Auf einen Blick
- Aufgaben: Leite die Sicherheits- und Compliance-Strategie für eine innovative AI-Plattform.
- Unternehmen: Ema, ein führendes Unternehmen im Bereich AI-Sicherheit und Compliance.
- Vorteile: Wettbewerbsfähiges Gehalt, Aktienoptionen und die Möglichkeit, etwas Bedeutendes zu schaffen.
- Weitere Informationen: Hohe Sichtbarkeit und direkter Zugang zur Engineering-Leitung.
- Warum dieser Job: Gestalte die Sicherheitsbasis einer bahnbrechenden AI-Plattform und beeinflusse große Unternehmen weltweit.
- Qualifikationen: Mindestens 8 Jahre Erfahrung in Sicherheit und Compliance, idealerweise mit Führungserfahrung.
Das prognostizierte Gehalt liegt zwischen 80000 - 110000 € pro Jahr.
About Ema
Ema is the Universal Agentic Control Plane for the enterprise.
Our platform enables organizations to deploy AI Employees that automate complex workflows across HR, Customer Support, Sales, Finance, and more — powered by Ema Fusion™ (a patented mixture-of-experts layer), GWE™ (our agentic orchestration engine), and the Enterprise Context Graph.
We work with the world’s largest enterprises — from Fortune 500 firms to fast-scaling tech companies — across industries that demand the highest standards of security, privacy, and regulatory compliance.
Our Trust Center trust. ema. ai reflects our commitment: SOC 2 Type II, HIPAA, GDPR, and a security-first architecture that supports on-prem and air-gapped deployments.
The Role
We are looking for a Security & Compliance Lead to own Ema’s entire security and compliance posture — both internal and customer-facing.
This is a critical, high-visibility role that sits at the intersection of enterprise compliance, cloud infrastructure security, and the rapidly evolving landscape of AI/ML-driven development.
You will report directly to the Head of Engineering and serve as the single point of accountability for how Ema secures its platform, earns customer trust, and stays ahead of regulatory requirements in the agentic AI space.
You will work closely with our Infrastructure team, Product Engineering, and directly with the Info Sec teams, CISOs, and compliance officers of our global enterprise clients.
What You Will Do
- Compliance & Regulatory Leadership
- Serve as the primary point of contact for customer Info Sec teams and CISOs during security reviews, vendor assessments, and due diligence cycles.
- Have high ownership in building and maintaining the security posture of the organization. Play a critical role in hiring and mentoring folks.
- Own and drive SOC 2 Type II, PCI DSS, Fed RAMP, ISO 27001/27701/27017/42001, DORA and UK Cyber Essentials Plus, HIPAA and GDPR compliance programs end-to-end — from gap analysis through audit readiness and certification maintenance.
- Build and maintain Ema’s compliance documentation, evidence repositories, and control frameworks. Keep our Trust Center trust. ema. ai current and credible.
- Navigate the emerging regulatory landscape for AI/ML systems — including AI governance frameworks, model risk management expectations, and data residency requirements across global markets.
- Security Posture & Architecture
- Define and enforce Ema’s internal and external security perimeters — covering cloud infrastructure, application security, API security, network segmentation, and access controls.
- Work closely with the Infrastructure team to harden production environments, implement zero-trust principles, and ensure secure multi-tenant and air-gapped deployment architectures.
- Establish and run vulnerability management, penetration testing, and incident response programs. Own the security incident lifecycle from detection through post-mortem.
- Evaluate and implement security tooling: SIEM, CSPM, SAST/DAST, secrets management, and runtime protection.
- Strong understanding of WAF. Expertise on Cloudflare, Akamai etc .. is beneficial.
- Exposure to enterprise security layers → workspace, identity providers.
- Dev Sec Ops & AI-Native SDLC
- Pioneer the Dev Sec Ops practice for an AI-first engineering org — embedding security into CI/CD pipelines, code review workflows, and deployment gates.
- Innovate on the SDLC for the age of AI-driven development: define guardrails for AI-generated code, secure model pipelines, protect training data integrity, and establish provenance tracking for agentic workflows.
- Secure the ML/Agentic stack specifically — model serving infrastructure, prompt injection defenses, agent-to-agent trust boundaries, and data exfiltration prevention in LLM-powered systems.
