GRC Engineer (CMMC)
Workstreet - United States
Hiring: GRC Engineer (CMMC) Company: Workstreet Location: United States Job Posted Time: 2026-09-16 17:42:54 Employment Type: Remote Target Skills & Keywords : AWS, Azure, CPT, FedRAMP, GDPR, Microsoft Excel, Project Management, SOC 2, SaaS About the job Experience: •2+ years of direct execution in GRC roles with active exposure driving FedRAMP, NIST SP 800-53, and federal authorization lifecycles. Required Skills: •Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to ensure client software architectures align with federal agency requirements. •Author and update core federal authorization artifacts, including System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, and SARs. •Perform detailed readiness assessments and gap analyses to prepare client environments for Joint Authorization Board (JAB) or Agency ATO validation paths. •Architect technical authorization boundaries and scoping profiles across FedRAMP and CMMC environments, mapping data flows, interconnectivity, and shared responsibility models. •Execute continuous monitoring (ConMon) cycles, actively tracking monthly vulnerability management logs, incident response reports, and structural change control workflows. •Coordinate external assessment pipelines, facilitating critical operational alignment between clients, Cloud Service Providers (CSPs), 3PAOs, and federal stakeholders. •Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 controls, translating dense regulatory language into practical, actionable security milestones. •Formulate highly structured compliance documentation specifically required for CMMC Level 1 and Level 2 assessment readiness. Qualifications: •Proven federal compliance analyst - Bring 2+ years of direct execution in GRC roles with active exposure driving FedRAMP, NIST SP 800-53, and federal authorization lifecycles. •Federal documentation practitioner - Hands-on experience authoring, evaluating, and maintaining key federal artifacts, explicitly including System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms). •CMMC and NIST framework generalist - Grounded in the structural requirements of CMMC 2.0 and NIST SP 800-171 baselines as they apply to defense contractors and supply chain data. •Sovereign cloud environment navigator - Familiar with the shared responsibility models, operational constraints, and secure configurations of government clouds like AWS GovCloud, Azure Government, or Microsoft GCC High. •Disciplined portfolio coordinator - Command strong project management mechanics to support multiple fast-moving client compliance initiatives simultaneously while preserving documentation quality. •Regulated technology consultant - Experienced partnering with B2B SaaS providers, federal contractors, or regulated tech companies to systematically navigate federal security baselines. •High-velocity startup operator - Excel within fluid consulting or fast-growth startup environments, demonstrating the agility to adapt to shifting client demands and assert immediate task ownership. •What Will Help You Succeed •Direct JAB or Agency ATO execution - Direct history supporting live Joint Authorization Board or federal agency Authority to Operate (ATO) certification tracks. •Credentialed compliance professional - Hold industry-specific defense designations such as CMMC Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA). Compensation: •Flexible work environment (work from home / hybrid options) •Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!