Skip to content

Open nowPosted 23 hours ago

GRC Engineer

Cape26 open roles

Where
Hybrid, DC
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowGRC EngineerCape · Hybrid, DC
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Cape's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. Cape postings stay open a median of 43 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.9%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.1%30 days
This job: posted 23 hours ago

Cape median: 43 days open

The posting

ABOUT CAPE

Cape is America’s privacy-first mobile carrier. Our mission is to be a force for good in global wireless. Cape was founded in 2022 by people who believe privacy is a fundamental right, not a luxury to be traded away. Our journey began when our founder recognized a critical vulnerability in our modern world: everyone relies on the same stagnant cellular infrastructure and legacy systems that track our every movement, monitor and profile our connections, and lose and sell our personal data.

Instead of accepting the status quo, we decided to fix it. National security professionals, journalists, parents, and everyone in between can stay connected and have privacy.

We didn’t just build a layer on top of old tech; we built America’s most private and secure mobile carrier from the ground up. By building our own network from scratch, we are able to design and build a suite of privacy and security features that no other carrier on the planet can offer.

Today, Cape provides our secure network to consumers, businesses, and government agencies alike. We closed our Series C in March 2026, and we are scaling rapidly, with the goal of giving people back control of their most personal information.

THE TEAM

At Cape, we are the architects of a privacy-centric movement that is just getting started. We are relentless builders, constantly innovating at the edge of what's possible in telecommunications. We operate on a foundation of high trust and high expectations. Our structure is flat, and collaboration matters more than hierarchy. As a member of our team, you will collaborate with world-class engineers, architects, and visionaries, and work across organizational lines to solve "impossible" problems and deliver mission-critical results for our users every single day.

THE ROLE:

We are looking for a GRC Engineer to help grow the governance, risk, and compliance function that keeps Cape secure, trustworthy, and audit-ready as we scale. You will sit at the intersection of security, engineering, and compliance — translating regulatory and contractual requirements into automated controls, clear policies, and pragmatic engineering solutions. You are equally comfortable writing a policy as you are writing a script to enforce it. As a steward of Cape culture, you will partner with engineering and security leaders to identify and remediate risk, run our compliance programs (SOC 2, CMMC, and beyond), and support customers through security due diligence. You put people and data first and always use evidence to drive decisions. You'll join an existing GRC function and are passionate about building on its foundation, sharpening our automation, and helping it scale with the business. This role reports to our Head of Security.

WHAT YOU'LL WORK ON:

- Design, build, and maintain automated systems for continuous controls monitoring across our cloud infrastructure (AWS/GCP/Azure), CI/CD, and SaaS stack.

- Own and mature our compliance programs end-to-end (SOC 2 Type II, CMMC, and future frameworks as they arise), including audit prep, evidence collection, and remediation tracking.

- Provide subject matter expertise in: risk assessment, controls design, security policy, vendor/third-party risk, access review automation, and audit management.

- Proactively assess technical and organizational risk, make data-driven recommendations, and implement scalable solutions rather than one-off manual fixes.

- Roll up your sleeves to execute a full range of GRC duties — from writing policy to shipping the automation that enforces it.

- Collaborate closely with Security and Engineering to implement solutions across risk management, policy, and compliance tooling.

- Ensure successful rollout of key GRC programs such as risk registers, access reviews, vendor risk assessments, and audit cycles.

- Lead and contribute to projects as an integral member of the Security team.

- Support customers and prospects through security questionnaires, due diligence requests, and trust-building conversations, and build tooling to make that process faster.

EXPERIENCE:

- 3+ years in GRC engineering, security engineering, or compliance with hands-on technical work; startup experience preferred.

- Demonstrable expertise across compliance frameworks (SOC 2, CMMC, FedRAMP, NIST CSF, GDPR), including how regulatory and contractual requirements translate into technical controls and day-to-day engineering decisions.

- Successful track record of designing and implementing risk or compliance programs, with processes that are clear and auditable but adapt as the business and regulatory landscape change.

- Strong prioritization and project management skills, especially when running audits against real deadlines.

- Experience partnering with and influencing engineering and security leaders to drive risk decisions and audit outcomes; you build trust easily with both engineers and auditors.

- A clear communication style, and the ability to translate technical risk into business terms for different audiences.

- Ability to see all sides of a risk tradeoff, remain objective, and drive issues to resolution — including through ambiguity, with a willingness to roll up your sleeves.

- BA / BS in a related field or equivalent practical experience; relevant security or audit certifications (CISSP, CISA, CRISC, or similar) a plus.

- (Bonus) Proficiency in at least one scripting or programming language (Python, Go, TypeScript) to automate evidence collection, monitoring, and reporting.

- (Bonus) Experience standing up a GRC program or compliance automation tooling (Vanta, Drata, Secureframe, OneTrust) from scratch, and working knowledge of cloud platforms (AWS, GCP, Azure) and their native security and logging tooling.

COMPENSATION

We offer competitive compensation that is geo-adjusted based on your location, along with meaningful equity so you share in the value you help create. Salary range for this role in New York, NY or Arlington, VA is $155,000 - $185,000 depending on experience and interview performance and location.

Our benefits include:

- 401(k) match

- 100% coverage of medical, dental, and vision premiums for you and your dependents

- 12 weeks paid parental leave (for all parents, no waiting period)

  • Stipends for
  • Family-forming needs
  • Gender-affirming care

- Unlimited PTO

OUR CULTURE & VALUES

- We hire excellent people, give them outsized responsibility, and trust them to execute. Every person at Cape has a proven track record of tackling hard problems and winning.

- We believe that personal privacy and national security are not at odds, and that they can be reconciled through strong technology.

- We believe companies exist to build awesome things and take care of the people who build them, so we offer top-tier healthcare, 401(k) matching, and a generous vacation policy that our team actually uses to recharge.

- We believe that a stronger company and a better product are built by people from all walks of life. We hire without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital status, disability, or Veteran status. If you are great at what you do, you belong here.

HOW TO APPLY

Click the link below to apply.

We reserve the right to make use of any unsolicited resumes received from outside recruiting agencies and / or individual recruiters without being responsible for payment of any fees asserted from the use of unsolicited resumes.

We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin, and without regard to disability or status as a protected veteran, or any other status protected by law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Cape's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Cape's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Cape's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.