Trust & Assurance Lead
Straight from Sysdig’s careers page. Apply on the company site — no recruiter, no middleman.
Trust & Assurance Lead
Team: CISO Security & Compliance
Location: Flexible - USA
Commitment: Regular - Full Time
Workplace Type: remote
What you will do
- Rebuild assurance as engineering. Instrument controls so they report their own state, express policy as code, and detect control drift in near real time. Route failures to the team that owns the system, not a spreadsheet.
- Own the certification program end-to-end. ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II: scope, readiness, fieldwork, population and sampling requests, and remediation. You own the ISMS and PIMS artifacts and the quarterly security objectives, and you run the independent internal audit and the external assessors.
- Drive down the cost of proof. Labor per audit cycle should fall year over year. That number shows the engineering work is real, and it is the one we will hold you to.
- Build AI assurance from nothing. ISO 42001, the NIST AI RMF, and the EU AI Act obligations that actually apply to us, treated as an engineering problem rather than a documentation exercise. Define and instrument controls for model and agent behavior, for data handling inside AI systems, and for AI-assisted development in our own engineering organization.
- Own AI third-party risk. Most new vendor risk now arrives wearing an AI label. Decide what we accept, and be able to show why.
- Run customer and partner assurance. The trust profile, questionnaire pipeline, intake channel, and frequently requested document library. Lead the high-consequence engagements yourself: regulated financial services, pharmaceutical, aviation, and sovereign or region-specific programs, including third-party audits routed through a partner.
- Write the specifications that settle hard questions. Access paths, separation of duties, administrative transparency, tenant isolation. In writing, and defensible under audit rather than persuasive on a call.
- Enable the field. Sales engineers and account teams should answer most security questions without you in the room. Build for that, then measure whether it happened.
- Own the integrity of our public claims. The certifications page, the trust center, marketplace listings, and anything a customer can cite back to us. Catch stale reports and overstated scope before a customer does. This is a brand-risk control, not compliance administration.
- Push risk into engineering. Turn findings into commitments with owners and dates, or into a formal management response when the answer is to accept the risk. Escalate when the answer should be no.
- Be customer zero for assurance. Where Sysdigs own platform can produce the evidence, use it in production before customers do, then tell product where it falls short. Youll have as much roadmap influence as youre willing to take.
- Use agents to scale the function itself. Evidence generation, questionnaire drafting, control validation, gap analysis. If an assurance task is repeatable, it should run without you.
- Represent Sysdig externally. Engage customer security teams on matters of significance, and publish and speak on the work — encouraged, resourced, and supported.
Youll own how Sysdig proves its security claims — to auditors, to enterprise customers, and to regulators — and youll rebuild that function as engineering rather than paperwork. Youll also build one program from nothing: AI assurance, covering both our own AI systems and the AI questions now arriving in every enterprise deal.
We maintain ISO 27001, ISO 27701, and SOC 2 Type II, and were moving entirely off point-in-time assessments. Today, most evidence for those certifications is still collected by hand. Your job is to make it a pipeline output: controls that report their own state, validation running continuously against production, and an audit that becomes a query against something already running.
This role is customer-facing in a way most compliance roles are not. When a deal turns on a security answer, youre the person in the room. And it sits in Security Engineering deliberately, reporting to the Director of Security Engineering rather than into a governance function, because we think the answer to a control problem is usually to fix the control.
This is a senior individual contributor role with the latitude to design and build the program you wished existed. The Office of the CISO operates transparently, and we want our security team to publish and speak, so the work you do here becomes work the industry can use.
What you will bring with you
- Have run a certification and audit program end-to-end for a cloud or SaaS company, owning the outcome rather than the coordination
- Have shipped code or automation in service of a control objective — Python, Go, Terraform, CI pipelines, or an API wired into a compliance platform. We are not hiring a software engineer, and we are not hiring someone who has never opened a terminal
- Have genuine depth in at least two of SOC 2, ISO 27001, ISO 27701, ISO 42001, with working knowledge of the rest
- Have sat across from an enterprise customers security team, or an auditor, and been able to demonstrate compliance with operational evidence rather than only with a policy document
- Have a cloud-native technical foundation: Kubernetes, containers, at least one major cloud, and enough understanding of runtime security to ask a good question about it
- Are already building with agentic tooling and have opinions about where it fails
- Can tell a finding that matters from one that only matters to an auditor, and are willing to say so in the room
- Are credible with a customers CISO and with the engineers youre asking to change how they work, without changing register much between them
- Are energized rather than unsettled by problems where established principles dont fully apply
What we look for
- Built an assurance or compliance function that didnt exist before, at a company where much of it was theirs to define
- Worked on AI governance frameworks — ISO 42001, the EU AI Act, NIST AI RMF — while the requirements were still moving
- Built continuous controls monitoring or GRC engineering tooling, including cases where you concluded the tooling was the wrong answer
- Worked assurance at a security vendor, where the customers security team reads the answers closely
- Experience with public sector requirements, regulated financial services, or EU data protection
- A track record of conference speaking, published research, or contribution to a control framework or open standard
When you join Sysdig, you can expect
- Extra days off to prioritize your well-being
- 401(k) Retirement Savings Plan with a 3% company match
- Maternity and Parental Leave
- Mental health support for you and your family through the Modern Health app
- Full health benefits package for you and your family
Similar remote jobs
More like this →

Starling Bank
Senior Infrastructure Engineer (GCP)


Discover More than 100,000 Hidden Remote Jobs Before Everyone Else
Unlock All Remote Jobs Today
Simple pricing. Big savings on Quarterly and Yearly.
Monthly Access
- Instant access to fresh remote jobs from 500+ companies
- New opportunities added hourly, often 3-7 days before anywhere else
- Advanced filtering by role type, stack, pay, and location
- Priority customer support
Yearly Access
- Everything in Monthly
- Save $169 (~74%) vs paying monthly
- Average job search takes ~6 months - get covered for the whole journey
- Less than the cost of one lunch per month for competitive advantage
- Equivalent to just ~$4.92/month