Назад
Company hidden
4 дня назад

Trust & Assurance Lead (AI)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Trust & Assurance Lead (AI) (Security Compliance): Rebuilding assurance as an engineering function through continuous controls monitoring, automated evidence pipelines, and end-to-end certification programs with an accent on ISO, SOC 2, AI governance, and cloud-native security. Focus on designing AI assurance for ISO 42001, the NIST AI RMF, and the EU AI Act, reducing audit effort, and supporting high-consequence customer security engagements.

Location: Flexible - USA; remote

Company

hirify.global provides a cloud-native security platform and operates a security engineering function responsible for customer, regulatory, and enterprise assurance.

What you will do

  • Rebuild assurance as an engineering function with policy-as-code, continuously validated controls, near-real-time drift detection, and automated evidence pipelines.
  • Own ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II certification programs, including scope, readiness, audits, assessments, remediation, and ISMS/PIMS artifacts.
  • Build hirify.global's AI assurance program around ISO 42001, the NIST AI RMF, and applicable EU AI Act obligations.
  • Lead AI third-party risk, customer and partner assurance, security questionnaires, trust-center content, and high-consequence regulated engagements.
  • Translate security findings into engineering commitments, specifications, risk decisions, and defensible public claims.
  • Use agents and hirify.global's own platform to automate evidence generation, questionnaire drafting, control validation, and gap analysis, while representing hirify.global externally.

Requirements

  • End-to-end certification and audit program experience in a cloud or SaaS company.
  • Hands-on automation or code experience supporting control objectives, using technologies such as Python, Go, Terraform, CI pipelines, or compliance-platform APIs.
  • Deep expertise in at least two of SOC 2, ISO 27001, ISO 27701, and ISO 42001, with working knowledge of the others.
  • Cloud-native foundation including Kubernetes, containers, at least one major cloud, and runtime security.
  • Experience demonstrating operational compliance to enterprise security teams or auditors.
  • Must be able to work remotely from the USA.

Nice to have

  • Experience building an assurance or compliance function from the ground up.
  • Experience with AI governance frameworks, continuous controls monitoring, or GRC engineering tooling.
  • Experience at a security vendor or with public-sector, regulated financial-services, or EU data-protection requirements.
  • Conference speaking, published research, or contributions to a control framework or open standard.

Culture & Benefits

  • Remote work with a transparent Office of the CISO.
  • Support for publishing and speaking about assurance and security engineering work.
  • Extra days off and mental health support through the Modern Health app.
  • 401(k) retirement savings plan with a 3% company match.
  • Full health benefits and maternity and parental leave.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →