Workstreet
Manager, GRC Engineering
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 2h ago · Added today
First listed today.
Salary
Not stated
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Senior
Category
Software
This employer didn't state pay. Jobs like this usually pay around $170k–$225k a year, a typical range taken from 597 senior-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States (Remote)"
- Job description states: "authorized to work in the U.S. without the need for visa"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Workstreet
At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the GRC Engineering Team
Our GRC Engineering team is the primary point of contact for Workstreet's clients. We bring deep framework compliance knowledge and program management to each engagement to ensure our clients' compliance goals are met. Our teammates are trusted advisors not only in the compliance space, but also operationally in the role of vCISO. We deliver quickly using common templates and methodologies and are adept at creative problem-solving. GRC Engineering Team members also listen for and act as a centralized resource to advise clients on Workstreet's other service offerings to support their compliance, privacy, and information security goals.
The Opportunity
We are seeking a Manager, GRC Engineering (vCISO) who leads with a client-first mindset and brings the executive presence, technical depth, and relationship skills to serve as a trusted security leader for a portfolio of clients. The ideal candidate is a seasoned security professional who knows how to build trust with executive stakeholders, speak fluently about complex security architectures, and represent clients confidently on their most important prospect and customer calls.
The successful candidate will be able to come up to speed quickly, integrate into the organization, and take on clients within your first 30 days. You will serve as the dedicated virtual CISO for a portfolio of clients, owning strategic security relationships end-to-end, guiding risk and compliance decisions with authority, and ensuring every client can count on you as a security expert.
What You'll Do
Own the vCISO relationship end-to-end - serve as the dedicated virtual CISO for a portfolio of clients, operating with the executive authority, credibility, and trust of an embedded security leader.
Lead strategic client engagements and security roadmaps - guide clients from initial risk assessment through certification milestones, providing proactive executive guidance, strategic direction, and risk management aligned to business goals.
Represent clients on live prospect and customer calls - join client sales and due diligence calls as their acting CISO, answering technical security questions in real-time with total fluency in their architecture and controls without notes.
Handle high-stakes escalations with executive authority - resolve complex security issues and client escalations with urgency and composure, making independent, authoritative security calls without deferring judgment.
Deliver contextualized strategic security leadership - deeply understand each client's tech stack, business model, and risk appetite to produce custom architecture recommendations, threat models, policy sets, and executive briefings.
Lead comprehensive risk and compliance oversight - conduct risk assessments, maintain registers, and guide programs across frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, CMMC, NIST CSF/800-171, GDPR, CCPA, DORA, and NYDFS.
Manage continuous compliance and security operations - facilitate quarterly access reviews, annual pentests, and tabletop IR exercises while leveraging GRC platforms (Vanta, Drata, SecureFrame) for continuous audit readiness.
Maintain proactive client mastery - participate in regular syncs, contextualize GRC platform telemetry, track architectural changes, and identify emerging risks before they manifest into operational blockers.
Lead, coach, and develop a pod of GRC analysts - manage 3–5 analysts through direct coaching, performance management, and delivery oversight to drive high-quality execution across active client accounts.
Drive internal practice development and pre-sales - refine internal vCISO playbooks, mentor junior practice members, and join pre-sales scoping discussions to support proposal development.
Who You Are
Extensive information security leadership experience - you bring 8+ years of experience in information security, including at least 3 years in a senior security leadership role, driving security strategy, governance, and risk management across complex environments.
Demonstrated client relationship management - you're comfortable owning client engagements, leading difficult conversations, serving as a trusted security advisor, and building long-term relationships with executive stakeholders.
Executive-level security communication - you're confident discussing security architecture, compliance posture, and control trade-offs with clients and prospects, translating complex technical concepts into practical business decisions without sacrificing accuracy.
Deep expertise in cybersecurity frameworks - you have extensive hands-on knowledge of frameworks and standards such as SOC 2, ISO 27001, NIST CSF, HIPAA, HITRUST, NIST SP 800-171, and/or CMMC, helping organizations build and mature security programs.
Strong program and client management skills - you're experienced managing multiple security programs or client engagements simultaneously, ideally within consulting, advisory, or fractional security leadership environments.
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- ·Career Development : Clear path with mentorship and training opportunities.
- ·Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
- ·Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- ·Growth Opportunity : Early-stage company with significant room for career advancement.
- ·Remote-First Culture : Flexibility to work from anywhere while collaborating with a global team.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Workstreet, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 15h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $170k to $225k per year · You'll be taken to the employer's careers page.