Security GRC Engineer
San Francisco, CAFull-timePosted 3 days agoStill listed 2 days ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near San Francisco, CA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
Cursor seeks a Security GRC Engineer to design, implement, and scale governance, risk, and compliance programs, automating workflows, building self‑serve tools, and ensuring product and infrastructure security while collaborating across engineering, legal, and audit teams.
Skills & qualifications
Skills
Qualifications
Full job description
Our mission is to automate coding. The first step in our journey is to build the best tool for professional programmers, using a combination of inventive research, design, and engineering. Our organization is very flat, and our team is small and talent dense. We particularly like people who are truth-seeking, passionate, and creative. We enjoy spirited debate, crazy ideas, and shipping code. About the Role Security GRC Engineers design, implement, and scale our governance, risk, and compliance (GRC) program. You'll lead automation of compliance workflows, build self-serve tools to enable GTM teams, and ensure our products and infrastructure meet the highest security standards. This role blends technical implementation with strategic program development, directly shaping how we build trust with customers.
You may be a fit if
-
You have experience with GRC frameworks such as SOC 2, ISO 27001, ISO 42001, and AIUC-1.
-
You're comfortable tracing an external claim back to how the product and infrastructure are actually configured — you use coding agents and curiosity to confirm that what we say is what we do, flag issues that affect the security and AI governance program, and drive them to the right outcome.
-
You have strong cross-functional collaboration skills, especially with Engineering, Legal, GTM, Trust & Safety, auditors, and regulators.
Sample projects include
-
Automate evidence gathering and continuous control testing.
-
Own the relationship with audit firms and customers — you're the person who explains the security and AI governance program and earns their trust in it.
-
Conduct security compliance reviews for new products, features, and vendors.
-
Support Legal in contract negotiations with timely, accurate guidance on security and AI governance terms.
-
Support incident response communications — draft and review customer-facing updates during security incidents.
-
Build self-serve documentation and tools to answer customer security and AI governance inquiries.
-
Maintain corporate security policies.
Applying If there appears to be a fit, we'll reach out to schedule 2–3 short technicals. After that, we'll schedule an onsite at our office, where you'll work on a small project, discuss ideas, and meet the team.
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Lead GRC EngineerHiggsfield AI · San Francisco, CA (Hybrid) · $220–280K/yrPosted 4w agoPosted 4w ago
Security GRC LeadMercor · San Francisco, CA · $350–425K/yrPosted 2w agoPosted 2w ago
Security EngineerGreptile · San Francisco, CA · $170–300K/yrPosted 3w agoPosted 3w ago
Product Engineer, SecurityGreptile · San Francisco, CA · $170–300K/yrPosted 2w agoPosted 2w ago
Member of Technical Staff, Infrastructure SecurityParallel · Bay Area, CA · $150–300K/yrPosted 1w agoPosted 1w ago
You've read the whole posting — now see how you match it.