Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Cape

GRC Engineer

Cape

. Design, build, and maintain automated continuous-controls-monitoring systems across AWS, GCP, Azure, CI/CD, and SaaS .

Posted 10/10/2026full-timeUnited StatesMid-LevelSenior💰 $155,000 - $185,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in designing and implementing compliance programs such as SOC 2, CMMC, and NIST CSF, while effectively translating technical risks into business terms. Proficient in risk assessment, audit management, and automation within cloud environments like AWS, GCP, and Azure.

Highest-signal resume keywords
GRC EngineeringSOC 2 ComplianceRisk AssessmentPython ProgrammingProject Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk AssessmentCompliance Program DesignAudit ManagementTechnical Controls ImplementationAutomation Scripting
Soft Skills
PrioritizationCollaborationCommunication
Tools & Technologies
AWSGCPAzureVantaDrata
Certifications & Qualifications
CISSPCISACRISC
Industry Keywords
CMMCFedRAMPNIST CSFGDPRSOC 2 Type II

Tech Stack

Tools & technologies
AWSAzureGoogle Cloud PlatformPythonTypeScriptGo

About the role

Key responsibilities & impact
  • Design, build, and maintain automated continuous-controls-monitoring systems across AWS, GCP, Azure, CI/CD, and SaaS
  • Own and mature SOC 2 Type II, CMMC, and future compliance programs end-to-end
  • Prepare audits, collect evidence, and track remediation
  • Provide subject matter expertise in risk assessment, controls design, security policy, vendor risk, access-review automation, and audit management
  • Assess technical and organizational risk and implement scalable solutions
  • Write policies and ship automation to enforce them
  • Collaborate with Security and Engineering on risk-management, policy, and compliance tooling
  • Roll out risk registers, access reviews, vendor-risk assessments, and audit cycles
  • Lead and contribute to Security team projects
  • Support customers and prospects with security questionnaires, due diligence, and trust-building conversations
  • Build tooling to accelerate security due-diligence processes
  • Report to the Head of Security

Requirements

What you’ll need
  • 3+ years in GRC engineering, security engineering, or compliance with hands-on technical work
  • Demonstrable expertise across SOC 2, CMMC, FedRAMP, NIST CSF, and GDPR
  • Experience translating regulatory and contractual requirements into technical controls and engineering decisions
  • Track record of designing and implementing risk or compliance programs
  • Strong prioritization and project management skills
  • Experience running audits against real deadlines
  • Experience partnering with engineering and security leaders to drive risk decisions and audit outcomes
  • Ability to translate technical risk into business terms
  • Ability to assess risk tradeoffs objectively and drive issues to resolution
  • BA / BS in a related field or equivalent practical experience
  • Relevant security or audit certifications such as CISSP, CISA, or CRISC are a plus
  • Proficiency in Python, Go, or TypeScript is a bonus
  • Experience with Vanta, Drata, Secureframe, or OneTrust is a bonus
  • Working knowledge of AWS, GCP, Azure, and native security and logging tooling is a bonus

Benefits

Comp & perks
  • Meaningful equity
  • 401(k) match
  • 100% coverage of medical, dental, and vision premiums for you and your dependents
  • 12 weeks paid parental leave for all parents, with no waiting period
  • Stipends for family-forming needs
  • Stipends for gender-affirming care
  • Unlimited PTO
  • Generous vacation policy