- Champion a security-aware engineering culture through training, threat modeling workshops, and lightweight governance that accelerates rather than blocks delivery.
- Enterprise Client Engagement
- Partner with Sales Engineering and Customer Success to support enterprise deals — completing security questionnaires, participating in client CISO reviews, and designing customer-specific security architectures.
- Work with global enterprise clients across regulated industries (financial services, healthcare, government) to meet their security and compliance requirements.
- Translate complex compliance requirements into engineering work, and communicate Ema’s security story with clarity and confidence to technical and executive audiences.
- What We Look For
- 8+ years of experience in security engineering, compliance, or Dev Sec Ops — with at least 3 years in a lead or senior IC role owning compliance programs.
- Deep, hands-on experience with SOC 2 Type II, PCI DSS, and Fed RAMP. Experience with HIPAA and GDPR is strongly preferred.
- Strong background in cloud security on GCP, Azure — including IAM, network security, container/Kubernetes security, and infrastructure-as-code security.
- Experience securing ML/AI systems is a significant plus — model pipelines, training data governance, inference security, and the unique threat surface of agentic/LLM systems.
- Track record of working directly with enterprise client security teams, CISOs, and auditors. Comfortable in high-stakes customer-facing conversations.
- Familiarity with modern Dev Sec Ops tooling: SAST/DAST (Snyk, Semgrep, etc.), CSPM (Wiz, Prisma), SIEM, secrets management (Vault), and CI/CD security integration.
- Strong written and verbal communication — you can write a clear security policy and present a compliance roadmap to a board audience.
- Bias toward action, pragmatism over perfection, and a builder’s mindset. You thrive in a fast-moving startup that ships to large enterprises.
- Nice to Have
- Relevant certifications: CISSP, CISM, Lead Auditor, CCSP, CCSK or equivalent.
- Experience building security programs from the ground up at a high-growth startup.
- Familiarity with AI governance frameworks (NIST AI RMF, EU AI Act, ISO 42001).
- Experience with on-premise / air-gapped deployment security for enterprise customers.
- Prior experience in a platform or infrastructure company serving regulated verticals.
Why Ema?
- Shape the security foundation of a category-defining AI platform — your decisions will directly impact how the world’s largest enterprises trust and adopt agentic AI.
- Work at the frontier of AI security — securing LLM-powered agents, agentic workflows, and ML infrastructure presents novel challenges you won’t find anywhere else.
- High-impact, high-visibility role with direct access to the Head of Engineering and enterprise CISOs.
- Well-funded company with a proven product, blue-chip enterprise customers, and a team that combines deep AI expertise with enterprise delivery discipline.
- Competitive compensation, equity, and the opportunity to build something that matters.
- #J-18808-Ljbffr
Security & Compliance Lead Arbeitgeber: Ema Unlimited
Ema ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern die Möglichkeit bietet, an der Spitze der KI-Technologie zu arbeiten und dabei eine bedeutende Rolle in der Transformation der Unternehmensproduktivität zu spielen. Mit einem dynamischen Arbeitsumfeld, das Innovation und Zusammenarbeit fördert, sowie umfangreichen Wachstums- und Entwicklungsmöglichkeiten, ist Ema der ideale Ort für Fachkräfte, die ihre Karriere im Bereich der Lösungenarchitektur vorantreiben möchten. Zudem profitieren Mitarbeiter von einer unterstützenden Unternehmenskultur und der Chance, mit führenden Investoren und Experten der Branche zusammenzuarbeiten.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Security & Compliance Lead erhalten könntest
✨Mit Compliance-Events in Kontakt treten
Besuche branchenspezifische Events und Konferenzen im Bereich Compliance, wie zum Beispiel die Compliance-Akademie oder Netzwerktreffen von Fachverbänden. Hier kannst du direkt mit Experten sprechen und eventuell sogar Ansprechpartner von Ema Unlimited treffen!
✨Zertifizierungen und Weiterbildungen nutzen
Schaue dir relevante Zertifizierungen oder Weiterbildungsmöglichkeiten an, die in der Compliance-Branche anerkannt sind. Wenn du zum Beispiel die CCEP oder ähnliche Qualifikationen hast, zeigt das Engagement und könnte dir einen Vorteil im Auswahlprozess bei Ema Unlimited verschaffen.
