Sysdig logo
Sysdig

Trust & Assurance Lead

🕐 4 dias atrás📍 Flexible - USA🌍 Remoto💰 $160,000 - $200,000 USD

What you will do

You'll own how Sysdig proves its security claims — to auditors, to enterprise customers, and to regulators — and you'll rebuild that function as engineering rather than paperwork. You'll also build one program from nothing: AI assurance, covering both our own AI systems and the AI questions now arriving in every enterprise deal.

We maintain ISO 27001, ISO 27701, and SOC 2 Type II, and we're moving entirely off point-in-time assessments. Today, most evidence for those certifications is still collected by hand. Your job is to make it a pipeline output: controls that report their own state, validation running continuously against production, and an audit that becomes a query against something already running.

This role is customer-facing in a way most compliance roles are not. When a deal turns on a security answer, you're the person in the room. And it sits in Security Engineering deliberately, reporting to the Director of Security Engineering rather than into a governance function, because we think the answer to a control problem is usually to fix the control.

This is a senior individual contributor role with the latitude to design and build the program you wished existed. The Office of the CISO operates transparently, and we want our security team to publish and speak, so the work you do here becomes work the industry can use.

Responsibilities

  • Rebuild assurance as engineering. Instrument controls so they report their own state, express policy as code, and detect control drift in near real time.
  • Own the certification program end-to-end. ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II: scope, readiness, fieldwork, population and sampling requests, and remediation.
  • Drive down the cost of proof. Labor per audit cycle should fall year over year.
  • Build AI assurance from nothing. ISO 42001, the NIST AI RMF, and the EU AI Act obligations treated as an engineering problem.
  • Own AI third-party risk. Decide what we accept, and be able to show why.
  • Run customer and partner assurance. Lead high-consequence engagements yourself.
  • Write specifications that settle hard questions. Access paths, separation of duties, administrative transparency, tenant isolation.
  • Enable the field. Build for sales engineers and account teams to answer most security questions without you in the room.
  • Own the integrity of our public claims. Catch stale reports and overstated scope before a customer does.
  • Push risk into engineering. Turn findings into commitments with owners and dates.
  • Be customer zero for assurance. Use Sysdig's own platform to produce evidence.
  • Use agents to scale the function itself. Evidence generation, questionnaire drafting, control validation, gap analysis.
  • Represent Sysdig externally. Engage customer security teams and publish on the work.

What you will bring with you

  • Experience running a certification and audit program end-to-end for a cloud or SaaS company.
  • Experience shipping code or automation in service of a control objective — Python, Go, Terraform, CI pipelines, or an API.
  • Genuine depth in at least two of SOC 2, ISO 27001, ISO 27701, ISO 42001.
  • Experience demonstrating compliance with operational evidence.
  • Cloud-native technical foundation: Kubernetes, containers, at least one major cloud.
  • Experience with agentic tooling and opinions about where it fails.
  • Ability to differentiate between significant findings and those that only matter to an auditor.
  • Credibility with a customer's CISO and engineers.
  • Energized by problems where established principles don't fully apply.

What we look for

  • Built an assurance or compliance function that didn't exist before.
  • Worked on AI governance frameworks while the requirements were still moving.
  • Built continuous controls monitoring or GRC engineering tooling.
  • Experience working assurance at a security vendor.
  • Experience with public sector requirements, regulated financial services, or EU data protection.
  • A track record of conference speaking, published research, or contribution to a control framework or open standard.

Benefits

  • Extra days off to prioritize your well-being.
  • 401(k) Retirement Savings Plan with a 3% company match.
  • Maternity and Parental Leave.
  • Mental health support for you and your family through the Modern Health app.
  • Full health benefits package for you and your family.

🇧🇷 Essa vaga exige inglês. Você está pronto?

A DevSpeak Academy prepara desenvolvedores brasileiros para conquistar vagas internacionais. Domine o inglês técnico com professores que entendem o mundo dev.

Conheça a DevSpeak Academy