GRC Engineer

Cape•Arlington, VA
•$155,000 - $185,000•Remote

About The Position

Cape is seeking a GRC Engineer to enhance its governance, risk, and compliance functions, ensuring the company remains secure, trustworthy, and audit-ready during its scaling phase. This role operates at the intersection of security, engineering, and compliance, focusing on translating regulatory and contractual requirements into automated controls, clear policies, and practical engineering solutions. The ideal candidate is comfortable with both policy creation and script development for enforcement. As a guardian of Cape's culture, this individual will collaborate with engineering and security leaders to identify and mitigate risks, manage compliance programs (such as SOC 2 and CMMC), and assist customers with security due diligence. A strong emphasis is placed on prioritizing people and data, using evidence to guide decisions, and building upon the existing GRC foundation with a focus on automation and scalability. This position reports to the Head of Security.

Requirements

  • 3+ years in GRC engineering, security engineering, or compliance with hands-on technical experience; startup experience preferred.
  • Demonstrable expertise across compliance frameworks (SOC 2, CMMC, FedRAMP, NIST CSF, GDPR), including translating regulatory and contractual requirements into technical controls and daily engineering decisions.
  • Successful track record of designing and implementing risk or compliance programs with clear, auditable processes that adapt to business and regulatory changes.
  • Strong prioritization and project management skills, particularly in managing audits against deadlines.
  • Experience partnering with and influencing engineering and security leaders to drive risk decisions and audit outcomes.
  • Clear communication style, with the ability to translate technical risk into business terms for various audiences.
  • Ability to analyze risk tradeoffs objectively, drive issues to resolution, and work through ambiguity with a willingness to take on tasks.
  • BA/BS in a related field or equivalent practical experience.
  • Relevant security or audit certifications (CISSP, CISA, CRISC, or similar) are a plus.
  • Proficiency in at least one scripting or programming language (Python, Go, TypeScript) to automate evidence collection, monitoring, and reporting is a bonus.
  • Experience standing up a GRC program or compliance automation tooling (Vanta, Drata, Secureframe, OneTrust) from scratch is a bonus.
  • Working knowledge of cloud platforms (AWS, GCP, Azure) and their native security and logging tooling is a bonus.

Nice To Haves

  • Startup experience preferred.
  • Relevant security or audit certifications (CISSP, CISA, CRISC, or similar).
  • Proficiency in at least one scripting or programming language (Python, Go, TypeScript) to automate evidence collection, monitoring, and reporting.
  • Experience standing up a GRC program or compliance automation tooling (Vanta, Drata, Secureframe, OneTrust) from scratch.
  • Working knowledge of cloud platforms (AWS, GCP, Azure) and their native security and logging tooling.

Responsibilities

  • Design, build, and maintain automated systems for continuous controls monitoring across cloud infrastructure (AWS/GCP/Azure), CI/CD, and SaaS stack.
  • Own and mature compliance programs end-to-end, including SOC 2 Type II, CMMC, and future frameworks, encompassing audit preparation, evidence collection, and remediation tracking.
  • Provide subject matter expertise in risk assessment, controls design, security policy, vendor/third-party risk, access review automation, and audit management.
  • Proactively assess technical and organizational risk, provide data-driven recommendations, and implement scalable solutions.
  • Execute a full range of GRC duties, from writing policy to developing automation for enforcement.
  • Collaborate with Security and Engineering teams to implement solutions across risk management, policy, and compliance tooling.
  • Ensure successful rollout of key GRC programs such as risk registers, access reviews, vendor risk assessments, and audit cycles.
  • Lead and contribute to projects as an integral member of the Security team.
  • Support customers and prospects through security questionnaires, due diligence requests, and trust-building conversations, and develop tooling to streamline this process.

Benefits

  • 401(k) match
  • 100% coverage of medical, dental, and vision premiums for you and your dependents
  • 12 weeks paid parental leave (for all parents, no waiting period)
  • Stipends for family-forming needs
  • Stipends for gender-affirming care
  • Unlimited PTO
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service