Skip to main content

Cursor

Security GRC Engineer

San FranciscofulltimemidAdded today

About this role

Lead the design and implementation of governance, risk, and compliance programs at an AI coding automation company. You'll automate compliance workflows, build tools for go-to-market teams, and ensure products meet security standards while working cross-functionally across engineering, legal, and customer-facing teams.

What you'll do

  • Design and scale GRC programs aligned with SOC 2, ISO 27001, ISO 42001, and AI governance frameworks
  • Automate evidence gathering, control testing, and compliance workflow processes
  • Manage relationships with audit firms and customers, explaining security and AI governance programs
  • Conduct security compliance reviews for new products, features, and vendor integrations
  • Support legal team with security and AI governance guidance during contract negotiations
  • Build self-serve tools and documentation for customer security inquiries and corporate security policies

What they're looking for

  • SOC 2, ISO 27001, ISO 42001, and AI governance framework expertise
  • Security compliance and control testing knowledge
  • Cross-functional collaboration and stakeholder management
  • Technical investigation and verification skills
  • Incident response communication and documentation
  • Automation and process improvement mindset
  • Customer and auditor relationship management
  • Contract review and security requirements analysis
Apply with Autofill

Opens the application — the Jobs AI extension fills it for you. Set up autofill

Opens the official application on the employer’s site. No login required.

Cursor

Cursor builds an AI-driven code editor used by millions of developers to transform how software is built. The company is hiring for infrastructure engineers, ML systems specialists, enterprise platform builders, security engineers, and customer success roles focused on driving adoption within large organizations.

Website
cursor.com
View all jobs at Cursor

Likely interview questions

  • Walk us through how you'd verify that our actual product configuration matches our SOC 2 claims—what tools or methods would you use?
  • Describe your experience managing audit relationships. How do you handle auditor requests and tight compliance timelines?