Trust & Assurance Lead
At Sysdig , we believe cloud security isn't a compromise - it's a promise. From the start, our mission has been clear: to help organizations secure innovation in the cloud, the right way.
We created Falco, the open standard for cloud threat detection, and continue to lead the cloud security market with runtime insights, open innovation, and agentic Al. Creators of technology trusted by over 60% of the Fortune 500, Sysdig gives teams the real-time clarity to move fast and defend what matters most.
Culture matters here. We believe diversity fuels stronger ideas, and open dialogue drives sharper decisions. Recognized as a Best Place to Work and one of Deloitte's fastest-growing companies for the past 5 years, we're here to raise the standard for what cloud security and workplace culture should be.
If you have the passion to dig deeper, the desire to challenge convention, and the curiosity to build something better, Sysdig is the right place for you.
What you will do
You'll own how Sysdig proves its security claims โ to auditors, to enterprise customers, and to regulators โ and you'll rebuild that function as engineering rather than paperwork. You'll also build one program from nothing: AI assurance, covering both our own AI systems and the AI questions now arriving in every enterprise deal.
We maintain ISO 27001, ISO 27701, and SOC 2 Type II, and we're moving entirely off point-in-time assessments. Today, most evidence for those certifications is still collected by hand. Your job is to make it a pipeline output: controls that report their own state, validation running continuously against production, and an audit that becomes a query against something already running.
This role is customer-facing in a way most compliance roles are not. When a deal turns on a security answer, you're the person in the room. And it sits in Security Engineering deliberately, reporting to the Director of Security Engineering rather than into a governance function, because we think the answer to a control problem is usually to fix the control.
This is a senior individual contributor role with the latitude to design and build the program you wished existed. The Office of the CISO operates transparently, and we want our security team to publish and speak, so the work you do here becomes work the industry can use.
- Rebuild assurance as engineering. Instrument controls so they report their own state, express policy as code, and detect control drift in near real time. Route failures to the team that owns the system, not a spreadsheet.
- Own the certification program end-to-end. ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II: scope, readiness, fieldwork, population and sampling requests, and remediation. You own the ISMS and PIMS artifacts and the quarterly security objectives, and you run the independent internal audit and the external assessors.
- Drive down the cost of proof. Labor per audit cycle should fall year over year. That number shows the engineering work is real, and it is the one we will hold you to.
- Build AI assurance from nothing. ISO 42001, the NIST AI RMF, and the EU AI Act obligations that actually apply to us, treated as an engineering problem rather than a documentation exercise. Define and instrument controls for model and agent behavior, for data handling inside AI systems, and for AI-assisted development in our own engineering organization.
- Own AI third-party risk. Most new vendor risk now arrives wearing an AI label. Decide what we accept, and be able to show why.
- Run customer and partner assurance. The trust profile, questionnaire pipeline, intake channel, and frequently requested document library. Lead the high-consequence engagements yourself: regulated financial services, pharmaceutical, aviation, and sovereign or region-specific programs, including third-party audits routed through a partner.
- Write the specifications that settle hard questions. Access paths, separation of duties, administrative transpa
Get remote jobs like this by email
One weekly digest. No spam, unsubscribe anytime.