GRC Security Engineer, Federal & Public Sector
cursor
Start your Pro trial in 30 seconds (3 days free): you also get the AI match score with your resume.
Role overview
cursor is hiring for the GRC Security Engineer, Federal & Public Sector role in San Francisco, US. It is full-time, Mid-level level, in the Tech sector. It was posted 5/10/2026.
On TalentyGo you can review this job and apply more effectively: Charlie prepares an ATS-optimized resume and a cover letter tailored to "GRC Security Engineer, Federal & Public Sector" at cursor in about a minute. Before you apply, you can also check how well your profile fits, with a match score based on skills, experience, location and seniority.
- Role
- GRC Security Engineer, Federal & Public Sector
- Company
- cursor
- Location
- San Francisco, US
- Work mode
- On-site
- Employment
- Full-time
- Seniority
- Mid-level
- Sector
- Tech
- Posted
- 5/10/2026
Description
Our mission is to automate coding. The first step in our journey is to build the best tool for professional programmers, using a combination of inventive research, design, and engineering. Our organization is very flat, and our team is small and talent dense. We particularly like people who are truth-seeking, passionate, and creative. We enjoy spirited debate, crazy ideas, and shipping code.
About the role
Cursor is investing in serving federal and other regulated-market customers, and we're building the GRC foundation to get there. Federal compliance — FedRAMP and adjacent authorizations — is a key path, and we're looking for a senior GRC engineer to lead the technical execution.
This is a hands-on GRC engineering role. We treat compliance as code. You'll write code, ship infrastructure changes, generate machine-readable artifacts, and design evidence collection pipelines that keep compliance honest without dragging engineers into screenshot purgatory. You'll partner closely with our security engineering, infrastructure, and legal teams.
We're in-person with cozy offices in North Beach, San Francisco and Manhattan, New York, complete with well-stocked libraries. SF is preferred for this role since you'll be partnering closely with the GRC and security leadership team in person.
What you'll do
Help us evaluate and shape our federal and regulated-market compliance strategy — FedRAMP, impact levels, and international equivalents — and lead the technical execution
Own the technical heavy lifting on any authorization we pursue: control implementation, SSP authorship, 3PAO engagement, POA&M management, and continuous monitoring
Build compliance-as-code: automated evidence collection, machine-readable artifacts, and continuous control monitoring tied into our existing security telemetry
Author honest, defensible control narratives across the major NIST 800-53 families
Influence and drive international compliance strategy as we expand
Support the broader security team on security and trust enablement as needed
You may be a fit if
You have direct, hands-on experience with FedRAMP authorization — as a CSP team member who took a service through ATO, or as a senior assessor at a 3PAO
You read NIST SP 800-53 Rev. 5 like a developer reads RFCs — you can argue control intent, not just recite it
You write code (Go, Python, or comparable) and have automated something in compliance that other people would have done with screenshots
You know what OSCAL is, why it matters, and ideally have generated or consumed it in production
You've worked in or alongside AWS GovCloud, Azure Government, or DoD IL4/5 environments
You have working knowledge of FIPS 140-3, FedRAMP 20x / KSIs, CMMC, and how DoD impact levels map onto FedRAMP baselines
Bonus: dual-perspective experience — you've been an operator who has taken organizations through FedRAMP authorization multiple times and spent time on the 3PAO assessor side. OSCAL tooling or GRC engineering tooling contributions and public writing or speaking on GRC engineering are also a plus
#LI-DNI
The market for this role in San Francisco
TalentyGo lists 5292 similar roles (502 in San Francisco), 22% remote. Charlie ranks them against your CV, each with a clear score.
Similar jobs
TalentyGo is an aggregator of job postings from public sources. Always verify information directly with the company. Applications go through the original company website; TalentyGo does not manage hiring processes.