
Senior Security Assurance Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Design, document, maintain, and evaluate IT General Controls and security measures throughout the designated estate.
• Map shared controls and validate them against SOX, SOC 2, ISO 27001, ISO 42001, NIST CSF, PCI-DSS, privacy regulations, and customer contractual obligations.
• Act as the compliance liaison and point of contact for IT, Corporate Security, Engineering, and Finance teams.
• Establish standards and control expectations for the governed use of AI across corporate and business systems.
• Collaborate with Security Governance on corporate security policies, standards, procedures, reviews, attestations, and adherence to the Acceptable Use Policy.
• Conduct ongoing compliance monitoring for access reviews, privileged access, segregation of duties, change management, and configuration baselines.
• Evaluate system implementations, migrations, and significant changes for control readiness prior to go-live.
• Oversee SOX ITGC testing and certification requests from both internal and external auditors.
• Lead and automate evidence collection for external audits.
• Identify, track, and manage the remediation of control deficiencies and risks.
• Suggest enhancements to compliance processes, metrics, and reporting.
• A minimum of 5 years of experience in IT compliance, security compliance, IT auditing, information security, or information technology.
• Bachelor's degree in a business or technology field or equivalent professional experience.
• Proficient in testing controls and documenting evaluations against COSO, COBIT, NIST CSF, ISO 27001, SOC 2, and SOX ITGC.
• Experienced in direct collaboration with internal or external auditors.
• Familiar with assessing controls in SaaS and cloud-native application environments.
• Working knowledge of identity and access management, including SSO, SCIM, RBAC, privileged access, and joiner/mover/leaver processes.
• Understanding of AI governance concepts and control questions related to AI tools, agents, and integrations.
• Experience in contributing to security policies and standards, as well as supporting policy adherence or attestation processes.
• Ability to analyze data flows among product usage, billing, subscription, and financial reporting systems.
• Excellent written and verbal communication skills.
• Proficient in using GitLab, or a willingness to learn.
• Experience with a Big 4 or external audit firm is advantageous.
• Relevant certifications such as CISA, CISSP, CRISC, or CISM are preferred.
• Familiarity with usage-based or consumption billing platforms, subscription management systems, or in-house metering and entitlement services is a plus.
• Experience with compliance automation and continuous control monitoring, or establishing standards for AI use in an enterprise context, is a bonus.
• Prior experience in a Security Assurance or GRC role supporting both corporate IT and product engineering is highly desirable.
• Comprehensive benefits to promote your health, financial well-being, and overall wellness.
• Flexible Paid Time Off policy.
• Participation in Team Member Resource Groups.
• Equity Compensation and Employee Stock Purchase Plan.
• Growth and Development Fund to support career advancement.
• Parental Leave to support family needs.
GitLab
GitLab
Cisco
Lovesac
Get handpicked remote jobs straight to your inbox weekly.