SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 160,000 - 200,000 / annual
Sysdig is seeking a Trust & Assurance Lead to own how the company proves its security claims to auditors, enterprise customers, and regulators. This is a senior individual contributor role reporting to the Director of Security Engineering, deliberately positioned within Security Engineering rather than a governance function.
You will rebuild the assurance function as engineering rather than paperwork. Key responsibilities include:
- Rebuild assurance as engineering: instrument controls to report their own state, express policy as code, and detect control drift in near real time. Route failures to the team that owns the system rather than a spreadsheet.
- Own the certification program end-to-end: ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II, including scope, readiness, fieldwork, population and sampling requests, and remediation. Manage ISMS and PIMS artifacts and quarterly security objectives. Run independent internal audits and coordinate with external assessors.
- Drive down the cost of proof: labor per audit cycle should fall year over year as engineering work scales the function.
- Build AI assurance from nothing: ISO 42001, NIST AI RMF, and EU AI Act obligations treated as an engineering problem. Define and instrument controls for model and agent behavior, data handling in AI systems, and AI-assisted development.
- Own AI third-party risk: evaluate and document vendor risk, particularly AI-labeled vendors.
- Run customer and partner assurance: manage the trust profile, questionnaire pipeline, intake channel, and document library. Lead high-consequence engagements in regulated financial services, pharma, aviation, and sovereign programs.
- Write specifications that settle hard questions: access paths, separation of duties, administrative transparency, tenant isolation—defensible under audit.
- Enable the field: build tools and documentation so sales engineers and account teams can answer most security questions independently.
- Own the integrity of public claims: manage the certifications page, trust center, and marketplace listings. Catch stale reports and overstated scope before customers do.
- Push risk into engineering: turn findings into commitments with owners and dates, or formal management responses. Escalate when risk should not be accepted.
- Be customer zero for assurance: use Sysdig's own platform to produce evidence in production before customers do, then influence product roadmap based on gaps.
- Use agents to scale the function: automate evidence generation, questionnaire drafting, control validation, and gap analysis.
- Represent Sysdig externally: engage customer security teams on significant matters and publish/speak on the work.
Requirements:
- Have run a certification and audit program end-to-end for a cloud or SaaS company, owning the outcome rather than just coordination.
- Have shipped code or automation in service of a control objective (Python, Go, Terraform, CI pipelines, or API integration with compliance platforms). Must have hands-on technical experience.
- Have genuine depth in at least two of: SOC 2, ISO 27001, ISO 27701, ISO 42001, with working knowledge of the rest.
- Have demonstrated compliance to enterprise customers or auditors using operational evidence, not just policy documents.
- Have a cloud-native technical foundation: Kubernetes, containers, at least one major cloud, and understanding of runtime security.
- Are already building with agentic tooling and have opinions about where it fails.
- Can distinguish findings that matter from those that only matter to auditors, and are willing to voice this in the room.
- Are credible with both CISOs and engineers, able to communicate effectively across audiences.
- Are energized by problems where established principles don't fully apply.
Desirable experience:
- Built an assurance or compliance function from scratch at a company where much was self-defined.
- Worked on AI governance frameworks (ISO 42001, EU AI Act, NIST AI RMF) while requirements were still evolving.
- Built continuous controls monitoring or GRC engineering tooling.
- Worked assurance at a security vendor.
- Experience with public sector requirements, regulated financial services, or EU data protection.
- Track record of conference speaking, published research, or contribution to control frameworks or open standards.