← Back to results

GRC Engineer

Join Cape as a GRC Engineer to enhance governance, risk, and compliance in a privacy-first mobile carrier.

Location
Washington DC, United States
Compensation
$155k–$185k/yr
Level
mid
Type
full time · Hybrid

Posted by employer 1 day ago

First seen on Joblaze 10 hours ago

Last verified on the company career page 10 hours ago

Apply at Cape → Save job Scanned from cape.co

What you'll build

  • Design automated systems for continuous controls monitoring
  • Own compliance programs end-to-end
  • Provide subject matter expertise in risk assessment
  • Collaborate with Security and Engineering
  • Support customers through security questionnaires

Must have

  • 3+ years in GRC engineering or compliance
  • Expertise in compliance frameworks
  • Track record of designing risk programs
  • Strong prioritization and project management skills
  • Clear communication style

Nice to have

  • Proficiency in scripting or programming languages
  • Experience with compliance automation tooling
  • Knowledge of cloud platforms and security tooling

Requirements

Experience
3+ years
Education
Bachelor's degree

Not disclosed in this posting: visa sponsorship.

Benefits

401k Match Unlimited PTO Equity/Stock Options Health Insurance Parental Leave

Joblaze summary

The GRC Engineer at Cape plays a crucial role in enhancing the governance, risk, and compliance framework essential for the company's security and trustworthiness. This position requires expertise in compliance frameworks like SOC 2 and CMMC, along with technical skills to automate controls and policies across cloud infrastructures. Ideal candidates will have a background in GRC engineering or security, preferably within a startup environment, and should be adept at collaborating with engineering teams to drive risk management initiatives. Cape's flat organizational structure fosters collaboration, making it a fitting environment for innovative problem solvers.

Joblaze insights

  • Listed today — first seen on Joblaze October 11, 2026. Last confirmed on Cape's careers page October 11, 2026.
  • Salary band is in line with the typical range for Security roles (median ~$170,000).
  • Starts above 65% of 55 comparable mid security roles in United States that list Python we track (median $130,000 across 22 companies). See Python salary trends
  • Python appears in 43% of 200 comparable mid security roles in United States; CMMC appears in 3% of 200 comparable mid security roles in United States.

Quick facts

Is the GRC Engineer role remote?
It's hybrid — Cape expects some on-site time in Washington DC, United States.
What's the salary range?
Cape lists $155,000–$185,000 for this role.
How much experience is required?
At least 3 years of relevant experience for this GRC Engineer role.
Where is the role based?
Cape is hiring for this position in Washington DC, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Azure, CMMC, GCP, Go, Python.
What seniority level is this role?
Cape targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this GRC Engineer role at Cape.

From the original posting

The Role:

We are looking for a GRC Engineer to help grow the governance, risk, and compliance function that keeps Cape secure, trustworthy, and audit-ready as we scale. You will sit at the intersection of security, engineering, and compliance — translating regulatory and contractual requirements into automated controls, clear policies, and pragmatic engineering solutions. You are equally comfortable writing a policy as you are writing a script to enforce it. As a steward of Cape culture, you will partner with engineering and security leaders to identify and remediate risk, run our compliance programs (SOC 2, CMMC, and beyond), and support customers through security due diligence. You put people and data first and always use evidence to drive decisions. You'll join an existing GRC function and are passionate about building on its foundation, sharpening our automation, and helping it scale with the business. This role reports to our Head of Security.

What You'll Work On:

  • Design, build, and maintain automated systems for continuous controls monitoring across our cloud infrastructure (AWS/GCP/Azure), CI/CD, and SaaS stack.

  • Own and mature our compliance programs end-to-end (SOC 2 Type II, CMMC, and future frameworks as they arise), including audit prep, evidence collection, and remediation tracking.

  • Provide subject matter expertise in: risk assessment, controls design, security policy, vendor/third-party risk, access review automation, and audit management.

  • Proactively assess technical and organizational risk, make data-driven recommendations, and implement scalable solutions rather than one-off manual fixes.

  • Roll up your sleeves to execute a full range of GRC duties — from writing policy to shipping the automation that enforces it.

  • Collaborate closely with Security and Engineering to implement solutions across risk management, policy, and compliance tooling.

  • Ensure successful rollout of key GRC programs such as risk registers, access reviews, vendor risk assessments, and audit cycles.

  • Lead and contribute to projects as an integral member of the Security team.

  • Support customers and prospects through security questionnaires, due diligence requests, and trust-building conversations, and build tooling to make that process faster.

Experience:

  • 3+ years in GRC engineering, security engineering, or compliance with hands-on technical work; startup experience preferred.

  • Demonstrable expertise across compliance frameworks (SOC 2, CMMC, FedRAMP, NIST CSF, GDPR), including how regulatory and contractual requirements translate into technical controls and day-to-day engineering decisions.

  • Successful track record of designing and implementing risk or compliance programs, with processes that are clear and auditable but adapt as the business and regulatory landscape change.

  • Strong prioritization and project management skills, especially when running audits against real deadlines.

  • Experience partnering with and influencing engineering and security leaders to drive risk decisions and audit outcomes; you build trust easily with both engineers and auditors.

  • A clear communication style, and the ability to translate technical risk into business terms for different audiences.

  • Ability to see all sides of a risk tradeoff, remain objective, and drive issues to resolution — including through ambiguity, with a willingness to roll up your sleeves.

  • BA / BS in a related field or equivalent practical experience; relevant security or audit certifications (CISSP, CISA, CRISC, or similar) a plus.

  • (Bonus) Proficiency in at least one scripting or programming language (Python, Go, TypeScript) to automate evidence collection, monitoring, and reporting.

  • (Bonus) Experience standing up a GRC program or compliance automation tooling (Vanta, Drata, Secureframe, OneTrust) from scratch, and working knowledge of cloud platforms (AWS, GCP, Azure) and their native security and logging tooling.

Compensation

We offer competitive compensation that is geo-adjusted based on your location, along with meaningful equity so you share in the value you help create. Salary range for this role in New York, NY or Arlington, VA is $155,000 - $185,000 depending on experience and interview performance and location.

Our benefits include:

  • 401(k) match

  • Stipends for

    • Family-forming needs

    • Gender-affirming care

  • Unlimited PTO

Our Culture & Values

  • We hire excellent people, give them outsized responsibility, and trust them to execute. Every person at Cape has a proven track record of tackling hard problems and winning.

How to apply

Click the link below to apply.

Standard company text repeated across Cape's postings is omitted here.

Similar positions

Cape
Head of Government Relations
Cape · Arlington, VA
Cape
Cape
Cape
Cape