Security Assurance LeadActive$356K

The opportunity

Scale is powering the generative AI wave by providing the data and infrastructure for companies to build large-scale foundation models. AI is rapidly changing the world, and Scale is growing to meet that rapid demand across global markets, including accelerating public sector and commercial business.

What you'll do

  • Lead public sector compliance programs (e.g., FedRAMP HIGH, DoD SRG: IL4/IL5/IL6, NIST 800-53/800-171, CMMC, and RMF), owning controls mapping, gap analysis, evidence collection, ATO packages, and certification timelines, including coordination with 3PAOs and external assessors.

  • Oversee Security Risk Management A & A processes, including cloud system risk: assessments, POAM development and tracking, vulnerability management, STIG implementation, and security configuration oversight.

  • Drive cross-functional control implementation by partnering with product,: engineering, security, operations, legal, and people ops to deploy technical, administrative, and operational controls.

  • Set priorities and cadences for intake, evidence collection, remediation: tracking, and deadline management, and reporting program health and risks to the Head of Global Assurance.

  • Manage external relationships with auditors, assessors, certification bodies,: and regulatory counterparts to achieve and sustain compliance outcomes.

  • Maintain system security documentation and GRC tooling, including continuous: updates to security documentation and uploading control evidence to eMASS or Xacta throughout the monitoring phase.

What they're looking for

  • Lead compliance reviews for new products and features, and proactively advise: the business on emerging certification programs, regulatory changes, and evolving requirements.
  • Maintain and expand Scale's certification portfolio, including SOC 2, ISO: 27001, ISO 42001, and ISO 9001, working with the global GRC team on renewals and new certifications.
  • Support customer and stakeholder assurance activities, including security: questionnaires, due diligence responses, compliance input to bids, and customer-facing assurance discussions.
  • An active US Top Secret security clearance with minimum IAT Level 2: certification (Security +, CASP, or similar).