Security GRC Engineer

Cursor

• $120K — $145K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Experience with GRC frameworks such as SOC 2 and ISO standards.
  • Ability to trace external claims to product configurations using coding agents.
  • Strong cross-functional collaboration skills with stakeholders.
  • Experience with security compliance and audits.
  • Understanding of security and AI governance programs.

Responsibilities

  • Design and implement the GRC program to enhance security governance.
  • Automate compliance workflows and evidence gathering processes.
  • Manage relationships with audit firms and ensure customer trust.
  • Conduct compliance reviews for new products and vendors.
  • Support legal teams by providing security guidance during negotiations.
  • Draft communications for customers during security incident responses.
  • Develop documentation and tools for customer inquiries on security governance.

Benefits

  • Flexible work environment with options for remote work.
  • Opportunities for professional development and training.
  • Collaborative team culture with cross-functional projects.
  • Access to modern tools and technologies for project execution.
  • Supportive leadership encouraging initiative and innovation.
Full Job Description
Engineering • Full-time • San Francisco; Palo Alto, CA
Apply

About the Role

Security GRC Engineers design, implement, and scale our governance, risk, and compliance (GRC) program. You'll lead automation of compliance workflows, build self-serve tools to enable GTM teams, and ensure our products and infrastructure meet the highest security standards. This role blends technical implementation with strategic program development, directly shaping how we build trust with customers.

You may be a fit if
  • You have experience with GRC frameworks such as SOC 2, ISO 27001, ISO 42001, and AIUC-1.
  • You're comfortable tracing an external claim back to how the product and infrastructure are actually configured - you use coding agents and curiosity to confirm that what we say is what we do, flag issues that affect the security and AI governance program, and drive them to the right outcome.
  • You have strong cross-functional collaboration skills, especially with Engineering, Legal, GTM, Trust & Safety, auditors, and regulators.

Sample projects include
  • Automate evidence gathering and continuous control testing.
  • Own the relationship with audit firms and customers - you're the person who explains the security and AI governance program and earns their trust in it.
  • Conduct security compliance reviews for new products, features, and vendors.
  • Support Legal in contract negotiations with timely, accurate guidance on security and AI governance terms.
  • Support incident response communications - draft and review customer-facing updates during security incidents.
  • Build self-serve documentation and tools to answer customer security and AI governance inquiries.
  • Maintain corporate security policies.

Applying

If there appears to be a fit, we'll reach out to schedule 2-3 short technicals. After that, we'll schedule an onsite at our office, where you'll work on a small project, discuss ideas, and meet the team.

Similar Jobs

More Jobs at Cursor

More Information Technology Jobs

Find similar Security GRC Engineer jobs: