Workstreet logo

GRC Engineer – NIST

Workstreet

AnywhereFull-time3 days agoRemote
Apply Now

At a Glance

Employment Type
Full-time
Experience Level
Mid-level
Location
Anywhere (Remote)
Salary
$41.4k - $86.1k
Posted
3 days ago

This is a full-time GRC Engineer – NIST position at Workstreet, based in Anywhere, with remote work available. The role offers $41.4k - $86.1k.

Compensation

$41.4k - $86.1k

Job Description

Job Description

  • Execute NIST 800-53 control mappings and apply security and privacy controls and baselines to software architectures
  • Create, update, and maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and supporting authorization artifacts
  • Conduct technical gap analyses and readiness reviews for federal agency ATO or FedRAMP authorization paths
  • Support continuous monitoring cycles by tracking monthly vulnerability logs, POA&M updates, and structural change requests
  • Guide clients through the Assessment and Authorization (A&A) process
  • Coordinate operational logistics with 3PAOs and independent assessors
  • Partner with internal and client technical teams to remediate control deficiencies across Low, Moderate, and High baselines
  • Document technical security boundaries, interconnectivity agreements, and shared responsibility profiles across cloud environments
  • Track evolving NIST SP 800-53 revisions, FedRAMP requirements, and federal policy updates
  • Partner directly with organizations pursuing federal authorizations
  • Manage multiple compliance projects concurrently under senior guidance
  • Collaborate with global teams during U.S. Eastern Time business hours

Requirements

  • 2+ years of direct experience executing GRC deliverables across NIST SP 800-53, FedRAMP, or NIST Risk Management Framework (RMF) lifecycles
  • Hands-on experience creating, evaluating, and maintaining System Security Plans (SSPs), POA&Ms, and technical security narratives
  • Ability to manage multiple federal compliance project tasks simultaneously while maintaining attention to detail
  • Familiarity with cloud service providers and secure configurations in government clouds such as AWS GovCloud or Azure Government
  • Strong written and verbal English communication skills
  • Foundational knowledge of NIST SP 800-53 and FedRAMP Moderate and High baseline requirements
  • Recognized professional designation such as CGRC, CAP, CISSP, or CompTIA Security+ (helpful)
  • Practical experience supporting live agency Authority to Operate (ATO) certifications or working alongside 3PAO assessment teams (helpful)
  • Familiarity with automated or manual FedRAMP Continuous Monitoring (ConMon) workflows (helpful)
  • Exposure to CMMC 2.0 or NIST SP 800-171 baselines (helpful)
  • Reliable, high-speed internet connection
  • Professional home office environment supporting confidential conversations and uninterrupted collaboration
  • Availability for a standard schedule of 8:00 AM–5:00 PM US Eastern Time
  • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities
  • Must participate in live video interviews with camera on and verify identity during recruitment and onboarding
  • Employment contingent upon identity verification and background screening, where permitted by law
  • Must be authorized to work in the U.S. without current or future visa sponsorship

Benefits

  • Career development with mentorship and training opportunities
  • Reimbursement for approved role-related training and certification courses
  • Competitive base salary
  • Regular performance reviews linked to merit-based appraisals
  • Bonus opportunities
  • Significant room for career advancement
  • Remote-first culture with flexibility to work from anywhere
  • Collaboration with a global team

Job Details

Employment Type
Full-time
Location
Anywhere
Remote Work
Yes
Posted
3 days ago

Ready to Apply?

Click below to apply directly on the company's website.

Apply on Company Website