Workstreet

Senior GRC Engineer – Government

Workstreet

full-time

Posted on:

Origin:  • 🇺🇸 United States

Visit company website
AI Apply
Apply

Job Level

Senior

Tech Stack

AWSAzureCyber Security

About the role

  • Analyze and interpret CMMC requirements and NIST SP 800-171 controls to ensure client compliance with Department of Defense cybersecurity standards.
  • Develop, implement, and maintain System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and other CMMC-required documentation.
  • Conduct gap assessments and readiness reviews for organizations pursuing CMMC certification.
  • Collaborate with defense contractors to identify and remediate gaps in their cybersecurity programs to meet CMMC Level 1 and Level 2 requirements.
  • Guide clients through the CMMC assessment process and coordinate with Certified Third-Party Assessment Organizations (C3PAOs).
  • Manage and coordinate multiple CMMC compliance projects across various defense contractors, ensuring timely completion before contract deadlines.
  • Lead and mentor a small team of compliance professionals to effectively deliver on CMMC objectives.
  • Stay current with evolving CMMC requirements, CMMC 2.0 rulemaking, and DoD cybersecurity policies.

Requirements

  • Strong organizational skills with the ability to manage multiple CMMC compliance projects concurrently.
  • 5+ years of experience in defense contractor compliance, CMMC, NIST 800-171, NIST 800-53, or FedRAMP implementation.
  • 3+ years of leadership experience managing or guiding a small team.
  • Deep understanding of CUI handling requirements and DFARS clauses (252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021).
  • Experience with NIST SP 800-171 control implementation and assessment.
  • Familiarity with DoD supply chain requirements and defense contractor workflows.
  • Experience working with small to mid-sized defense contractors.
  • Knowledge of common GCC High, Azure Government, or AWS GovCloud environments.
  • Experience thriving in a fast-paced startup environment.
  • CMMC Registered Practitioner (RP), CMMC Certified Professional (CCP), or CMMC Certified Assessor (CCA) certification (preferred).
  • Security+ or CISSP certification (preferred).
  • Experience with SPRS reporting and maintaining scores of 110 (preferred).
  • Familiarity with ITAR compliance requirements (preferred).
  • Ability to obtain U.S public trust security clearance (preferred).
  • Previous experience working directly with C3PAOs or as part of assessment teams (preferred).
  • Must be a US citizen or permanent resident (due to potential access to CUI).
  • Must be located in the United States.
  • Ability to obtain security clearance if required by client engagements.
  • Available for occasional travel to client sites within the US (estimated 10-20%).
IBM

Cybersecurity Certification and Accreditation Analyst

IBM
Mid · Seniorfull-time$130k–$150k / yearVirginia · 🇺🇸 United States
Posted: 2 days agoSource: recruiting.paylocity.com
AWSCloudCyber SecurityJavaScript
Inbox Business Technologies

Cyber Security Manager, Pre-Sales

Inbox Business Technologies
Senior · Leadfull-time🇸🇦 Saudi Arabia
Posted: 11 hours agoSource: apply.workable.com
AWSCloudCyber Security
GuidePoint Security

Manager, Corporate Governance, Risk, and Compliance (GRC)- Remote (Anywhere in the U.S.)

GuidePoint Security
Mid · Seniorfull-time🇺🇸 United States
Posted: 37 days agoSource: boards.greenhouse.io
Cyber Security
NOVA Corporation

Program Manager

NOVA Corporation
Senior · Leadfull-timeMassachusetts · 🇺🇸 United States
Posted: 4 days agoSource: ddc-dine-careers.icims.com
Cyber SecurityLinux
RTX

Procurement Manager, Hybrid

RTX
Mid · Seniorfull-time$90k–$182k / yearCalifornia · 🇺🇸 United States
Posted: 36 days agoSource: globalhr.wd5.myworkdayjobs.com
Cyber Security