Grc Security Engineer, Federal & Public Sector

Cursor Cursor · Coding AI · San Francisco, CA · Engineering

This role focuses on building the GRC (Governance, Risk, and Compliance) foundation for a company automating coding, specifically targeting federal and regulated markets. The engineer will lead technical execution for compliance, treating it as code by writing code, shipping infrastructure, generating machine-readable artifacts, and designing evidence collection pipelines. Key responsibilities include shaping compliance strategy, owning authorization processes (FedRAMP, SSP authorship, 3PAO engagement), building automated evidence collection, and authoring control narratives. Experience with FedRAMP, NIST 800-53, and automation in compliance is required.

What you'd actually do

  1. Help us evaluate and shape our federal and regulated-market compliance strategy — FedRAMP, impact levels, and international equivalents — and lead the technical execution
  2. Own the technical heavy lifting on any authorization we pursue: control implementation, SSP authorship, 3PAO engagement, POA&M management, and continuous monitoring
  3. Build compliance-as-code: automated evidence collection, machine-readable artifacts, and continuous control monitoring tied into our existing security telemetry
  4. Author honest, defensible control narratives across the major NIST 800-53 families
  5. Influence and drive international compliance strategy as we expand

Skills

Required

  • Direct, hands-on experience with FedRAMP authorization
  • Experience with NIST SP 800-53 Rev. 5
  • Proficiency in coding (Go, Python, or comparable)
  • Experience automating compliance tasks
  • Knowledge of OSCAL
  • Experience in AWS GovCloud, Azure Government, or DoD IL4/5 environments
  • Working knowledge of FIPS 140-3, FedRAMP 20x / KSIs, CMMC

Nice to have

  • Dual-perspective experience (operator and assessor)
  • Contributions to OSCAL tooling or GRC engineering tooling
  • Public writing or speaking on GRC engineering

What the JD emphasized

  • FedRAMP
  • compliance-as-code
  • automated evidence collection
  • machine-readable artifacts
  • continuous monitoring
  • NIST 800-53
  • OSCAL