Senior Security Assurance Manager

1 month, 1 week ago
Full-time
Lead
Cybersecurity
Trase Systems

Trase Systems

Trase Systems specializes in delivering and implementing comprehensive AI agent applications that enable organizations to automate complex administrative workflows and processes securely and efficiently.

Professional Services
Founded 2023

Description

  • Own and operate Trase's SOC 2 and HIPAA programs end-to-end, including scoping, control design, evidence collection, and remediation tracking.
  • Lead readiness and execution for additional compliance frameworks such as ISO 27001, FedRAMP, NIST 800-53, CMMC, and ISO 42001 as the company enters new markets.
  • Manage the full lifecycle of internal and external audits and serve as the primary point of contact for auditors, assessors, and regulators.
  • Maintain the enterprise risk register and conduct recurring risk assessments across people, process, and technology.
  • Design, document, and operationalize security policies, standards, and procedures aligned to industry frameworks and Trase's risk appetite.
  • Own the common control framework in Drata and refine controls across overlapping regimes to reduce duplication and audit burden.
  • Implement continuous control monitoring, automated evidence collection, and recurring control testing to make compliance more proactive.
  • Define KRIs, KPIs, and reporting cadences that provide leadership with real-time visibility into program health.
  • Enhance third-party risk management, including vendor security reviews, ongoing monitoring, and contractual security requirements.
  • Partner with Legal, Engineering, HR, IT, Finance, and customer-facing teams on shared controls, trust conversations, RFPs, and due diligence.

Requirements

  • 10+ years of progressive experience in security assurance, GRC, controls engineering, or information security audit roles, including several years in a senior or program-owning capacity.
  • Deep, hands-on experience owning or supporting SOC 2 and HIPAA programs end-to-end, including managing external auditors or internal assessors.
  • Strong working knowledge of ISO 27001, FedRAMP (Moderate/High), NIST 800-53, NIST CSF, and CMMC, preferably with experience mapping requirements into common control frameworks.
  • Demonstrated experience designing and operating continuous control monitoring programs.
  • Proven ability to author clear, defensible security policies, standards, procedures, and memoranda.
  • Strong risk management background, including hands-on experience conducting risk assessments and maintaining a risk register.
  • Experience leading customer-facing security reviews, RFP responses, and trust conversations with enterprise buyers or partners.
  • Track record of partnering effectively with engineering and product teams to design controls into systems.
  • Excellent written and verbal communication skills across auditors, executives, customers, and engineers.
  • Strong affinity and practical skill for working with LLMs and AI agents as part of your workflow.
  • Experience scaling a compliance program inside a high-growth startup or scale-up (preferred).
  • Experience with FedRAMP authorization, DoD RMF, HITRUST, or StateRAMP (preferred).
  • Familiarity with ISO 42001 or other emerging AI governance frameworks (preferred).
  • Industry-recognized certifications such as CISSP, CISA, CISM, CRISC, or HCISPP (preferred).
  • Experience supporting customers in healthcare, defense, energy, or other regulated verticals (preferred).
  • Familiarity with modern GRC platforms such as ServiceNow IRM, Vanta, Drata, Hyperproof, or OneTrust (preferred).

Benefits

  • Salary range of $170,000-$230,000.
  • 100% employer-paid medical, dental, and vision coverage for you and your family.
  • Paid maternity and paternity leave for 14 weeks at employees' normal pay.
  • Unlimited PTO with management approval.
  • Opportunities for professional development and continued learning.
  • Optional 401(k), FSA, and equity incentives.
  • Mental health benefits through Tara Mind.
  • Potential for rapid career advancement as the firm grows.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Microsoft Security Consultant

Quisitive 1K-5K Internet Software & Services

Quisitive is hiring a Microsoft Security Consultant to work with clients on assessing risk, designing and implementing Microsoft security solutions, and improving security maturity across Microsoft cloud and security environments.

Active Directory Azure Network Security PowerShell SOC
16 hours, 48 minutes ago

IT Risk Compliance Director

Assyst Tecnologia 1-10 Wireless Telecommunication Services

ASSYST is seeking an IT Risk Compliance Director to provide on-demand cybersecurity support for a Department’s enterprise environment by identifying, analyzing, and mitigating security risks and responding to threats and incidents.

Cybersecurity Network Security Penetration Testing
17 hours, 19 minutes ago

Cybersecurity Risk Advisor

Assyst Tecnologia 1-10 Wireless Telecommunication Services

ASSYST is seeking a Cybersecurity Risk Advisor to support a federal cybersecurity program by assessing FISMA system risk posture, advising executive leadership, and guiding stakeholders on RMF and privacy-related actions.

Cybersecurity HIPAA
17 hours, 19 minutes ago

Fractional Cyber Security Analyst (Advisor Network)

Arootah 11-50 Professional Services

Arootah is seeking an experienced Cybersecurity Analyst to join its advisor network and support hedge fund and family office clients on project-based cybersecurity engagements.

Active Directory Azure Cybersecurity Encryption Network Security Penetration Testing SQL Windows Server
17 hours, 34 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers