
Trust & Assurance Lead
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in United States.
• Take ownership of how Sysdig demonstrates its security assertions to auditors, enterprise clients, and regulatory bodies.
• Reinvent assurance within engineering by implementing controls, articulating policy as code, and identifying control drift.
• Manage the ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II certification program from inception to completion.
• Oversee ISMS and PIMS documentation along with quarterly security goals.
• Conduct independent internal audits and collaborate with external assessors.
• Aim to decrease labor intensity for audit cycles year after year.
• Develop Sysdig's AI assurance initiative that encompasses its AI systems and enterprise-level AI requirements.
• Establish and implement controls for model and agent behaviors, AI data management, and AI-enhanced development.
• Manage third-party risks associated with AI.
• Facilitate customer and partner assurance, which includes managing trust profiles, questionnaires, intake processes, and document repositories.
• Lead critical assurance engagements for regulated sectors such as financial services, pharmaceuticals, aviation, and specific regional programs.
• Draft defensible specifications concerning access pathways, separation of duties, administrative transparency, and tenant isolation.
• Equip sales engineers and account teams to effectively respond to the majority of security inquiries.
• Uphold the accuracy of public security claims, certification pages, trust center, and marketplace listings.
• Channel risk findings into engineering commitments or formal management replies.
• Utilize Sysdig's platform in a production environment to produce evidence and shape the product roadmap.
• Employ agents to enhance evidence generation, questionnaire preparation, control validation, and gap analysis.
• Engage with customer security teams and represent Sysdig in external forums through publishing and public speaking.
• Have successfully run a certification and audit program from start to finish for a cloud or SaaS organization, taking responsibility for the results rather than just coordination.
• Have delivered code or automation to meet a control objective, utilizing Python, Go, Terraform, CI pipelines, or an API integrated into a compliance platform.
• Possess substantial expertise in at least two of SOC 2, ISO 27001, ISO 27701, ISO 42001, with a working knowledge of the remaining standards.
• Have interacted directly with an enterprise customer's security team or an auditor to demonstrate compliance with operational evidence.
• Have a solid cloud-native technical foundation: Kubernetes, containers, at least one major cloud platform, and a sufficient understanding of runtime security.
• Are currently utilizing agentic tools and have insights on their limitations.
• Can differentiate between significant findings and those that are primarily of interest to auditors.
• Have credibility with a customer's Chief Information Security Officer (CISO) and with engineering teams.
• Established an assurance or compliance function that was previously non-existent.
• Worked on AI governance frameworks such as ISO 42001, the EU AI Act, and NIST AI RMF.
• Created continuous controls monitoring or Governance, Risk, and Compliance (GRC) engineering tools.
• Gained experience in assurance roles at a security vendor.
• Familiarity with public sector requirements, regulated financial services, or EU data protection regulations.
• A proven history of conference speaking, published research, or contributions to a control framework or open standard.
• Additional days off to focus on your well-being.
• 401(k) Retirement Savings Plan featuring a 3% company match.
• Maternity and Parental Leave.
• Mental health support available for you and your family through the Modern Health app.
• Comprehensive health benefits package for you and your family.
Cisco
Duck Creek Technologies
Trucordia
Trucordia
Get handpicked remote jobs straight to your inbox weekly.