Cape
Cape
Cape este o companie de telecomunicații care dezvoltă o rețea mobilă axată în primul rând pe confidențialitate, pentru comunicații mai sigure și mai de încredere. Serviciile sale sunt concepute pentru a le oferi utilizatorilor un nivel mai ridicat de confidențialitate atunci când folosesc conectivitatea mobilă, răspunzând preocupărilor tot mai mari legate de modul în care sunt gestionate informațiile personale în comunicațiile moderne.

GRC Engineer

Build automated controls and compliance programs to secure Cape’s privacy-focused mobile carrier. Lead SOC 2 and CMMC efforts, risk management, audits, and customer security reviews.

Descriere

  • Build automated controls monitoring across AWS, GCP, Azure, CI/CD, and SaaS environments.
  • Own and improve SOC 2 Type II, CMMC, and future compliance programs.
  • Prepare audits, gather evidence, and monitor remediation.
  • Advise on risk assessments, control design, security policies, vendor risk, automated access reviews, and audit management.
  • Evaluate technical and organizational risks and implement scalable responses.
  • Develop policies and automation to put them into practice.
  • Partner with Security and Engineering on risk, policy, and compliance tools.
  • Introduce risk registers, access reviews, vendor assessments, and audit cycles.
  • Lead and contribute to Security team initiatives.
  • Help customers and prospects with security questionnaires, due diligence, and trust discussions.
  • Build tools that speed up security due diligence.
  • Report to the Head of Security.

Cerințe

  • Bring at least three years of hands-on technical experience in GRC engineering, security engineering, or compliance.
  • Demonstrate expertise in SOC 2, CMMC, FedRAMP, NIST CSF, and GDPR.
  • Translate regulatory and contractual requirements into technical controls and engineering decisions.
  • Have designed and implemented risk or compliance programs.
  • Bring strong prioritization and project management skills.
  • Have managed audits with firm deadlines.
  • Partner with engineering and security leaders to guide risk decisions and audit outcomes.
  • Explain technical risks in business terms.
  • Assess risk tradeoffs objectively and drive issues to resolution.
  • Hold a BA or BS in a related field, or have equivalent practical experience.
  • Security or audit certifications such as CISSP, CISA, or CRISC are a plus.
  • Python, Go, or TypeScript proficiency is a bonus.
  • Experience with Vanta, Drata, Secureframe, or OneTrust is a bonus.
  • Working knowledge of AWS, GCP, Azure, and their native security and logging tools is a bonus.

Beneficii

  • Meaningful equity.
  • 401(k) matching.
  • Medical, dental, and vision premiums fully covered for you and your dependents.
  • 12 weeks of paid parental leave for all parents, with no waiting period.
  • Stipends for family-forming needs.
  • Stipends for gender-affirming care.
  • Unlimited paid time off.
  • Generous vacation policy.

Locuri de muncă similare