Join Cape as a GRC Engineer to enhance governance, risk, and compliance in a privacy-first mobile carrier.
Posted by employer 1 day ago
First seen on Joblaze 10 hours ago
Last verified on the company career page 10 hours ago
What you'll build
Must have
Nice to have
Requirements
Not disclosed in this posting: visa sponsorship.
Benefits
Joblaze summary
The GRC Engineer at Cape plays a crucial role in enhancing the governance, risk, and compliance framework essential for the company's security and trustworthiness. This position requires expertise in compliance frameworks like SOC 2 and CMMC, along with technical skills to automate controls and policies across cloud infrastructures. Ideal candidates will have a background in GRC engineering or security, preferably within a startup environment, and should be adept at collaborating with engineering teams to drive risk management initiatives. Cape's flat organizational structure fosters collaboration, making it a fitting environment for innovative problem solvers.
Joblaze insights
Quick facts
From the original posting
We are looking for a GRC Engineer to help grow the governance, risk, and compliance function that keeps Cape secure, trustworthy, and audit-ready as we scale. You will sit at the intersection of security, engineering, and compliance — translating regulatory and contractual requirements into automated controls, clear policies, and pragmatic engineering solutions. You are equally comfortable writing a policy as you are writing a script to enforce it. As a steward of Cape culture, you will partner with engineering and security leaders to identify and remediate risk, run our compliance programs (SOC 2, CMMC, and beyond), and support customers through security due diligence. You put people and data first and always use evidence to drive decisions. You'll join an existing GRC function and are passionate about building on its foundation, sharpening our automation, and helping it scale with the business. This role reports to our Head of Security.
Design, build, and maintain automated systems for continuous controls monitoring across our cloud infrastructure (AWS/GCP/Azure), CI/CD, and SaaS stack.
Own and mature our compliance programs end-to-end (SOC 2 Type II, CMMC, and future frameworks as they arise), including audit prep, evidence collection, and remediation tracking.
Provide subject matter expertise in: risk assessment, controls design, security policy, vendor/third-party risk, access review automation, and audit management.
Proactively assess technical and organizational risk, make data-driven recommendations, and implement scalable solutions rather than one-off manual fixes.
Roll up your sleeves to execute a full range of GRC duties — from writing policy to shipping the automation that enforces it.
Collaborate closely with Security and Engineering to implement solutions across risk management, policy, and compliance tooling.
Ensure successful rollout of key GRC programs such as risk registers, access reviews, vendor risk assessments, and audit cycles.
Lead and contribute to projects as an integral member of the Security team.
Support customers and prospects through security questionnaires, due diligence requests, and trust-building conversations, and build tooling to make that process faster.
3+ years in GRC engineering, security engineering, or compliance with hands-on technical work; startup experience preferred.
Demonstrable expertise across compliance frameworks (SOC 2, CMMC, FedRAMP, NIST CSF, GDPR), including how regulatory and contractual requirements translate into technical controls and day-to-day engineering decisions.
Successful track record of designing and implementing risk or compliance programs, with processes that are clear and auditable but adapt as the business and regulatory landscape change.
Strong prioritization and project management skills, especially when running audits against real deadlines.
Experience partnering with and influencing engineering and security leaders to drive risk decisions and audit outcomes; you build trust easily with both engineers and auditors.
A clear communication style, and the ability to translate technical risk into business terms for different audiences.
Ability to see all sides of a risk tradeoff, remain objective, and drive issues to resolution — including through ambiguity, with a willingness to roll up your sleeves.
BA / BS in a related field or equivalent practical experience; relevant security or audit certifications (CISSP, CISA, CRISC, or similar) a plus.
(Bonus) Proficiency in at least one scripting or programming language (Python, Go, TypeScript) to automate evidence collection, monitoring, and reporting.
(Bonus) Experience standing up a GRC program or compliance automation tooling (Vanta, Drata, Secureframe, OneTrust) from scratch, and working knowledge of cloud platforms (AWS, GCP, Azure) and their native security and logging tooling.
We offer competitive compensation that is geo-adjusted based on your location, along with meaningful equity so you share in the value you help create. Salary range for this role in New York, NY or Arlington, VA is $155,000 - $185,000 depending on experience and interview performance and location.
Our benefits include:
401(k) match
Stipends for
Family-forming needs
Gender-affirming care
Unlimited PTO
We hire excellent people, give them outsized responsibility, and trust them to execute. Every person at Cape has a proven track record of tackling hard problems and winning.
Click the link below to apply.
Standard company text repeated across Cape's postings is omitted here.