FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in managing compliance programs and audits, particularly SOC 2 and ISO 27001, while effectively communicating security and compliance topics to diverse audiences. Proficient in automating GRC workflows and translating regulatory requirements into actionable controls.
Highest-signal resume keywords
GRC ManagementSOC 2 ComplianceISO 27001 ExperienceSecurity AssuranceProject Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
GRC AutomationSecurity QuestionnairesCompliance FrameworksCloud Security ControlsRisk ManagementEvidence CollectionControl DesignVendor Risk ManagementTechnical Architecture EvaluationIncident Response
Soft Skills
Strong Communication SkillsCritical EvaluationCuriositySound JudgmentProject Coordination
Tools & Technologies
GRC PlatformsAPIsScriptsIntegrationsTrust-Center Platforms
Certifications & Qualifications
CISSPCISACISMCRISCCCSKISO 27001 Lead Implementer/Auditor
Industry Keywords
SaaSCloud SecurityFintechHealthcareGDPRCCPA/CPRAHIPAAPCI DSSNIST CSFNIST 800-53
Tech Stack
Tools & technologiesCloud
About the role
Key responsibilities & impact- Build the process to own and complete customer security questionnaires, assessments, and due-diligence requests
- Join customer and prospect calls to explain the company’s security posture, controls, architecture, and risk-management practices
- Build and maintain reusable trust materials, including standard responses, evidence packages, security documentation, and trust-center content
- Manage compliance programs and audits such as SOC 2 and ISO 27001 from readiness through evidence collection, testing, remediation, and ongoing monitoring
- Automate evidence collection, control monitoring, questionnaire responses, and repetitive GRC workflows
- Maintain policies, risk registers, control mappings, vendor reviews, and remediation plans
- Partner with Product, Engineering, IT, Legal, Sales, and Customer Success on security and compliance requirements
- Translate regulatory, contractual, and customer requirements into practical product and operational controls
- Participate in product design and roadmap discussions, identifying control requirements and recommending secure, scalable, and usable solutions
- Track emerging customer expectations and compliance requirements and help prioritize security-program improvements
- Define metrics showing the effectiveness, efficiency, and business impact of the GRC and customer-trust program
Requirements
What you’ll need- Experience in GRC, security assurance, customer trust, compliance, security engineering, or a related field
- Hands-on experience completing customer security questionnaires and supporting customer security reviews
- Strong written and verbal communication skills, including explaining technical and compliance topics clearly to technical and non-technical audiences
- Experience managing or supporting SOC 2, ISO 27001, NIST CSF, NIST 800-53, or similar frameworks
- Working knowledge of SaaS and cloud security controls, including identity and access management, encryption, logging, vulnerability management, secure development, incident response, business continuity, and vendor risk
- Ability to evaluate evidence critically rather than treating compliance as a checklist
- Strong project-management skills and comfort coordinating work across multiple teams
- Interest in using APIs, scripts, integrations, AI, or GRC platforms to reduce manual work
- Curiosity about product design and building controls into systems from the beginning
- Sound judgment balancing security, customer commitments, usability, and business needs
- Experience at startups, B2B SaaS, cloud, infrastructure, fintech, healthcare, or other security-conscious technology companies (optional)
- Familiarity with GDPR, CCPA/CPRA, HIPAA, PCI DSS, or FedRAMP (optional)
- Experience with GRC automation, trust-center, or questionnaire-management platforms (optional)
- Ability to read technical architecture diagrams, audit logs, configurations, and code to validate control design and evidence (optional)
- Experience designing product-level controls (optional)
- Relevant certifications such as CISSP, CISA, CISM, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor; certifications are helpful but not required
Benefits
Comp & perks- Inclusive workplace committed to welcoming, respecting, and empowering every team member
- Equal opportunity employer
- Workplace free from discrimination and harassment
