- Own how Sysdig proves its security claims to auditors, enterprise customers, and regulators
- Rebuild assurance as engineering by instrumenting controls, expressing policy as code, and detecting control drift
- Own the ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II certification program end-to-end
- Own ISMS and PIMS artifacts and quarterly security objectives
- Run independent internal audits and external assessors
- Reduce labor per audit cycle year over year
- Build Sysdig's AI assurance program covering its AI systems and enterprise AI requirements
- Define and instrument controls for model and agent behavior, AI data handling, and AI-assisted development
- Own AI third-party risk
- Run customer and partner assurance, including trust profiles, questionnaires, intake, and document libraries
- Lead high-consequence assurance engagements for regulated financial services, pharmaceutical, aviation, and sovereign or region-specific programs
- Write defensible specifications for access paths, separation of duties, administrative transparency, and tenant isolation
- Enable sales engineers and account teams to answer most security questions
- Maintain the integrity of public security claims, certifications pages, trust center, and marketplace listings
- Push risk findings into engineering commitments or formal management responses
- Use Sysdig's platform in production to generate evidence and influence the product roadmap
- Use agents to scale evidence generation, questionnaire drafting, control validation, and gap analysis
- Engage customer security teams and represent Sysdig externally through publishing and speaking
Requirements
- Have run a certification and audit program end-to-end for a cloud or SaaS company, owning the outcome rather than the coordination
- Have shipped code or automation in service of a control objective, using Python, Go, Terraform, CI pipelines, or an API wired into a compliance platform
- Have genuine depth in at least two of SOC 2, ISO 27001, ISO 27701, ISO 42001, with working knowledge of the rest
- Have sat across from an enterprise customer's security team or an auditor and demonstrated compliance with operational evidence
- Have a cloud-native technical foundation: Kubernetes, containers, at least one major cloud, and enough understanding of runtime security
- Are already building with agentic tooling and have opinions about where it fails
- Can distinguish significant findings from findings that only matter to an auditor
- Are credible with a customer's CISO and with engineers
- Built an assurance or compliance function that did not exist before
- Worked on AI governance frameworks including ISO 42001, the EU AI Act, and NIST AI RMF
- Built continuous controls monitoring or GRC engineering tooling
- Worked assurance at a security vendor
- Experience with public sector requirements, regulated financial services, or EU data protection
- Track record of conference speaking, published research, or contribution to a control framework or open standard
Core Competencies
Demonstrates expertise in managing end-to-end certification and audit programs for cloud or SaaS environments, with a strong focus on ISO 27001, SOC 2, and AI governance frameworks. Capable of engaging with enterprise security teams and auditors while maintaining compliance and integrity of security claims.
Highest-signal resume keywords
- End-To-End Certification Management
- Python Programming
- ISO 27001 Compliance
- Cloud-Native Security
- AI Governance Frameworks
ATS Optimization Keywords
Hard Skills
- Python
- Go
- Terraform
- CI Pipelines
- Kubernetes
- Containers
- Continuous Controls Monitoring
- GRC Engineering Tooling
- Operational Evidence Demonstration
- Control Objective Automation
Soft Skills
- Credibility with CISO
- Effective Communication
- Engagement with Security Teams
- Leadership in Assurance Programs
- Analytical Problem-Solving
Certifications & Qualifications
- ISO 27001:2022
- ISO 27701:2019
- SOC 2 Type II
- ISO 42001
Industry Keywords
- Regulated Financial Services
- Pharmaceutical Compliance
- Public Sector Requirements
- EU Data Protection
- AI-Assisted Development
Tools & Technologies
- Compliance Platforms
- Sysdig Platform
- Agentic Tooling
- Control Validation Tools
- Evidence Generation Tools
#J-18808-Ljbffr
Trust & Assurance Lead Arbeitgeber: Jobtailor
Als Front Office Supervisor in unserem dynamischen Team bieten wir Ihnen die Möglichkeit, in einem unterstützenden und freundlichen Arbeitsumfeld zu wachsen. Wir legen großen Wert auf die berufliche Entwicklung unserer Mitarbeiter und bieten regelmäßige Schulungen sowie die Chance, Verantwortung zu übernehmen. Unsere Lage ermöglicht es Ihnen, Teil einer lebendigen Gemeinschaft zu sein, während Sie gleichzeitig die Standards unseres Franchise-Partners einhalten und unseren Gästen einen unvergesslichen Aufenthalt bieten.