GRC Engineer (NIST)
WorkstreetAbout the role
About Workstreet
At Workstreet, we’re on an exciting journey to help businesses scale securely by designing and implementing cutting-edge security and compliance programs. As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and FedRAMP. We empower companies to meet regulatory requirements and enhance their cybersecurity posture from day one.
Get to know the GRC Engineering (GOV) Team
Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment & Authorization compliance efforts. We act as our clients' trusted guides and primary point of contact end-to-end, leading them through gap assessments, System Security Plans, POA&Ms, and C3PAO/3PAO coordination with clarity, composure, and a genuinely client-first mindset. Beyond the technical depth in RMF, CUI/DFARS requirements, and GovCloud environments, what defines us is how we work: we translate complex requirements into plain language, manage escalations with urgency and care, and take real pride in making every client feel informed, supported, and well-prepared. We're a group that mentors one another, holds a high bar for quality, and thrives in a fast-paced environment where our work directly strengthens the security of the defense industrial base.
The Opportunity
Workstreet is seeking a GRC Engineer (NIST 800-53/FedRAMP) who is highly motivated, detail-oriented, and possesses foundational knowledge of NIST SP 800-53 and FedRAMP Moderate and High baseline requirements. Operating as a key technical contributor within our government delivery practice, this role focuses on supporting client-facing compliance initiatives, authoring authorization artifacts, and executing gap assessments across the Assessment and Authorization (A&A) lifecycle.
The successful candidate will combine strong communication skills with the organizational discipline to manage multiple compliance projects concurrently under senior guidance. In this role, you will partner directly with organizations pursuing federal authorizations, assist with 3PAO assessment preparation, and help clients achieve and sustain compliance across government clouds during U.S. Eastern Time business hours.
What You'll Do
- Execute NIST 800-53 control mappings - analyze and apply NIST SP 800-53 security and privacy controls and control baselines to ensure software architectures meet federal agency standards.
- Author core authorization documentation - create, update, and maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and supporting A&A artifacts.
- Conduct readiness and gap assessments - perform technical gap analyses and readiness reviews to prepare clients for federal agency ATO or FedRAMP authorization validation paths.
- Support continuous monitoring operations - assist with continuous monitoring (ConMon) cycles by tracking monthly vulnerability logs, POA&M updates, and structural change requests.
- Facilitate external assessment activities - guide clients through the Assessment and Authorization (A&A) process and coordinate operational logistics with 3PAOs and independent assessors.
- Assist in control remediation efforts - partner with internal and client technical teams to remediate control deficiencies across Low, Moderate, and High baselines.
- Map authorization boundaries - help document technical security boundaries, interconnectivity agreements, and shared responsibility profiles across cloud environments.
- Track federal regulatory updates - stay current on evolving NIST SP 800-53 revisions, FedRAMP requirements, and federal policy updates to keep client programs aligned.
Who You Are
- Federal compliance practitioner - bring 2+ years of direct experience executing GRC deliverables across NIST SP 800-53, FedRAMP, or NIST Risk Management Framework (RMF) lifecycles.
- Federal artifact author - hands-on execution experience creating, evaluating, and maintaining System Security Plans (SSPs), POA&Ms, and technical security narratives.
- Multi-project GRC
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s