Workstreet
GRC Engineer (CMMC)
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 2h ago · Added today
First listed today.
Salary
Not stated
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Mid
Category
Software
This employer didn't state pay. Jobs like this usually pay around $155k–$250k a year, a typical range taken from 596 mid-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Remote (United States)"
- Job description states: "authorized to work in the U.S. without the need for visa"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Workstreet
At Workstreet , we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment & Authorization compliance efforts. We act as our clients' trusted guides and primary point of contact end-to-end, leading them through gap assessments, System Security Plans, POA&Ms, and C3PAO/3PAO coordination with clarity, composure, and a genuinely client-first mindset. Beyond the technical depth in RMF, CUI/DFARS requirements, and GovCloud environments, what defines us is how we work: we translate complex requirements into plain language, manage escalations with urgency and care, and take real pride in making every client feel informed, supported, and well-prepared. We're a group that mentors one another, holds a high bar for quality, and thrives in a fast-paced environment where our work directly strengthens the security of the defense industrial base.
The Opportunity
We are seeking a GRC Engineer who is highly motivated, detail-oriented, and has foundational knowledge of FedRAMP Moderate and High baseline requirements, with complementary experience supporting CMMC and NIST SP 800-171-based programs. The ideal candidate brings strong client-facing communication skills and the ability to contribute to multiple compliance initiatives simultaneously. This role is focused on guiding clients through federal compliance frameworks, supporting both SaaS providers and federal contractors through the FedRAMP authorization lifecycle—including readiness assessment, authorization support, and continuous monitoring—as well as advising defense contractors on CMMC Level 1 and Level 2 compliance and related NIST 800-171 requirements. The successful candidate will play a critical role in helping clients achieve and sustain federal and DoD compliance while leading high-quality delivery across all engagements.
What You'll Do
Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to ensure client software architectures align with federal agency requirements.
Author and update core federal authorization artifacts , including System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, and SARs.
Perform detailed readiness assessments and gap analyses to prepare client environments for Joint Authorization Board (JAB) or Agency ATO validation paths.
Architect technical authorization boundaries and scoping profiles across FedRAMP and CMMC environments, mapping data flows, interconnectivity, and shared responsibility models.
Execute continuous monitoring (ConMon) cycles , actively tracking monthly vulnerability management logs, incident response reports, and structural change control workflows.
Coordinate external assessment pipelines , facilitating critical operational alignment between clients, Cloud Service Providers (CSPs), 3PAOs, and federal stakeholders.
Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 controls , translating dense regulatory language into practical, actionable security milestones.
Formulate highly structured compliance documentation specifically required for CMMC Level 1 and Level 2 assessment readiness.
Who You Are
Proven federal compliance analyst - Bring 2+ years of direct execution in GRC roles with active exposure driving FedRAMP, NIST SP 800-53, and federal authorization lifecycles.
Federal documentation practitioner - Hands-on experience authoring, evaluating, and maintaining key federal artifacts, explicitly including System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
CMMC and NIST framework generalist - Grounded in the structural requirements of CMMC 2.0 and NIST SP 800-171 baselines as they apply to defense contractors and supply chain data.
Sovereign cloud environment navigator - Familiar with the shared responsibility models, operational constraints, and secure configurations of government clouds like AWS GovCloud, Azure Government, or Microsoft GCC High.
Disciplined portfolio coordinator - Command strong project management mechanics to support multiple fast-moving client compliance initiatives simultaneously while preserving documentation quality.
Regulated technology consultant - Experienced partnering with B2B SaaS providers, federal contractors, or regulated tech companies to systematically navigate federal security baselines.
High-velocity startup operator - Excel within fluid consulting or fast-growth startup environments, demonstrating the agility to adapt to shifting client demands and assert immediate task ownership.
What will help you succeed
Direct JAB or Agency ATO execution - Direct history supporting live Joint Authorization Board or federal agency Authority to Operate (ATO) certification tracks.
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- ·Career Development : Clear path with mentorship and training opportunities.
- ·Role-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.
- ·Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.
- ·Growth Opportunity : Early-stage company with significant room for career advancement.
- ·Remote-First Culture : Flexibility to work from anywhere while collaborating with a global team.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Workstreet, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 15h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $155k to $250k per year · You'll be taken to the employer's careers page.