Trust & Assurance Lead

9 hours, 45 minutes ago
Full-time
Senior
Cybersecurity
Sysdig

Sysdig

Sysdig provides advanced security solutions for containers, Kubernetes, and cloud environments, enabling organizations to gain visibility and context through runtime insights to proactively prevent cyber attacks.

IT Services
251-1K
Founded 2013
$730M raised

Description

  • Rebuild assurance as engineering through policy-as-code, continuous control validation, drift detection, and automated evidence generation.
  • Own ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II certification programs, including audits, assessments, remediation, and ISMS/PIMS artifacts.
  • Build Sysdig’s AI assurance program covering ISO 42001, the NIST AI RMF, applicable EU AI Act obligations, AI system controls, data handling, and AI-assisted development.
  • Manage AI-related third-party risk and document risk acceptance decisions.
  • Lead customer, partner, and high-consequence security assurance engagements, including questionnaires, trust materials, and third-party audits.
  • Define defensible security specifications for access, separation of duties, administrative transparency, and tenant isolation.
  • Enable sales and account teams to answer routine security questions independently through repeatable content and processes.
  • Maintain the accuracy of public security claims, certifications, trust-center content, and marketplace listings.
  • Convert assurance findings into engineering commitments, risk acceptance decisions, and escalations.
  • Use automation and agentic tooling for evidence generation, questionnaire drafting, control validation, and gap analysis; represent Sysdig externally through customer engagement, publishing, and speaking.

Requirements

  • End-to-end experience running certification and audit programs for a cloud or SaaS company.
  • Experience shipping code or automation for control objectives using tools such as Python, Go, Terraform, CI pipelines, APIs, or compliance platforms.
  • Deep expertise in at least two of SOC 2, ISO 27001, ISO 27701, and ISO 42001, with working knowledge of the others.
  • Experience demonstrating operational compliance evidence to enterprise customers or auditors.
  • Cloud-native technical knowledge including Kubernetes, containers, at least one major cloud provider, and runtime security fundamentals.
  • Experience building with agentic tooling and understanding its limitations.
  • Ability to distinguish material business risk from audit-only findings and communicate effectively with CISOs and engineers.
  • Experience creating an assurance or compliance function from the ground up.
  • Experience with AI governance frameworks such as ISO 42001, the EU AI Act, or NIST AI RMF.
  • Experience with continuous controls monitoring, GRC engineering, security vendors, public-sector requirements, regulated financial services, or EU data protection is preferred.
  • Conference speaking, published research, or contributions to control frameworks or open standards are preferred.

Benefits

  • U.S. salary range of $160,000–$200,000 per year.
  • Extra paid days off for well-being.
  • 401(k) plan with a 3% company match.
  • Maternity and parental leave.
  • Mental health support for employees and families through Modern Health.
  • Full health benefits package for employees and families.
  • Remote work opportunity.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Government Compliance Technical Specialist

BeyondTrust 1K-5K Professional Services

BeyondTrust is hiring a Government Compliance Technical Specialist to execute and modernize its FedRAMP, TX-RAMP, IRAP, and related public-sector compliance programs within the Trust & Assurance team.

Cybersecurity
9 hours, 16 minutes ago

Medicare Marketing Compliance Specialist [Contract]

Spark Advisors 11-50 Insurance

Spark Advisors is hiring a Contract Marketing Oversight Associate to manage its Medicare marketing compliance program, reviewing partner materials, coordinating carrier approvals, and protecting brokers and beneficiaries.

9 hours, 16 minutes ago

Lead Compliance Manager

Motive 1K-5K Road & Rail

Motive is hiring a Lead Compliance Manager for its Financial Products team to build and own the end-to-end compliance function for its commercial lending and spend management program across current and future markets.

9 hours, 31 minutes ago

Legal & Compliance Intern

Greenlight 251-1K Capital Markets

Greenlight is seeking a Legal & Compliance Intern for the 2026–2027 school year to support its Legal and Compliance team with regulatory research, compliance operations, and legal projects within a fintech company.

Git
9 hours, 31 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers