The opportunity
Scale is powering the generative AI wave by providing the data and infrastructure for companies to build large-scale foundation models. AI is rapidly changing the world, and Scale is growing to meet that rapid demand across global markets, including accelerating public sector business across EMEA.
What you'll do
Lead region-specific assurance programs across the GCC and UK, including: Qatar NCSA National Information Assurance (NIA), KSA NCA Essential Cybersecurity Controls (ECC), UAE DESC Information Security Regulation (ISR), and UK Cyber Essentials Plus, Defence Cyber Certification (DCC), and NCSC Secure by Design (SdB). You will own controls mapping, evidence collection, gap analysis, certification timelines, and submission management for each, working with accredited external assessors where required.
Work with the global GRC team to maintain and renew Scale's existing: certifications and obtain new ones, including SOC 2, ISO 27001, ISO 42001, and ISO 9001. You will also own their extension to EMEA and international operations, including for NATO-aligned defence tenders.
Design and maintain EMEA-specific controls, adapting Scale's global controls: framework to sovereign regulatory and customer requirements, including data residency and sector-specific requirements (e.g., health sector), identifying where existing controls satisfy local standards and where new controls or evidence artifacts are needed.
Set priorities and operating cadences for EMEA assurance workflows, including: intake, evidence collection, control owner follow-up, remediation tracking, and deadline management, reporting progress through Scale's global assurance dashboards.
Support EMEA public sector customer assurance activities, including security: questionnaires, compliance due diligence responses, customer-facing assurance discussions, and compliance input to bid and capture processes where assurance readiness is a procurement gate.
Partner with Legal on EMEA contract-driven assurance obligations, data: protection and AI governance compliance intersections (e.g., GDPR, Qatar PDPPL, EU AI Act), and sensitive escalations involving sovereign regulators.
What they're looking for
- Manage relationships with EMEA-based external auditors, assessors,: certification bodies, and regulatory counterparts.
- Support internal and external audits across EMEA and report into the Head of: Global Assurance on program health, key risks, certification timelines, and regional regulatory developments.
- + years of experience in cybersecurity compliance, GRC, public sector: assurance, IT audit, cloud security, or related roles, with meaningful exposure to EMEA markets.
- Experience executing government or public sector assurance programs in the: UK, EU, or GCC, including working with external certification bodies, government assessors, or authorizing officials.