FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in managing certification programs, including SOC 2 and ISO 27001, while ensuring compliance with regulatory standards such as GDPR and NIS2. Proficient in evidence gathering, vendor management, and maintaining security documentation across various platforms.
Highest-signal resume keywords
SOC 2 Certification ManagementISO 27001 ComplianceEvidence Gathering DisciplineVendor Review Process ManagementGRC Platform Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Certification Programme ManagementAudit Cycle ExperienceSecurity Questionnaire WritingSubprocessor List MaintenanceRisk Register Management
Soft Skills
Judgment for EscalationPlain Writing Skills
Tools & Technologies
GRC PlatformsVantaDrataMycroftSegregato
Industry Keywords
ISO 42001NIS2GDPRFinancial ServicesTelco Buyers
About the role
Key responsibilities & impact- Own the Q&A library mapped to ISO 27001, SOC 2, ISO 42001, NIS2, and GDPR
- Govern ownership, approval status, evidence links, confidentiality classifications, and review dates for the Q&A library
- Maintain consistency across the Q&A library, trust center, Trust Center portal, policies, and engineering practices
- Manage customer security reviews from questionnaire intake through delivery
- Validate unverified answers with Security, Engineering, or Product
- Keep public trust-center and NDA-gated Trust portal document sets current
- Run the annual audit and certification programme, including SOC 2 Type II renewal, ISO 27001 and ISO 42001 surveillance, NIS2 assessment, penetration testing and retesting, and customer right-to-audit requests
- Gather evidence and liaise with the DPO and auditors
- Manage audit findings, remediation, and management assertions
- Operate the ISMS and AIMS with the Security Lead, including the risk register, statement of applicability, policy lifecycle, access reviews, internal audit, management review, and security steering cadence
- Own vendor policy and third-party risk processes, including intake, tiering, due diligence, DPA terms, AI-provider data-retention and no-training commitments, approval, re-review, and offboarding
- Manage subprocessor reviews, customer notifications, DPA updates, and portal updates
- Report to the Head of Engineering and work daily with the Security Lead
Requirements
What you’ll need- Experience running a certification programme end to end through a real audit cycle, including SOC 2, ISO 27001, or equivalent
- Ability to write precise, evidenced, and honest security questionnaire answers
- Experience building or running a third-party/vendor review process
- Experience maintaining an accurate subprocessor list under contractual notice obligations
- Evidence-gathering discipline and audit-readiness
- Judgment about escalation to Engineering, Security, or Legal
- Ability and willingness to use AI tooling and agents
- Plain writing skills
- Experience with financial services or telco buyers is a plus
- Experience with AI governance or ISO 42001 is a plus
- Experience with GRC platforms such as Vanta, Drata, Mycroft, Segregato, or similar is a plus
- Experience working on the vendor side as a processor answering to controllers is a plus
Benefits
Comp & perks- Unlimited AI budget
- Autonomy to do your best work
- Professional development and mentoring autonomy
- Ability to fly out to talk to important customers
- Real AI product with real enterprise customers
