Flexible hours$100k - $125k
...Compliance Consultant to work 100% remote and help DoD contractors pass CMMC audits. Responsibilities include leading CMMC policy development,... ...candidates should have 3-5 years of experience in cybersecurity GRC, a deep understanding of NIST 800-171 and CMMC, and hold a...For contractorsRemote work- A prominent technology firm in Seattle is seeking a Governance, Risk, and Compliance (GRC) Analyst to enhance its data and insights solutions. The role emphasizes sustaining FedRAMP Moderate Authorization and requires strong organizational skills and collaboration across...
$95k - $110k
Blackkite in Boston seeks a Senior GRC Analyst to manage compliance platforms and customer security assessments. The ideal candidate... ...security, paired with skills in SOC 2 and ISO 27001. You'll support FedRAMP ConMon reporting and ensure audit-ready documentation while...- ...intimate knowledge of our customers’ business. About the Role As a GRC Consultant at Network Coverage, you will be part of the GRC Team... ...a client facing capacity, under the guidance of the Director of CMMC Compliance and Chief Advisory Officer. Due to the nature of the work...Work at officeRemote workOverseasFlexible hoursShift work
- ...Hotman Group is seeking a CMMC / NIST Consultant / Analyst to support client projects involving... ..., NIST SP 800-171, NIST SP 800-53, FedRAMP, evidence collection, control documentation... ...for 3-5 years of relevant experience in GRC, cybersecurity compliance, or related consulting...Full timeContract workPart timeRemote work
- ...Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for... ...the Defense Industrial Base navigating CMMC, NIST 800-171, and federal compliance requirements... ...with NIST SP 800-171, NIST SP 800-53, and FedRAMP documentation, control mapping, and...Permanent employmentFull timeContract workPart timeRemote work
$130k - $150k
...than yourself. The Opportunity We are hiring a Senior GRC Engineer to build and scale an engineering-driven, automation-first, and... ...and support audits including SOC 2, ISO 27001, ISO 27701, FedRAMP and CJIS Build automated audit readiness and continuous compliance...Work at officeRemote workWork from homeHome officeFlexible hours$180k - $200k
...matter, you'll feel at home here. Aircall is hiring a Senior GRC Engineer to build and operate the engineering backbone of our... ...Type II, ISO 27001 (and any future certifications such as HIPAA, FedRAMP, PCI as the strategy evolves), preparing evidence, walking auditors...Worldwide- ...in collaboration with Security Engineers based on where CUI/FCI resides... ...Create and maintain the full CMMC compliance policy library: access... ...in cybersecurity compliance, GRC, or IT audit roles. ~ Direct... ...(NIST 800-171, NIST 800-53, FedRAMP, ISO 27001, or similar). ~ Working...For contractors
$115.7k - $160.1k
...Blackboard seeks a Staff Governance, Risk & Compliance Engineer to manage compliance programs including FedRAMP and State/Federal regulations. This remote role requires 8+ years of experience in compliance and risk management, strong documentation skills, and the ability...Remote work- ...GRC Security Engineer, Federal & Public Sector Engineering · Full-time · San Francisco Our mission... ...to get there. Federal compliance — FedRAMP and adjacent authorizations — is a key... ...knowledge of FIPS 140-3, FedRAMP 20x / KSIs, CMMC, and how DoD impact levels map onto...Full time
- ...Senior Security Compliance Engineer, AWS (FedRAMP High / DoD IL5) Remote, US Description Keeper Security is hiring a Senior Security Compliance Engineer to lead the technical implementation and ongoing maintenance of FedRAMP High and DoD IL5 compliance for our AWS-based...Temporary workRemote work
- B Capital is seeking a Public Sector GRC Lead in San Francisco to manage FedRAMP compliance and drive security governance in cloud products. You will be responsible for maintaining key documents, engaging with auditors, and supporting sales in targeting public sector compliance...
- A leading technology firm in Boston is seeking a GRC Program Manager to oversee FedRAMP authorization and broader compliance initiatives. The role requires managing complex audits, coordinating across teams, and enhancing GRC processes. Ideal candidates have 5+ years in...
- ...JOB DESCRIPTION: Insight Global's government drone manufacturing client is seeking a Systems Engineer to support a time-sensitive CMMC 2.0 certification initiative. This role will focus on securing and managing a small, distributed Windows environment, while helping...Remote work
- ...GRC Engineer Every enterprise spends millions of dollars on Governance, Risk, and Compliance (GRC). It's one of the most critical, yet... ...two major compliance frameworks (SOC 2, ISO 27001, NIST CSF, FedRAMP, HIPAA, PCI-DSS, or similar). You've lived inside these frameworks...Contract workWork at officeRelocation packageFlexible hoursDay shift
- The Merlin Group is seeking an Automation Engineer in McLean, VA. This role focuses on designing and implementing CI/CD and evidence automation... ...to transform manual compliance into automated processes in a FedRAMP-authorized environment. Ideal candidates have 3+ years of...
- ...GRC Engineer McLean, Virginia; Mountain View, California, United States Company Overview ID.me is the next-generation digital identity... ...AI agents that automate the compliance lifecycle across FedRAMP, ISO 27001, SOC 2, and Kantara accreditation programs. This...Full timeWork at office
$200k - $250k
...fleet is the small team that keeps Postman engineers productive, secure, and unblocked. We're... ...will partner closely with Security and GRC on CMMC Level 2 readiness, and you'll have a... ...frameworks such as CMMC, SOC 2, ISO 27001, or FedRAMP. Familiarity with managing Windows or...Contract workWork at officeFlexible hours3 days per week- ...technically sound Governance, Risk, and Compliance (GRC) program is critical. We are looking for a GRC Engineer to serve as a key technical contributor for our... ...certifications in regulated markets (e.g., FedRAMP, ITAR, PCI, HIPAA ). Pragmatic Governance: Apply...Full timeTemporary workWork at officeWorldwideMonday to FridayFlexible hoursShift work
- ...Security Engineer Saronic Technologies is a leader in revolutionizing autonomy at sea... ...-on security engineering role; not a GRC or project management role. No single... ...including NIST SP 800-53, NIST SP 800-171, CMMC 2.0, FedRAMP, IEC 62443, IMO MASS Code, and IACS UR...Permanent employmentContract workTemporary workWork at office
- ...Framework Ventures is seeking a Senior GRC Engineer to enhance compliance and risk management via automation. The ideal candidate will lead the development of automated compliance systems supporting the Magic Labs ecosystem. Key responsibilities include building integrations...Remote workFlexible hours
- Opportunity Overview Northramp is seeking a Test Automation Engineer to join the team supporting the client’s Cloud BPA Bridge program... ...cloud services across IaaS, PaaS, and SaaS environments under FedRAMP High authorization. You will design and operate automated testing...Temporary workLocal areaRemote workWork from homeShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Engineer (CMMC/FedRAMP). Be the first to apply!

