GRC Engineer – NIST

Job not on LinkedIn

🔥 4 minutes ago

🇺🇸 United States – Remote

⏰ Full Time

🟢 Junior

🟡 Mid-level

🚔 Compliance

🚫👨‍🎓 No degree required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Workstreet

Workstreet

11 - 50 employees

Founded 2023

🔒 Cybersecurity

📋 Compliance

🤝 B2B

Cybersecurity • Compliance • B2B

Workstreet is a managed security and compliance services provider that helps businesses automate and modernize their security programs. With expertise in compliance frameworks including SOC 2, ISO 27001, HIPAA, and GDPR, Workstreet supports companies in achieving their security and compliance outcomes efficiently. Their services include acting as a virtual Chief Information Security Officer (vCISO), full-scale penetration testing, and vendor risk management, aiming to streamline security processes while allowing businesses to focus on growth.

📋 Description

• Execute NIST 800-53 control mappings and apply security and privacy controls and baselines to software architectures • Create, update, and maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and supporting authorization artifacts • Conduct technical gap analyses and readiness reviews for federal agency ATO or FedRAMP authorization paths • Support continuous monitoring cycles by tracking monthly vulnerability logs, POA&M updates, and structural change requests • Guide clients through the Assessment and Authorization (A&A) process • Coordinate operational logistics with 3PAOs and independent assessors • Partner with internal and client technical teams to remediate control deficiencies across Low, Moderate, and High baselines • Document technical security boundaries, interconnectivity agreements, and shared responsibility profiles across cloud environments • Track evolving NIST SP 800-53 revisions, FedRAMP requirements, and federal policy updates • Partner directly with organizations pursuing federal authorizations • Manage multiple compliance projects concurrently under senior guidance • Collaborate with global teams during U.S. Eastern Time business hours

🎯 Requirements

• 2+ years of direct experience executing GRC deliverables across NIST SP 800-53, FedRAMP, or NIST Risk Management Framework (RMF) lifecycles • Hands-on experience creating, evaluating, and maintaining System Security Plans (SSPs), POA&Ms, and technical security narratives • Ability to manage multiple federal compliance project tasks simultaneously while maintaining attention to detail • Familiarity with cloud service providers and secure configurations in government clouds such as AWS GovCloud or Azure Government • Strong written and verbal English communication skills • Foundational knowledge of NIST SP 800-53 and FedRAMP Moderate and High baseline requirements • Recognized professional designation such as CGRC, CAP, CISSP, or CompTIA Security+ (helpful) • Practical experience supporting live agency Authority to Operate (ATO) certifications or working alongside 3PAO assessment teams (helpful) • Familiarity with automated or manual FedRAMP Continuous Monitoring (ConMon) workflows (helpful) • Exposure to CMMC 2.0 or NIST SP 800-171 baselines (helpful) • Reliable, high-speed internet connection • Professional home office environment supporting confidential conversations and uninterrupted collaboration • Availability for a standard schedule of 8:00 AM–5:00 PM US Eastern Time • Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities • Must participate in live video interviews with camera on and verify identity during recruitment and onboarding • Employment contingent upon identity verification and background screening, where permitted by law • Must be authorized to work in the U.S. without current or future visa sponsorship

🏖️ Benefits

• Career development with mentorship and training opportunities • Reimbursement for approved role-related training and certification courses • Competitive base salary • Regular performance reviews linked to merit-based appraisals • Bonus opportunities • Significant room for career advancement • Remote-first culture with flexibility to work from anywhere • Collaboration with a global team

Apply Now

Similar Jobs

🔥 4 hours ago

HealthEdge

1001 - 5000

🏥 Healthcare

💼 Consulting

⚕️ Healthcare Insurance

Compliance Manager integrating HealthEdge’s privacy and compliance operations. Governing risk, controls, reporting, documentation, and cross-functional accountability across a healthcare technology organization.

🔥 4 hours ago

McKesson

10,000+ employees

💼 Consulting

📦 Logistics

🏥 Healthcare

Regulatory Affairs Specialist I managing oncology clinical-trial compliance and IRB documentation for SCRI, a cancer research organization. Fully remote across the United States.

🔥 4 hours ago

Centene Corporation

10,000+ employees

🛡️ Insurance

💼 Consulting

🏥 Healthcare

Compliance Oversight Specialist monitoring WellCare’s managed-care contracts and regulatory programs for Centene, a healthcare solutions provider. Conducting audits, risk assessments, remediation, and corrective-action follow-up across markets and delegated subcontractors.

🔥 6 hours ago

Stride, Inc.

5001 - 10000

💼 Consulting

🏥 Healthcare

📚 Education

Special Education Compliance Specialist providing individualized online instruction and IEP compliance for Texas Virtual Academy. Supporting students, families, and learning coaches through virtual teaching, documentation, and data-driven interventions.

🔥 9 hours ago

Precision For Medicine

1001 - 5000

🏥 Healthcare

💼 Consulting

📦 Logistics

Regulatory Manager guiding clinical-trial submissions for Precision for Medicine. Advising project teams on regulatory strategy, compliance, and drug-development approvals.

🇺🇸 United States – Remote

💵 $106k - $151k / year

💰 $75M Private Equity Round on 2015-12

⏰ Full Time

🟡 Mid-level

🟠 Senior

🚔 Compliance