Security GRC Engineer
Summary
Designs, implements, and scales governance, risk, and compliance programs at Cursor: automating evidence gathering and continuous control testing, running security reviews of products and vendors, supporting contracts and incident communications, and building self-service security and AI governance documentation. Core focus is GRC frameworks like SOC 2, ISO 27001, ISO 42001, and AIUC-1.
You will design, implement, and scale governance, risk, and compliance programs. You will automate compliance workflows, conduct reviews, support contract and incident communications, maintain policies, and build documentation and tools for security and AI governance inquiries.
Responsibilities
- Automate evidence gathering and continuous control testing
- Manage relationships with audit firms and customers
- Conduct security compliance reviews for products, features, and vendors
- Support contract negotiations with security and AI governance guidance
- Draft and review customer-facing incident communications
- Build self-service security and AI governance documentation and tools
- Maintain corporate security policies
Requirements
- Experience with GRC frameworks including SOC 2, ISO 27001, ISO 42001, and AIUC-1
- Ability to trace external claims to product and infrastructure configurations
- Cross-functional collaboration with Engineering, Legal, GTM, Trust & Safety, auditors, and regulators