GRC Engineer, CMMC

🔥 0 minutes ago

🇺🇸 United States – Remote

⏰ Full Time

🟢 Junior

🟡 Mid-level

🚔 Compliance

🚫👨‍🎓 No degree required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Workstreet

Workstreet

11 - 50 employees

Founded 2023

🔒 Cybersecurity

📋 Compliance

🤝 B2B

Cybersecurity • Compliance • B2B

Workstreet is a managed security and compliance services provider that helps businesses automate and modernize their security programs. With expertise in compliance frameworks including SOC 2, ISO 27001, HIPAA, and GDPR, Workstreet supports companies in achieving their security and compliance outcomes efficiently. Their services include acting as a virtual Chief Information Security Officer (vCISO), full-scale penetration testing, and vendor risk management, aiming to streamline security processes while allowing businesses to focus on growth.

📋 Description

• Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to align client software architectures with federal agency requirements • Author and update System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, and SARs • Perform readiness assessments and gap analyses for JAB or Agency ATO validation paths • Architect technical authorization boundaries and scoping profiles across FedRAMP and CMMC environments • Map data flows, interconnectivity, and shared responsibility models • Execute continuous monitoring cycles, tracking vulnerability management logs, incident response reports, and change-control workflows • Coordinate external assessment pipelines among clients, Cloud Service Providers, 3PAOs, and federal stakeholders • Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 controls • Translate regulatory language into practical security milestones • Formulate compliance documentation required for CMMC Level 1 and Level 2 assessment readiness • Guide SaaS providers and federal contractors through FedRAMP readiness, authorization support, and continuous monitoring • Lead high-quality delivery across multiple client engagements

🎯 Requirements

• 2+ years of direct execution in GRC roles with active exposure driving FedRAMP, NIST SP 800-53, and federal authorization lifecycles • Hands-on experience authoring, evaluating, and maintaining System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms) • Grounded knowledge of CMMC 2.0 and NIST SP 800-171 baselines as applied to defense contractors and supply chain data • Familiarity with shared responsibility models, operational constraints, and secure configurations of AWS GovCloud, Azure Government, or Microsoft GCC High • Strong project management skills supporting multiple simultaneous client compliance initiatives • Experience partnering with B2B SaaS providers, federal contractors, or regulated technology companies • Experience in fluid consulting or fast-growth startup environments • Excellent written and verbal English communication skills • Reliable, high-speed internet connection and professional home office environment supporting confidential conversations and uninterrupted collaboration • Availability to work 8:00 AM–5:00 PM US Eastern Time, with occasional flexibility • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities • Must participate in live video interviews with camera on and verify identity during recruitment and onboarding • Successful identity verification and background screening, where permitted by law • Must be authorized to work in the U.S. without current or future visa sponsorship • Direct JAB or Agency ATO execution experience • CMMC Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA) designation • Active CISSP, CISM, or CompTIA Security+ certification • Strong knowledge of CUI protections, DFARS regulatory clauses, and SPRS submission workflows • Prior experience working directly with 3PAO or C3PAO assessment teams

🏖️ Benefits

• Clear path with mentorship and training opportunities • Reimbursement for successful completion of approved training and certification courses relevant to the current role • Competitive base salary with regular performance reviews linked to merit-based appraisals and bonus opportunities • Significant room for career advancement • Remote-first culture and flexibility to work from anywhere while collaborating with a global team

Apply Now

Similar Jobs

🔥 4 hours ago

HealthEdge

1001 - 5000

🏥 Healthcare

💼 Consulting

⚕️ Healthcare Insurance

Compliance Manager integrating HealthEdge’s privacy and compliance operations. Governing risk, controls, reporting, documentation, and cross-functional accountability across a healthcare technology organization.

🔥 4 hours ago

McKesson

10,000+ employees

💼 Consulting

📦 Logistics

🏥 Healthcare

Regulatory Affairs Specialist I managing oncology clinical-trial compliance and IRB documentation for SCRI, a cancer research organization. Fully remote across the United States.

🔥 4 hours ago

Centene Corporation

10,000+ employees

🛡️ Insurance

💼 Consulting

🏥 Healthcare

Compliance Oversight Specialist monitoring WellCare’s managed-care contracts and regulatory programs for Centene, a healthcare solutions provider. Conducting audits, risk assessments, remediation, and corrective-action follow-up across markets and delegated subcontractors.

🔥 6 hours ago

Stride, Inc.

5001 - 10000

💼 Consulting

🏥 Healthcare

📚 Education

Special Education Compliance Specialist providing individualized online instruction and IEP compliance for Texas Virtual Academy. Supporting students, families, and learning coaches through virtual teaching, documentation, and data-driven interventions.

🔥 9 hours ago

Precision For Medicine

1001 - 5000

🏥 Healthcare

💼 Consulting

📦 Logistics

Regulatory Manager guiding clinical-trial submissions for Precision for Medicine. Advising project teams on regulatory strategy, compliance, and drug-development approvals.

🇺🇸 United States – Remote

💵 $106k - $151k / year

💰 $75M Private Equity Round on 2015-12

⏰ Full Time

🟡 Mid-level

🟠 Senior

🚔 Compliance