← Back to results

Security GRC Engineer

Design and implement a governance, risk, and compliance program while ensuring security standards are met.

Location
San Francisco, United States
Compensation
Not disclosed
Level
Not specified
Type
full time · On-site

Posted by employer 12 hours ago

First seen on Joblaze 7 hours ago

Last verified on the company career page 7 hours ago

What you'll build

  • Automate evidence gathering and continuous control testing
  • Own the relationship with audit firms and customers
  • Conduct security compliance reviews for new products
  • Support Legal in contract negotiations
  • Build self-serve documentation and tools

Must have

  • Experience with GRC frameworks such as SOC 2, ISO 27001, ISO 42001, and AIUC-1
  • Strong cross-functional collaboration skills

Not disclosed in this posting: compensation, seniority, years of experience, visa sponsorship.

Joblaze summary

In the role of Security GRC Engineer, the individual is responsible for designing and implementing a governance, risk, and compliance program while automating compliance workflows and developing self-serve tools for teams. Key skills include familiarity with GRC frameworks like SOC 2 and ISO standards, along with a strong ability to collaborate across various departments. This position is well-suited for someone with a technical background who can bridge the gap between compliance and engineering. The company culture emphasizes a flat structure and values creativity and open debate.

Joblaze insights

  • Listed today — first seen on Joblaze September 23, 2026. Last confirmed on Cursor's careers page September 23, 2026.
  • SOC 2 appears in 6.3% of 783 comparable security roles in United States; ISO 42001 appears in 0.3% of 783 comparable security roles in United States.

Quick facts

Is the Security GRC Engineer role remote?
No — this is an on-site role in San Francisco, United States.
Where is the role based?
Cursor is hiring for this position in San Francisco, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: AIUC-1, GRC, ISO 27001, ISO 42001, SOC 2.
Is this full-time or contract?
Full-time for this Security GRC Engineer role at Cursor.

From the original posting

About the Role

Security GRC Engineers design, implement, and scale our governance, risk, and compliance (GRC) program. You'll lead automation of compliance workflows, build self-serve tools to enable GTM teams, and ensure our products and infrastructure meet the highest security standards. This role blends technical implementation with strategic program development, directly shaping how we build trust with customers.

You may be a fit if

  • You have experience with GRC frameworks such as SOC 2, ISO 27001, ISO 42001, and AIUC-1.

  • You're comfortable tracing an external claim back to how the product and infrastructure are actually configured — you use coding agents and curiosity to confirm that what we say is what we do, flag issues that affect the security and AI governance program, and drive them to the right outcome.

  • You have strong cross-functional collaboration skills, especially with Engineering, Legal, GTM, Trust & Safety, auditors, and regulators.

Sample projects include

  • Automate evidence gathering and continuous control testing.

  • Own the relationship with audit firms and customers — you're the person who explains the security and AI governance program and earns their trust in it.

  • Conduct security compliance reviews for new products, features, and vendors.

  • Support Legal in contract negotiations with timely, accurate guidance on security and AI governance terms.

  • Support incident response communications — draft and review customer-facing updates during security incidents.

  • Build self-serve documentation and tools to answer customer security and AI governance inquiries.

  • Maintain corporate security policies.

Applying

If there appears to be a fit, we'll reach out to schedule 2–3 short technicals. After that, we'll schedule an onsite at our office, where you'll work on a small project, discuss ideas, and meet the team.

Standard company text repeated across Cursor's postings is omitted here.

Similar positions

Profound
Member of Technical Staff, GRC Director
Profound · New York, New York
HappyRobot
GRC Compliance Specialist
HappyRobot · Spain
Fireworks AI
GRC Analyst
Fireworks AI · San Mateo
Fireworks AI
Senior GRC Specialist
Fireworks AI · San Mateo
Gamma
Security Engineer
Gamma · San Francisco