Remote
GRC Engineer I (Special Programs)
About this role
Get to know the Special Programs Team The Special Programs team delivers high-impact, fast-paced services that help organizations accelerate their compliance journey. Unlike our standard offerings, Special Programs are purpose-built engagements designed to solve specific customer challenges, from establishing a compliance foundation in 30 days to migrating organizations onto new GRC platforms, supporting audits, and delivering other specialized compliance services.
For many customers, Special Programs represent their first experience working with Workstreet. Because of that, we are laser-focused on speed, quality, and an exceptional customer experience that builds trust from day one. We support hundreds of organizations, from early-stage startups to global enterprises, across nearly every industry. The Opportunity Workstreet is seeking a highly motivated, client-focused GRC Engineer to join our fast-growing team.
Built around client relationship excellence, this role focuses on delivering exceptional client experiences, cultivating trust, and driving program outcomes while managing accounts and overseeing a pod of analysts across frameworks such as SOC 2, ISO 27001, and NIST CSF. The successful candidate will integrate quickly into the organization and manage active client accounts within their first 15 days. You will serve as the dedicated primary point of contact for a portfolio of accounts, guiding engagements end-to-end, resolving escalations with composure and urgency, and ensuring every client interaction reflects the highest standard of service.
What you'll do Execute end-to-end client compliance initiatives - assist in implementing and maintaining client security compliance programs aligned with SOC 2, ISO 27001, and regulatory standards. Maintain policy and evidence repositories - author and update corporate security policies, standard operating procedures, and control evidence to support formal audits and assessments. Identify and mitigate technical risks - partner with cross-functional technical teams to track, evaluate, and remediate cybersecurity risks and control gaps.
Manage project deliverables and timelines - track compliance milestones, evidence gathering, and task execution across concurrent client engagements under senior guidance. Drive direct client communications - engage directly with client stakeholders via email, chat, and video calls to gather evidence, clarify control requirements, and share updates. Perform control testing and readiness reviews - conduct structured control evaluations and readiness checks to maintain continuous compliance alignment.