About Cape
Cape is America’s privacy-first mobile carrier. Our mission is to be a force for good in global wireless. Cape was founded in 2022 by people who believe privacy is a fundamental right, not a luxury to be traded away. Our journey began when our founder recognized a critical vulnerability in our modern world: everyone relies on the same stagnant cellular infrastructure and legacy systems that track our every movement, monitor and profile our connections, and lose and sell our personal data.
Instead of accepting the status quo, we decided to fix it. National security professionals, journalists, parents, and everyone in between can stay connected and have privacy.
We didn’t just build a layer on top of old tech; we built America’s most private and secure mobile carrier from the ground up. By building our own network from scratch, we are able to design and build a suite of privacy and security features that no other carrier on the planet can offer.
Today, Cape provides our secure network to consumers, businesses, and government agencies alike. We closed our Series C in March 2026, and we are scaling rapidly, with the goal of giving people back control of their most personal information.
The Team
At Cape, we are the architects of a privacy-centric movement that is just getting started. We are relentless builders, constantly innovating at the edge of what's possible in telecommunications. We operate on a foundation of high trust and high expectations. Our structure is flat, and collaboration matters more than hierarchy. As a member of our team, you will collaborate with world-class engineers, architects, and visionaries, and work across organizational lines to solve "impossible" problems and deliver mission-critical results for our users every single day.
The Role:
We are looking for a GRC Engineer to help grow the governance, risk, and compliance function that keeps Cape secure, trustworthy, and audit-ready as we scale. You will sit at the intersection of security, engineering, and compliance — translating regulatory and contractual requirements into automated controls, clear policies, and pragmatic engineering solutions. You are equally comfortable writing a policy as you are writing a script to enforce it. As a steward of Cape culture, you will partner with engineering and security leaders to identify and remediate risk, run our compliance programs (SOC 2, CMMC, and beyond), and support customers through security due diligence. You put people and data first and always use evidence to drive decisions. You'll join an existing GRC function and are passionate about building on its foundation, sharpening our automation, and helping it scale with the business. This role reports to our Head of Security.
What You'll Work On:
Design, build, and maintain automated systems for continuous controls monitoring across our cloud infrastructure (AWS/GCP/Azure), CI/CD, and SaaS stack.
Own and mature our compliance programs end-to-end (SOC 2 Type II, CMMC, and future frameworks as they arise), including audit prep, evidence collection, and remediation tracking.
Provide subject matter expertise in: risk assessment, controls design, security policy, vendor/third-party risk, access review automation, and audit management.
Proactively assess technical and organizational risk, make data-driven recommendations, and implement scalable solutions rather than one-off manual fixes.
Roll up your sleeves to execute a full range of GRC duties — from writing policy to shipping the automation that enforces it.
Collaborate closely with Security and Engineering to implement solutions across risk management, policy, and compliance tooling.
Ensure successful rollout of key GRC programs such as risk registers, access reviews, vendor risk assessments, and audit cycles.
Lead and contribute to projects as an integral member of the Security team.
Support customers and prospects through security questionnaires, due diligence requests, and trust-building conversations, and build tooling to make that process faster.
Experience:
3+ years in GRC engineering, security engineering, or compliance with hands-on technical work; startup experience preferred.
Demonstrable expertise across compliance frameworks (SOC 2, CMMC, FedRAMP, NIST CSF, GDPR), including how regulatory and contractual requirements translate into technical controls and day-to-day engineering decisions.
Successful track record of designing and implementing risk or compliance programs, with processes that are clear and auditable but adapt as the business and regulatory landscape change.
Strong prioritization and project management skills, especially when running audits against real deadlines.
Experience partnering with and influencing engineering and security leaders to drive risk decisions and audit outcomes; you build trust easily with both engineers and auditors.
A clear communication style, and the ability to translate technical risk into business terms for different audiences.
Ability to see all sides of a risk tradeoff, remain objective, and drive issues to resolution — including through ambiguity, with a willingness to roll up your sleeves.
BA / BS in a related field or equivalent practical experience; relevant security or audit certifications (CISSP, CISA, CRISC, or similar) a plus.
(Bonus) Proficiency in at least one scripting or programming language (Python, Go, TypeScript) to automate evidence collection, monitoring, and reporting.
(Bonus) Experience standing up a GRC program or compliance automation tooling (Vanta, Drata, Secureframe, OneTrust) from scratch, and working knowledge of cloud platforms (AWS, GCP, Azure) and their native security and logging tooling.
Compensation
We offer competitive compensation that is geo-adjusted based on your location, along with meaningful equity so you share in the value you help create. Salary range for this role in New York, NY or Arlington, VA is $155,000 - $185,000 depending on experience and interview performance and location.
Our benefits include:
401(k) match
100% coverage of medical, dental, and vision premiums for you and your dependents
12 weeks paid parental leave (for all parents, no waiting period)
Stipends for
Family-forming needs
Gender-affirming care
Unlimited PTO
Our Culture & Values
We hire excellent people, give them outsized responsibility, and trust them to execute. Every person at Cape has a proven track record of tackling hard problems and winning.
We believe that personal privacy and national security are not at odds, and that they can be reconciled through strong technology.
We believe companies exist to build awesome things and take care of the people who build them, so we offer top-tier healthcare, 401(k) matching, and a generous vacation policy that our team actually uses to recharge.
We believe that a stronger company and a better product are built by people from all walks of life. We hire without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital status, disability, or Veteran status. If you are great at what you do, you belong here.
How to apply
Click the link below to apply.
We reserve the right to make use of any unsolicited resumes received from outside recruiting agencies and / or individual recruiters without being responsible for payment of any fees asserted from the use of unsolicited resumes.
We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin, and without regard to disability or status as a protected veteran, or any other status protected by law.