Skip to content
Scale AIScale AI

Technical Assurance Lead

Lead public sector compliance and Security Risk Management A&A programs for Scale's AI infrastructure products. Own FedRAMP, DoD IL4/5/6, NIST, CMMC, and RMF controls, gap analysis, evidence collection, POAMs, and external audits while partnering cross-functionally with engineering, security, and legal teams.

About the job

Responsibilities

  • Lead public sector compliance programs (e.g., FedRAMP HIGH, DoD SRG IL4/IL5/IL6, NIST 800-53/800-171, CMMC, and RMF), owning controls mapping, gap analysis, evidence collection, ATO packages, and certification timelines, including coordination with 3PAOs and external assessors.
  • Oversee Security Risk Management A&A processes, including cloud system risk assessments, POAM development and tracking, vulnerability management, STIG implementation, and security configuration oversight.
  • Drive cross-functional control implementation by partnering with product, engineering, security, operations, legal, and people ops to deploy technical, administrative, and operational controls.
  • Set priorities and cadences for intake, evidence collection, remediation tracking, and deadline management, and reporting program health and risks to the Head of Global Assurance.
  • Manage external relationships with auditors, assessors, certification bodies, and regulatory counterparts to achieve and sustain compliance outcomes.
  • Maintain system security documentation and GRC tooling, including continuous updates to security documentation and uploading control evidence to eMASS or Xacta throughout the monitoring phase.
  • Lead compliance reviews for new products and features, and proactively advise the business on emerging certification programs, regulatory changes, and evolving requirements.
  • Maintain and expand Scale's certification portfolio, including SOC 2, ISO 27001, ISO 42001, and ISO 9001, working with the global GRC team on renewals and new certifications.
  • Support customer and stakeholder assurance activities, including security questionnaires, due diligence responses, compliance input to bids, and customer-facing assurance discussions.

Requirements

  • Active US Top Secret security clearance with minimum IAT Level 2 certification (Security+, CASP, or similar).
  • 7+ years of experience in security compliance, technology audit, GRC, cloud security, or related roles, with meaningful exposure to the public sector markets.
  • Experience implementing and maintaining some of the following frameworks and standards: FedRAMP, DoD Cloud Computing SRG, NIST 800-171, NIST 800-53, CMMC, NIST 800-53.
  • Deep familiarity with one or more of: STIG/RMF policy knowledge & implementation, including validating compliance via ACAS and other relevant tests, ISO 27001, ISO 9001, ISO 42001, SOC 2, or equivalent frameworks.
  • Experience in project management and taking projects from conception to launch.
  • Ability to translate between business and technical risk and communicate clearly to leadership.
  • Experience managing controls mapping, evidence collection, remediation tracking, and audit coordination across distributed engineering and infrastructure teams.
  • Experience with cloud environments (one or more of: AWS, Azure, GCP) and the ability to assess cloud architecture against compliance requirements.
  • Strong communication skills, sound judgment on escalation, and the ability to operate autonomously while maintaining alignment with a global program.

Nice-to-Haves

  • Bachelor’s degree in accounting, information systems, computer science, or a related field.
  • Relevant certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor, ISO 42001 Internal Auditor, or CCSP.
  • Experience at a high-growth technology company.

Skills

FedRAMP, Dod Srg, Nist 800-53, Nist 800-171, Cmmc, Rmf, Stig, Poam, Emass, Xacta, AWS, Azure, GCP, ISO 27001, SOC 2

Idme

Idme

McLean, VA

SOC Lead
$96k+/yrOn-site8+ YOESecurity Engineering

Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.

ConductorOne

ConductorOne

San Francisco, CA
Senior Security Engineer
$100k+/yrRemote5+ YOESecurity Engineering

Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.

Mercor

Mercor

San Francisco, CA

Security GRC Lead
$350k+/yrOn-site7+ YOESecurity Engineering

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.

Anthropic

Anthropic

San Francisco, CA
Lead, Security Controls Assurance - SOX
$410k+/yrHybridSecurity Engineering

Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.

Discord

Discord

United States

Senior Platform Security Engineer
$196k+/yrOn-site5+ YOESecurity Engineering

Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.