Cape
Cape
Cape is a telecommunications company building a privacy-first mobile network for more secure, trustworthy communication. Its services are designed to give users greater privacy while using mobile connectivity, addressing growing concerns about how personal information is handled in modern communications.

GRC Engineer

Build automated controls and compliance programs to secure Cape’s privacy-focused mobile carrier. Lead SOC 2 and CMMC efforts, risk management, audits, and customer security reviews.

Description

  • Build automated controls monitoring across AWS, GCP, Azure, CI/CD, and SaaS environments.
  • Own and improve SOC 2 Type II, CMMC, and future compliance programs.
  • Prepare audits, gather evidence, and monitor remediation.
  • Advise on risk assessments, control design, security policies, vendor risk, automated access reviews, and audit management.
  • Evaluate technical and organizational risks and implement scalable responses.
  • Develop policies and automation to put them into practice.
  • Partner with Security and Engineering on risk, policy, and compliance tools.
  • Introduce risk registers, access reviews, vendor assessments, and audit cycles.
  • Lead and contribute to Security team initiatives.
  • Help customers and prospects with security questionnaires, due diligence, and trust discussions.
  • Build tools that speed up security due diligence.
  • Report to the Head of Security.

Requirements

  • Bring at least three years of hands-on technical experience in GRC engineering, security engineering, or compliance.
  • Demonstrate expertise in SOC 2, CMMC, FedRAMP, NIST CSF, and GDPR.
  • Translate regulatory and contractual requirements into technical controls and engineering decisions.
  • Have designed and implemented risk or compliance programs.
  • Bring strong prioritization and project management skills.
  • Have managed audits with firm deadlines.
  • Partner with engineering and security leaders to guide risk decisions and audit outcomes.
  • Explain technical risks in business terms.
  • Assess risk tradeoffs objectively and drive issues to resolution.
  • Hold a BA or BS in a related field, or have equivalent practical experience.
  • Security or audit certifications such as CISSP, CISA, or CRISC are a plus.
  • Python, Go, or TypeScript proficiency is a bonus.
  • Experience with Vanta, Drata, Secureframe, or OneTrust is a bonus.
  • Working knowledge of AWS, GCP, Azure, and their native security and logging tools is a bonus.

Benefits

  • Meaningful equity.
  • 401(k) matching.
  • Medical, dental, and vision premiums fully covered for you and your dependents.
  • 12 weeks of paid parental leave for all parents, with no waiting period.
  • Stipends for family-forming needs.
  • Stipends for gender-affirming care.
  • Unlimited paid time off.
  • Generous vacation policy.

Related Jobs

Kreato Global | BPO and Language Solutions

Remote English-Spanish OPI/VRI Interpreter

Kreato Global | BPO and Language Solutions
201 – 500 Employees
HealthcareHospitalityLogistics

Interpret remotely between English- and Spanish-speaking people in medical, financial, social service, and customer care settings. Provide language support for Kreato Global across Latin America.

Open
SPERTON - Where Great People Meet

Sales Executive, Elevators and Car Parking Systems

SPERTON - Where Great People Meet
51 – 200 Employees

Drive elevator and car parking system sales across Mumbai’s Western Region. Build client and dealer relationships, and manage deals from initial enquiry through project execution.

Open