Posted today · be early
GRC Engineer I (Special Programs)
Workstreet
IndiaremotePosted 1 day ago
Skill Required
GRC-EngineerGovernance-Risk-And-ComplianceCompliance-EngineeringSecurity-Compliance-SpecialistDeliveryGRC-Security-EngineerGRC-EngineeringEngineering-GRCGRC-JobsGRC-SpecialistCybersecurityISO 27001automationdesigningsecuritywrittenTestNGandFulltime
Key highlights
- Competitive base salary with merit-based appraisals and bonus opportunities
- Must have hands-on execution experience across SOC 2, ISO 27001, or NIST CSF frameworks
- Must be available to work 8:00 AM–5:00 PM U.S. Eastern Time
- Reimbursement for approved training and certification course completion
- Remote-first culture with flexibility to work from anywhere
- Live video interviews with camera on are non-negotiable
Role overview
Workstreet is a fast-growing GRC (governance, risk, and compliance) startup that helps businesses scale securely by designing and implementing security and compliance programs across frameworks including SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. The Special Programs team delivers high-impact, fast-paced engagements—ranging from establishing a compliance foundation in 30 days to migrating organizations onto new GRC platforms, supporting audits, and providing other specialized compliance services—for hundreds of organizations from early-stage startups to global enterprises across nearly every industry.
Responsibilities
- Execute end-to-end client compliance initiatives, assisting in implementing and maintaining client security compliance programs aligned with SOC 2, ISO 27001, and regulatory standards
- Maintain policy and evidence repositories by authoring and updating corporate security policies, standard operating procedures, and control evidence to support formal audits and assessments
- Identify and mitigate technical risks by partnering with cross-functional technical teams to track, evaluate, and remediate cybersecurity risks and control gaps
- Manage project deliverables and timelines by tracking compliance milestones, evidence gathering, and task execution across concurrent client engagements under senior guidance
- Drive direct client communications by engaging directly with client stakeholders via email, chat, and video calls to gather evidence, clarify control requirements, and share updates
- Perform control testing and readiness reviews by conducting structured control evaluations and readiness checks to maintain continuous compliance alignment
- Partner cross-functionally on remediation by collaborating with internal IT, security, and operations teams to execute corrective action plans and improve compliance posture
- Contribute to operational process scaling by receiving mentorship from senior leaders while updating delivery templates, playbooks, and standard operating procedures
- Integrate quickly into the organization and manage active client accounts within the first 15 days
- Serve as the dedicated primary point of contact for a portfolio of accounts, guiding engagements end-to-end
- Resolve escalations with composure and urgency
- Ensure every client interaction reflects the highest standard of service
- Oversee a pod of analysts across frameworks such as SOC 2, ISO 27001, and NIST CSF
- Cultivate trust and drive program outcomes while managing accounts
Requirements
- Direct client engagement operator with proven ability to communicate directly with U.S. clients, maintaining professionalism and executive care across all touchpoints
- Multi-project GRC operator with strong organizational discipline to manage multiple cybersecurity compliance engagements simultaneously without losing velocity
- Technical compliance practitioner with hands-on execution experience across SOC 2, ISO 27001, or NIST CSF frameworks within tech-focused cybersecurity environments
- Policy lifecycle architect with practical familiarity authoring, rolling out, and enforcing enterprise cybersecurity policies and control benchmarks
- High-velocity startup operator who thrives in fast-paced startup settings, adapting quickly to shifting priorities and dynamic client challenges
- Exceptional technical communicator with outstanding written and verbal English communication skills suited for executive and technical interactions
- Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams
- A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration
- Commitment to working a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners while ensuring timely communication and support
- Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed
Nice to have
- Compliance automation platform mastery with practical exposure utilizing automated compliance solutions such as Vanta or similar GRC platforms
- Expanded regulatory framework knowledge with practical familiarity with additional regulatory frameworks including GDPR, HIPAA, or PCI DSS
- Active industry certifications as a credentialed practitioner holding recognized certifications such as ISO 27001 Lead Implementer, CISA, or Security+
Benefits
- Career Development: Clear path with mentorship and training opportunities
- Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role
- Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities
- Growth Opportunity: Early-stage company with significant room for career advancement
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team
Additional details
- Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding
- Employment is contingent upon successful completion of identity verification and background screening, where permitted by law
- Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet's operating principles
- Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step
- Reliable high-speed internet connection required
- Quiet, professional home office setup required
- Must be amenable to work US Eastern Time zone hours
- Fluency in written and verbal English communication skills required
- Workstreet is an equal opportunity employer committed to providing employment opportunities to all individuals; all applicants will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law
- Originally posted on Himalayas