JobBobsReal-time global job discoveryLive

Senior Manager, GRC Engineering

Workstreet · United States · 2026-08-03

managerRemote
Apply on the employer's site

About this role

About Workstreet At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one. Get to know the GRC Engineering Team Our GRC Engineering team is the primary point of contact for Workstreet's clients. We bring deep framework compliance knowledge and program management to each engagement to ensure our clients' compliance goals are met. Our teammates are trusted advisors not only in the compliance space, but also operationally in the role of vCISO. We deliver quickly using common templates and methodologies and are adept at creative problem-solving. GRC Engineering Team members also listen for and act as a centralized resource to advise clients on Workstreet's other service offerings to support their compliance, privacy, and information security goals. The Opportunity We are seeking a Senior Manager, GRC Engineering who leads with a client-first philosophy and brings a proven track record of managing high-stakes client relationships with professionalism, care, and strategic insight. The ideal candidate is an experienced client relationship leader who understands that exceptional service is the foundation of everything we do — and who pairs that client focus with 8+ years of deep expertise in cybersecurity compliance frameworks such as SOC 2, ISO 27001, and NIST CSF. The successful candidate will be able to come up to speed quickly, integrate into the organization, and take on clients within your first 15 days. You will serve as the primary point of contact for a portfolio of clients, leading engagements end-to-end, managing escalations with composure and urgency, and ensuring every client interaction reflects the highest standard of service. What You'll Do

Own executive-level client relationships as the senior strategic point of contact for a high-priority portfolio, building deep trust, driving retention, and resolving high-stakes client escalations with absolute composure and urgency.

Provide overarching program governance across multiple compliance engagements, ensuring tech-sector clients remain fully prepared, informed, and calibrated throughout complex audits and certification lifecycles.

Supervise, mentor, and upscale a high-performing team of subordinate managers and GRC analysts, embedding a performance-driven culture focused on strict operational accountability and clear professional growth.

Drive departmental resource and capacity strategy, directing hiring, target profiles, and optimized workload allocation models to seamlessly support the business as it scales.

Establish and enforce rigorous quality benchmarks across the delivery team, verifying that every piece of technical documentation and client communication reflects the highest standard of execution.

Engage directly with US-based client executives and technology founders, executing proactive multi-channel communications to dismantle complex compliance roadblocks and provide tailored risk advisory.

Develop, execute, and maintain enterprise-grade security policies and procedures, translating dense global regulations (including SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, HiTRUST, and NIST/CMMC) into scalable, operational controls.

Partner cross-functionally with internal and external teams to systematically isolate, evaluate, and remediate technical cybersecurity risks and framework deficiencies.

Who You Are

Executive portfolio commander - Command high-complexity client engagements, dismantle high-stakes structural escalations at the leadership tier, and confidently influence senior C-suite stakeholders to preserve long-term loyalty.

Elite corporate communicator - Assert flawless, authoritative written and verbal English communication capable of effortlessly translating dense technical risk data into clear business value for diverse audiences.

Scale-oriented enterprise people leader - Bring 5+ years of dedicated experience leading, upskilling, and managing mid-sized technical or professional services teams, explicitly demonstrating the capability to lead through subordinate people managers.

Cybersecurity compliance authority - Command 8+ years of direct, hands-on execution designing, implementing, and defending mature compliance programs across global frameworks (including SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, HiTRUST, and NIST/CMMC).

Policy governance architect - Bring 8+ years of experience engineering and enforcing technical security policies that seamlessly align rigorous regulatory mandates with fluid business growth objectives.

High-velocity startup operator - Thrive within volatile, fast-growth technology ecosystems, possessing the immediate operational agility to fully integrate into an organization and absorb strategic client accounts within your first 15 days.

Disciplined program navigator - Command macro-level organization and program management mechanics to oversee multiple concurrent compliance engagements simultaneously without degrading delivery quality or missing deadlines.

Domain-native technology strategist - Verifiable tenure operating within cybersecurity-focused SaaS or technology corporations where security governance, risk assessment, and technical compliance serve as core business differentiators.

What will help you succeed

Big 4 advisory or assurance tenure - Prior success directing technical IT compliance audits, data governance assessments, or complex risk assurance workflows inside elite environments like Deloitte, PwC, EY, or KPMG.

GRC consultancy lifecycle execution - Direct history managing compliance engineering functions or vCISO delivery tracks within a high-volume managed…

Skills asked for

Similar jobs

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.