Get to know the GRC Engineering Team
Our GRC Engineering team is the primary point of contact for Workstreet's clients. We bring deep framework compliance knowledge and program management to each engagement to ensure our clients' compliance goals are met. Our teammates are trusted advisors not only in the compliance space, but also operationally in the role of vCISO. We deliver quickly using common templates and methodologies and are adept at creative problem-solving. GRC Engineering Team members also listen for and act as a centralized resource to advise clients on Workstreet's other service offerings to support their compliance, privacy, and information security goals.
The Opportunity
Workstreet is seeking a highly motivated, detail-oriented Bilingual Senior GRC Engineer to join our fast-growing team. Acting as a trusted compliance advisor, this role focuses on delivering exceptional client experiences, cultivating trust across complex accounts, and leading successful program outcomes. In this capacity, you will oversee and mentor a team of junior analysts while applying deep technical expertise across frameworks such as SOC 2, ISO 27001, HIPAA, and NIST CSF.
The successful candidate will integrate quickly into the organization, assuming active account ownership and managing client engagements within their first 15 days. Serving as a high-touch, bilingual strategic interface for English and Spanish-speaking client accounts, you will lead end-to-end compliance initiatives, resolve complex escalations with composure, and ensure every partner remains deeply engaged, highly satisfied, and retained long term during U.S. Eastern Time business hours.
What You'll Do
- Own primary client relationship management - act as the dedicated primary contact for high-complexity client accounts, building strong executive relationships and delivering clear milestone updates.
- Lead bilingual client engagements - engage directly with U.S. and international client teams via phone, email, and video calls in English and Spanish to address compliance concerns and provide expert guidance.
- Execute multi-framework compliance architectures - analyze, interpret, and implement technical security requirements aligned with SOC 2, ISO 27001, HIPAA, and NIST CSF.
- Direct and develop analyst pods - provide day-to-day operational leadership, constructive feedback, and mentorship to junior analysts to foster high performance and delivery quality.
- Author and maintain compliance documentation - design, implement, and maintain enterprise security policies, standard operating procedures, and audit evidence artifacts.
- Manage complex account escalations - resolve difficult client challenges swiftly and professionally, utilizing solution-oriented communication to protect client retention.
- Collaborate on risk and gap remediation - partner with internal and client technical teams to identify, assess, track, and mitigate security risks and control deficiencies.
- Drive operational process improvement - continuously refine internal playbooks, standard operating procedures, and delivery frameworks to strengthen organizational efficiency.
Who You Are
- Experienced client relationship lead - proven track record of owning high-complexity accounts, leading client meetings, and serving as the primary face of technical engagements.
- Fluent bilingual communicator - possess professional fluency in written and verbal English and Spanish, with the ability to communicate technical concepts clearly in both languages.
- Proven pod team leader - bring 3+ years of leadership experience managing, mentoring, or guiding small teams of compliance analysts.
- Technical GRC engineer - bring direct experience executing cybersecurity compliance programs across SOC 2, ISO 27001, or NIST CSF frameworks.
- Concurrent project operator - highly organized practitioner with the ability to manage multiple complex compliance projects simultaneously without compromising quality.
- Policy framework practitioner - skilled at authoring, implementing, and enforcing corporate security policies within tech-focused or cybersecurity organizations.
- High-velocity startup operator - thrives in fast-paced startup environments, demonstrating high initiative, adaptability, and an eagerness to take direct task ownership.
What will help you succeed
- Big 4 advisory background - experience conducting assurance, risk, or technical advisory services within Big 4 or top-tier consulting firms.
- Expanded framework versatility - practical exposure to HIPAA, PCI DSS, or complementary regulatory compliance frameworks.
- Automated GRC platform mastery - hands-on proficiency leveraging compliance automation solutions such as Vanta, Drata, or similar tools.
- Active industry credentials - holder of recognized certifications such as CISA, CISSP, ISO 27001 Lead Implementer, or Security+.
What We Offer
- Career Development: Clear growth path with mentorship and training opportunities
- Technical Training: Comprehensive onboarding on security and compliance frameworks
- Competitive Compensation: Competitive base salary with regular performance reviews, merit-based appraisals, and bonus opportunities
- Growth Opportunity: Early-stage company with significant room for career advancement
- Remote-First Culture: Flexibility to work from anywhere while collaborating with a global team
What You'll Need to Thrive
- Excellent written and verbal English communication skills, with the ability to engage confidently with candidates, hiring managers, and business leaders across global teams.
- A reliable, high-speed internet connection and a professional home office environment that supports confidential conversations, virtual interviews, and uninterrupted collaboration.
- Commitment to working a standard schedule of 8:00 AM–5:00 PM US Eastern Time (ET) to effectively support hiring managers, candidates, and cross-functional teams. Occasional flexibility to adjust working hours is expected to accommodate changing business priorities, global collaboration, and time-sensitive hiring needs.
- Willingness and ability to travel locally for occasional onsite meetings, team gatherings, or business activities as needed.
Hiring and Selection Process
- Candidates must participate in live video interviews throughout the hiring process with camera on (non-negotiable) and be prepared to verify their identity during recruitment and onboarding.
- Employment is contingent upon successful completion of identity verification and background screening, where permitted by law.
- Selected candidates will participate in structured interviews with hiring managers and cross-functional stakeholders to assess role fit, experience, and alignment with Workstreet’s operating principles.
- Candidates will receive prompt updates and consistent communication throughout the interview process, ensuring a transparent, smooth, and engaging experience at every step.
Workstreet Is An Equal Opportunity Employer
As an equal opportunity employer, Workstreet is committed to providing employment opportunities to all individuals. All applicants for positions at Workstreet will be treated without regard to race, color, ethnicity, religion, sex, gender, gender identity and expression, sexual orientation, national origin, disability, age, marital status, veteran status, pregnancy, or any other basis prohibited by applicable law.