Trust & Assurance Lead

Jobtailor

Deutschland

Remote

EUR 120.000 - 180.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Erhalte eine Antwort von diesem Arbeitgeber — ein Lebenslauf und ein Anschreiben, die genau auf die Eigenschaften eingehen, die gesucht werden.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Sysdig is seeking an experienced assurance leader to own end-to-end certification programs (ISO 27001:2022, ISO 27701:2019, SOC 2 Type II) for cloud/SaaS environments. The role requires collaborating with auditors, regulators, and enterprise security teams to maintain trust and evidence credibility.

You will drive ISMS and PIMS artifacts, AI governance, and continuous controls monitoring, while coordinating with product and engineering to align with compliance requirements.

Qualifikationen

  • Experience running an end-to-end certification and audit program for a cloud or SaaS company.
  • Shipped code or automation in service of a control objective using Python, Go, Terraform, CI pipelines, or an API wired into a compliance platform.
  • Depth in at least two of SOC 2, ISO 27001, ISO 27701, ISO 42001 with working knowledge of the rest.
  • Persuasive communication with enterprise security teams and auditors with demonstrated evidence.
  • Cloud-native foundation: Kubernetes, containers, major cloud, and runtime security understanding.

Aufgaben

  • Own ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II programs end-to-end.
  • Run internal audits and coordinate external assessors for assurance.
  • Define controls, policy as code, and detect control drift to guide engineering.
  • Lead AI governance and AI assurance frameworks across products and services.
  • Engage customer security teams, respond to questionnaires, and publish trust materials.

Kenntnisse

Credibility with CISO
Effective Communication
Engagement with Security Teams
Leadership in Assurance Programs
Analytical Problem-Solving

Ausbildung

ISO 27001:2022
ISO 27701:2019
SOC 2 Type II
ISO 42001

Tools

Sysdig Platform
Compliance Platforms
Agentic Tooling
Control Validation Tools
Evidence Generation Tools

Jobbeschreibung

  • Own how Sysdig proves its security claims to auditors, enterprise customers, and regulators
  • Rebuild assurance as engineering by instrumenting controls, expressing policy as code, and detecting control drift
  • Own the ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II certification program end-to-end
  • Own ISMS and PIMS artifacts and quarterly security objectives
  • Run independent internal audits and external assessors
  • Reduce labor per audit cycle year over year
  • Build Sysdig's AI assurance program covering its AI systems and enterprise AI requirements
  • Define and instrument controls for model and agent behavior, AI data handling, and AI-assisted development
  • Own AI third-party risk
  • Run customer and partner assurance, including trust profiles, questionnaires, intake, and document libraries
  • Lead high-consequence assurance engagements for regulated financial services, pharmaceutical, aviation, and sovereign or region-specific programs
  • Write defensible specifications for access paths, separation of duties, administrative transparency, and tenant isolation
  • Enable sales engineers and account teams to answer most security questions
  • Maintain the integrity of public security claims, certifications pages, trust center, and marketplace listings
  • Push risk findings into engineering commitments or formal management responses
  • Use Sysdig's platform in production to generate evidence and influence the product roadmap
  • Use agents to scale evidence generation, questionnaire drafting, control validation, and gap analysis
  • Engage customer security teams and represent Sysdig externally through publishing and speaking
Requirements
  • Have run a certification and audit program end-to-end for a cloud or SaaS company, owning the outcome rather than the coordination
  • Have shipped code or automation in service of a control objective, using Python, Go, Terraform, CI pipelines, or an API wired into a compliance platform
  • Have genuine depth in at least two of SOC 2, ISO 27001, ISO 27701, ISO 42001, with working knowledge of the rest
  • Have sat across from an enterprise customer's security team or an auditor and demonstrated compliance with operational evidence
  • Have a cloud-native technical foundation: Kubernetes, containers, at least one major cloud, and enough understanding of runtime security
  • Are already building with agentic tooling and have opinions about where it fails
  • Can distinguish significant findings from findings that only matter to an auditor
  • Are credible with a customer's CISO and with engineers
  • Built an assurance or compliance function that did not exist before
  • Worked on AI governance frameworks including ISO 42001, the EU AI Act, and NIST AI RMF
  • Built continuous controls monitoring or GRC engineering tooling
  • Worked assurance at a security vendor
  • Experience with public sector requirements, regulated financial services, or EU data protection
  • Track record of conference speaking, published research, or contribution to a control framework or open standard
Core Competencies

Demonstrates expertise in managing end-to-end certification and audit programs for cloud or SaaS environments, with a strong focus on ISO 27001, SOC 2, and AI governance frameworks. Capable of engaging with enterprise security teams and auditors while maintaining compliance and integrity of security claims.

Highest-signal resume keywords
  • End-To-End Certification Management
  • Python Programming
  • ISO 27001 Compliance
  • Cloud-Native Security
  • AI Governance Frameworks
ATS Optimization Keywords
Hard Skills
  • Python
  • Go
  • Terraform
  • CI Pipelines
  • Kubernetes
  • Containers
  • Continuous Controls Monitoring
  • GRC Engineering Tooling
  • Operational Evidence Demonstration
  • Control Objective Automation
Soft Skills
  • Credibility with CISO
  • Effective Communication
  • Engagement with Security Teams
  • Leadership in Assurance Programs
  • Analytical Problem-Solving
Certifications & Qualifications
  • ISO 27001:2022
  • ISO 27701:2019
  • SOC 2 Type II
  • ISO 42001
Industry Keywords
  • Regulated Financial Services
  • Pharmaceutical Compliance
  • Public Sector Requirements
  • EU Data Protection
  • AI-Assisted Development
Tools & Technologies
  • Compliance Platforms
  • Sysdig Platform
  • Agentic Tooling
  • Control Validation Tools
  • Evidence Generation Tools
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Security Assurance Advisor
Information Security Assurance Advisor

Jobtailor • Deutschland

Remote
EUR 80.000 - 120.000
Senior Security Engineer – Cloud Security
Senior Security Engineer – Cloud Security

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 130.000
Platform Information Security Officer, Diagnostics Platform
Platform Information Security Officer, Diagnostics Platform

Jobtailor • Deutschland

Remote
EUR 180.000 - 240.000
Senior Security Engineer – Sec Ops
Senior Security Engineer – Sec Ops

Jobtailor • Deutschland

Remote
EUR 120.000 - 180.000
Director, Security Research
Director, Security Research

Jobtailor • Deutschland

Remote
EUR 190.000 - 260.000
Regional Field CTO
Regional Field CTO

Jobtailor • Deutschland

Remote
EUR 180.000 - 240.000
Security Automation Engineer
Security Automation Engineer

Jobtailor • Leverkusen

Vor Ort
EUR 80.000 - 130.000
Technology Security Lead
Technology Security Lead

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Product Security Engineer
Product Security Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
VP, Chief Information Security Officer
VP, Chief Information Security Officer

Jobtailor • Deutschland

Remote
EUR 130.000 - 190.000