{"id":1266931,"url":"https://alion.io/job/workstreet-senior-grc-engineer-3","title":"Senior GRC Engineer","company":{"id":686337,"name":"Workstreet","domain":"workstreet.com","url":"https://alion.io/company/workstreet","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Rippling","truth_index":{"grade":"B","score":80,"open_postings":10,"ghost_share":0,"stale_share":0.8,"repost_share":0,"time_to_fill_p50_days":35,"computed_at":"2026-10-02T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Philippines"],"countries":["PH"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":23000,"max_usd":51000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1261},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"FedRAMP","optional":false},{"name":"GDPR","optional":false},{"name":"HIPAA","optional":false},{"name":"ISO 27001","optional":false},{"name":"NIST 800-171","optional":false},{"name":"NIST 800-53","optional":false},{"name":"NIST CSF","optional":false},{"name":"PCI DSS","optional":false},{"name":"SOC 2","optional":false}],"status":"live","first_seen_at":"2026-09-25T19:40:56Z","employer_posted_date":"2026-09-25","last_verified_at":"2026-10-02T15:02:19Z","board_verified":true,"closed_at":null,"days_open":7,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":7},"description":"About Workstreet\nAt Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.\nGet to know the GRC Engineering Team\nOur GRC Engineering team is the primary point of contact for Workstreet's clients. We bring deep framework compliance knowledge and program management to each engagement to ensure our clients' compliance goals are met. Our teammates are trusted advisors not only in the compliance space, but also operationally in the role of vCISO. We deliver quickly using common templates and methodologies and are adept at creative problem-solving. GRCEngineering Team members also listen for and act as a centralized resource to advise clients on Workstreet's other service offerings to support their compliance, privacy, and information security goals.\nThe Opportunity\nWe are seeking a highly motivated, client-focused Sr. GRC Engineer to join our fast-growing team. The ideal candidate is a seasoned client relationship manager who brings deep expertise in cybersecurity compliance and a proven track record of leading high-complexity client engagements with professionalism and care. This role is first and foremost about delivering an exceptional client experience - managing accounts, building trust, and driving successful outcomes - while overseeing a pod of analysts and applying expertise across frameworks such as SOC 2, ISO 27001, and NIST CSF.\nThe successful candidate will be able to come up to speed quickly, integrate into the organization, and take on clients within your first 15 days. You will serve as the primary point of contact for a portfolio of clients, leading engagements end-to-end, managing escalations with composure and urgency, and ensuring every client interaction reflects the highest standard of service.\nWhat You'll Do\nOwn the client relationship lifecycle as the dedicated primary contact for a portfolio of high-complexity, long-term accounts, ensuring premium delivery, milestone tracking, and proactive account management.\nLead end-to-end compliance engagements, directing routine milestone check-ins, delivering progress logs, and steering tech clients confidently through dense audit lifecycles.\nExecute direct client communications, partnering closely with US-based client executives, DevOps leads, and technology founders via multi-channel pathways to provide tailored risk guidance.\nResolve complex account escalations swiftly and professionally, applying a clinical, solution-oriented approach that solidifies long-term retention, customer satisfaction, and trust.\nSupervise, mentor, and upscale a pod of junior analysts, managing day-to-day operations, implementing constructive feedback loops, and driving rigorous delivery standards.\nAnalyze and apply global cybersecurity frameworks, mapping technical environments and corporate architectures against SOC 2, ISO 27001, HIPAA, and NIST CSF baselines.\nFormulate and maintain enterprise compliance programs, authoring foundational security policies, operational procedures, and audit-ready control documentation.\nPartner cross-functionally with internal and external teams to systematically isolate, evaluate, and mitigate operational cybersecurity and data compliance risks.\nDrive continuous process improvement, modifying standard operating procedures, technical playbooks, and internal assessment frameworks to optimize team execution velocity.\nWho You Are\nProven client relationship manager - Command a documented history of independently owning high-consequence client accounts, successfully navigating difficult risk conversations, and building trusted advisor status with C-suite stakeholders.\nElite corporate communicator - Deliver flawless written and verbal English communication capable of confidently breaking down complex technical parameters for US-based tech founders and cross-functional business units.\nScale-oriented team leader - Bring 3+ years of experience managing, upskilling, and leading a technical pod, squad, or small team, with a verifiable track record of driving accountability and project results.\nHands-on GRC program architect - Bring 3+ years of practical experience constructing, implementing, and defending robust compliance programs under SOC 2, ISO 27001, or NIST CSF architectures.\nDisciplined portfolio manager - Command sharp project management mechanics to successfully orchestrate multiple multi-threaded compliance engagements simultaneously without losing delivery quality.\nHigh-velocity startup operator - Excel within fluid, fast-growth technology environments, possessing the immediate operational agility to fully integrate into an organization and absorb complex client portfolios within your first 15 days.\nPolicy governance architect - Experienced engineering, maintaining, and enforcing enterprise cybersecurity policies that seamlessly align strict regulatory criteria with business growth targets.\nDomain-native tech professional - Verifiable tenure operating within cybersecurity-focused technology organizations where security governance, risk assessment, and technical compliance serve as core business differentiators.\nWhat will help you succeed\nBig 4 advisory or assurance tenure - Prior success directing complex IT compliance audits, data governance assessments, or technical risk advisory workflows inside elite environments like Deloitte, PwC, EY, or KPMG.\nMulti-framework compliance command - Advanced familiarity with specialized, adjacent international frameworks and regulatory bodies, explicitly including HIPAA, PCI DSS, or regional data sovereignty baselines.\nMastery of compliance automation architectures - Direct backend operational mastery navigating, configuring, and tracking continuous evidence collection inside automated platforms like Vanta.\nValidated industry credentials - Hold active, globally recognized professional security and audit designations such as CISA, CISSP, ISO 27001 Lead Implementer, or CompTIA Security+.\nAdvanced audit coordination background - Proven history managing full-lifecycle third-party assessments, audit pathways, and independent examiner walkthroughs.\nWhat we offer\nCareer Development: Clear path with mentorship and training opportunities.\nRole-Related Training: Reimbursement for the successful completion of approved training and certification courses relevant to your current role.\nCompetitive Compensation: A competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities.\nGrowth Opportunity: Early-stage company with significant room for career advancement.\nRemote-First Culture: Flexibility to work from anywhere while collaborating with a global team.\nWhat you'll need to thrive\nExcellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.\nA reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.\nCommitment to working a standard schedule of 8:00 AM-5:00 PM U.S. Eastern Time (ET) to effectively collaborate with team members, stakeholders, and cross-functional partners while ensuring timely communication and support.\nWillingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.\nHiring and Selection Process\nCandidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.\nEmployment is contingent upon successful completion of identity verification and background screening, where permitted by law.\nSelected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.\nCandidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.\nWorkstreet Is An Equal Opportunity Employer\nAs an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.","description_format":"text","description_chars":8947,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"Upper-Intermediate (B2)","optional":false}]},"benefits":["Home office"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","Cybersecurity","Information Security","Security Compliance"],"lifecycle":[{"event":"open","at":"2026-09-25T22:40:28Z"}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":6,"expected_fill_days":35,"reasons":["conf:6","stale_co","velocity","win:early"],"computed_at":"2026-10-02T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/workstreet-senior-grc-engineer-3","json_url":"https://alion.io/job/workstreet-senior-grc-engineer-3.json","meta":{"generated_at":"2026-10-03T01:08:21Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":985,"day_limit":5000,"remaining_today":4015,"minute_limit":60,"resets_at":"2026-10-04T00:00:00Z"}}}