Trust & Assurance Lead

3 weeks, 2 days ago
Full-time
Senior
Cybersecurity
Sysdig

Sysdig

Sysdig provides advanced security solutions for containers, Kubernetes, and cloud environments, enabling organizations to gain visibility and context through runtime insights to proactively prevent cyber attacks.

IT Services
251-1K
Founded 2013
$730M raised

Description

  • Rebuild assurance as engineering through policy-as-code, continuous control validation, drift detection, and automated evidence generation.
  • Own ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II certification programs, including audits, assessments, remediation, and ISMS/PIMS artifacts.
  • Build Sysdig’s AI assurance program covering ISO 42001, the NIST AI RMF, applicable EU AI Act obligations, AI system controls, data handling, and AI-assisted development.
  • Manage AI-related third-party risk and document risk acceptance decisions.
  • Lead customer, partner, and high-consequence security assurance engagements, including questionnaires, trust materials, and third-party audits.
  • Define defensible security specifications for access, separation of duties, administrative transparency, and tenant isolation.
  • Enable sales and account teams to answer routine security questions independently through repeatable content and processes.
  • Maintain the accuracy of public security claims, certifications, trust-center content, and marketplace listings.
  • Convert assurance findings into engineering commitments, risk acceptance decisions, and escalations.
  • Use automation and agentic tooling for evidence generation, questionnaire drafting, control validation, and gap analysis; represent Sysdig externally through customer engagement, publishing, and speaking.

Requirements

  • End-to-end experience running certification and audit programs for a cloud or SaaS company.
  • Experience shipping code or automation for control objectives using tools such as Python, Go, Terraform, CI pipelines, APIs, or compliance platforms.
  • Deep expertise in at least two of SOC 2, ISO 27001, ISO 27701, and ISO 42001, with working knowledge of the others.
  • Experience demonstrating operational compliance evidence to enterprise customers or auditors.
  • Cloud-native technical knowledge including Kubernetes, containers, at least one major cloud provider, and runtime security fundamentals.
  • Experience building with agentic tooling and understanding its limitations.
  • Ability to distinguish material business risk from audit-only findings and communicate effectively with CISOs and engineers.
  • Experience creating an assurance or compliance function from the ground up.
  • Experience with AI governance frameworks such as ISO 42001, the EU AI Act, or NIST AI RMF.
  • Experience with continuous controls monitoring, GRC engineering, security vendors, public-sector requirements, regulated financial services, or EU data protection is preferred.
  • Conference speaking, published research, or contributions to control frameworks or open standards are preferred.

Benefits

  • U.S. salary range of $160,000–$200,000 per year.
  • Extra paid days off for well-being.
  • 401(k) plan with a 3% company match.
  • Maternity and parental leave.
  • Mental health support for employees and families through Modern Health.
  • Full health benefits package for employees and families.
  • Remote work opportunity.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

FOIA Analyst

TechOp Solutions International 51-250 Internet Software & Services

TechOp Solutions is hiring an experienced FOIA Analyst to process complex federal FOIA requests and support disclosure reviews, redaction, appeals, litigation, and quality assurance activities.

21 hours, 58 minutes ago

Safety Administrator

Remote Raven 11-50 Professional Services

Remote Safety, Insurance & Risk Administrator for a US multi-brand roofing and exteriors group, responsible for managing employee safety programs, OSHA compliance, workers’ compensation, and subcontractor documentation without field supervision.

21 hours, 58 minutes ago

Governance, Risk & Compliance (GRC) Manager

Loenbro 251-1K Construction & Engineering

Loenbro’s remote Information Technology team is seeking a Governance, Risk & Compliance Manager to lead and mature cybersecurity governance, risk, compliance, and audit programs, including CMMC Level 2, SOC audits, and SOX ITGC.

Cybersecurity
21 hours, 58 minutes ago

IT Risk and Compliance Analyst

Huge 251-1K Media

Huge is seeking a remote U.S.-based Compliance Officer to execute and help rebuild its IT risk and compliance program across contracts, security, privacy, vendors, and operational controls.

1 day, 21 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers