Manager, GRC Engineering
Workstreet - United States
Hiring: Manager, GRC Engineering Company: Workstreet Location: United States Job Posted Time: 2026-09-16 17:44:44 Employment Type: Remote Target Skills & Keywords : AWS, Azure, CPT, Embedded Systems, FedRAMP, GCP, GDPR, HIPAA, Program Management, Risk Management, SOC 2, SaaS About the job Experience: •8+ years of experience in information security, including at least 3 years in a senior security leadership role, driving security strategy, governance, and risk management across complex environments. •At least 3 years in a senior security leadership role, driving security strategy, governance, and risk management across complex environments. Required Skills: •We are seeking a Manager, GRC Engineering •Own the vCISO relationship end-to-end - serve as the dedicated virtual CISO for a portfolio of clients, operating with the executive authority, credibility, and trust of an embedded security leader. •Lead strategic client engagements and security roadmaps - guide clients from initial risk assessment through certification milestones, providing proactive executive guidance, strategic direction, and risk management aligned to business goals. •Represent clients on live prospect and customer calls - join client sales and due diligence calls as their acting CISO, answering technical security questions in real-time with total fluency in their architecture and controls without notes. •Handle high-stakes escalations with executive authority - resolve complex security issues and client escalations with urgency and composure, making independent, authoritative security calls without deferring judgment. •Deliver contextualized strategic security leadership - deeply understand each client's tech stack, business model, and risk appetite to produce custom architecture recommendations, threat models, policy sets, and executive briefings. •Lead comprehensive risk and compliance oversight - conduct risk assessments, maintain registers, and guide programs across frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, CMMC, NIST CSF/800-171, GDPR, CCPA, DORA, and NYDFS. •Manage continuous compliance and security operations - facilitate quarterly access reviews, annual pentests, and tabletop IR exercises while leveraging GRC platforms (Vanta, Drata, SecureFrame) for continuous audit readiness. Qualifications: •Extensive information security leadership experience - you bring 8+ years of experience in information security, including at least 3 years in a senior security leadership role, driving security strategy, governance, and risk management across complex environments. •Demonstrated client relationship management - you're comfortable owning client engagements, leading difficult conversations, serving as a trusted security advisor, and building long-term relationships with executive stakeholders. •Executive-level security communication - you're confident discussing security architecture, compliance posture, and control trade-offs with clients and prospects, translating complex technical concepts into practical business decisions without sacrificing accuracy. •Deep expertise in cybersecurity frameworks - you have extensive hands-on knowledge of frameworks and standards such as SOC 2, ISO 27001, NIST CSF, HIPAA, HITRUST, NIST SP 800-171, and/or CMMC, helping organizations build and mature security programs. •Strong program and client management skills - you're experienced managing multiple security programs or client engagements simultaneously, ideally within consulting, advisory, or fractional security leadership environments. •Exceptional communication skills - you communicate with clarity, confidence, and precision, effectively translating technical risks into business language for executive, technical, and non-technical audiences. •Independent decision-maker - you're comfortable owning your client portfolio, exercising sound judgment, and making informed security decisions independently while maintaining accountability for outcomes. •Strong technical cloud security expertise - you have practical experience implementing and evaluating security controls across cloud platforms such as AWS, GCP, and Azure, with a solid understanding of cloud security architecture and best practices. •What Will Help You Succeed •Active executive security credentials - hold recognized professional certifications such as CISSP, CISM, or CISA. Compensation: •Flexible work environment (work from home / hybrid options) •Competitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!