✨Jetzt auf die richtige Stelle bei Ema Unlimited bewerben!
Verpass nicht die Chance, dich direkt über unsere Website bei Ema Unlimited zu bewerben! Da wir oft auf unseren eigenen Kanälen nach Talenten suchen, stell sicher, dass du deine Bewerbung schnell einreichst – je früher, desto besser!
✨Globalen Compliance-Netzwerke beitreten
Tritt Online-Communities und Foren bei, die sich mit Compliance-Themen beschäftigen. Plattformen wie ComplianceNetzwerk oder LinkedIn-Gruppen können dir helfen, wertvolle Kontakte zu knüpfen und auf Stellenangebote aufmerksam zu werden. Diese Verbindung kann dir in Gesprächen bei Ema Unlimited den entscheidenden Vorteil verschaffen.
Wir glauben, dass du diese Fähigkeiten brauchst, um Security & Compliance Lead mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Kenn dein Compliance-ABC:Achte darauf, dass deine Bewerbung zeigt, dass du die relevanten Compliance-Vorgaben und Regularien beherrschst. Dies könnten z.B. ISO-Normen oder spezielle gesetzliche Anforderungen sein, die für Ema Unlimited wichtig sind. Wenn du relevante Zertifikate hast, zeig sie!
Lebenslauf mit klaren Nachweisen:Verstärke deinen Lebenslauf mit konkreten Beispielen, die deine Erfahrungen im Compliance-Bereich zeigen. Beleuchte deine Fähigkeiten zur Risikoanalyse und -bewertung, aber auch deine Erfahrungen in der Zusammenarbeit mit verschiedenen Abteilungen, die Compliance-Punkten unterliegen.
Motivation und Interesse ausschreiben:In deinem Bewerbungsschreiben solltest du nicht nur darstellen, was du kannst, sondern auch, warum du dich für die Compliance-Rolle bei Ema Unlimited interessierst. Zeige, dass du wirklich für die Themen brennst und bereit bist, dich stetig weiterzuentwickeln.
Zielgerichteter Kontakt:Falls du einen Vertreter von Ema Unlimited oder jemanden im Compliance-Team kennst, zögere nicht, ihn zu kontaktieren. Ein kurzes, freundliches E-Mail oder eine Nachricht kann dir zusätzliche Einblicke geben, die du in deiner Bewerbung nutzen kannst. Das zeigt Interesse und Initiative!
Wie man sich auf ein Vorstellungsgespräch bei Ema Unlimited vorbereitet
✨Vorbereitung auf Fachfragen zur Compliance
Bereite dich darauf vor, spezifische Fragen zu Compliance-Vorgaben, Gesetzen und ethischen Standards zu beantworten. Mach dich mit den neuesten Entwicklungen im Compliance-Bereich vertraut und sei bereit, konkrete Beispiele aus deinen Erfahrungen zu nennen, um deine Kenntnisse zu untermauern.
✨Den richtigen Umgang mit Compliance-Tools zeigen
Da Compliance oft mit speziellen Software-Tools und Datenanalyse verbunden ist, solltest du dich mit häufig genutzten Tools in der Branche vertraut machen. Sei bereit, Fragen zu beantworten, die deine Erfahrung mit diesen Tools und deine Fähigkeit, Daten zur Unterstützung von Compliance-Maßnahmen zu interpretieren, zeigen.
✨Motivation und Engagement für die Rolle
Zeige während des Gesprächs dein Interesse an den Auflagen und Standards der Branche. Arbeitgeber in der Compliance-Branche suchen nach Kandidaten, die motiviert sind und ein echtes Engagement zeigen, die Integrität des Unternehmens zu wahren und gute Praktiken zu fördern.
✨Beispiele für deine Problemlösungsfähigkeiten
Sei darauf vorbereitet, Situationen zu beschreiben, in denen du Compliance-Herausforderungen erfolgreich gemeistert hast. Beispiele aus der Praxis können dir helfen, deine Problemlösungsfähigkeiten und dein kritisches Denken zu demonstrieren. Zeige, wie du in schwierigen Situationen kreativ und effektiv Lösungen gefunden hast.