Skip to content
Scale AIScale AI

EMEA Assurance Lead

Leads EMEA cybersecurity assurance programs for public-sector and commercial operations, owning regional controls, certifications, audits, and customer assurance outcomes. Requires 7+ years in cybersecurity compliance, GRC, IT audit, cloud security, or related work, with experience across UK, EU, or GCC frameworks.

About the job

Responsibilities

  • Lead region-specific assurance programs across the GCC and UK, including Qatar NCSA National Information Assurance (NIA), KSA NCA Essential Cybersecurity Controls (ECC), UAE DESC Information Security Regulation (ISR), UK Cyber Essentials Plus, Defence Cyber Certification (DCC), and NCSC Secure by Design (SdB).
  • Own controls mapping, evidence collection, gap analysis, certification timelines, and submission management, working with accredited external assessors where required.
  • Maintain and renew SOC 2, ISO 27001, ISO 42001, and ISO 9001 certifications, including extensions to EMEA and international operations and NATO-aligned defence tenders.
  • Design and maintain EMEA-specific controls for sovereign regulatory, data residency, and sector-specific requirements.
  • Manage assurance intake, evidence collection, control-owner follow-up, remediation tracking, deadlines, dashboards, and reporting.
  • Support public-sector customer assurance activities, including security questionnaires, compliance due diligence, assurance discussions, and bid and capture processes.
  • Partner with Legal on contract-driven assurance, data protection, AI governance, GDPR, Qatar PDPPL, and EU AI Act matters.
  • Manage relationships with auditors, assessors, certification bodies, and regulatory counterparts.
  • Support internal and external audits and report program health, risks, timelines, and regulatory developments.

Requirements

  • 7+ years of experience in cybersecurity compliance, GRC, public-sector assurance, IT audit, cloud security, or related roles, with meaningful EMEA exposure.
  • Experience executing government or public-sector assurance programs in the UK, EU, or GCC.
  • Familiarity with UK Cyber Essentials/Cyber Essentials+, ISO 27001, ISO 9001, ISO 42001, SOC 2, and GCC sovereign security regimes.
  • Familiarity with EMEA data protection and AI governance requirements, including GDPR, PDPPL, and the EU AI Act.
  • Experience managing controls mapping, evidence collection, remediation tracking, and audit coordination across distributed engineering and infrastructure teams.
  • Experience with AWS, Azure, or Google Cloud and assessing cloud architecture against compliance requirements.
  • Strong communication, judgment, autonomy, and escalation skills.

Nice to Have

  • CISSP, CISM, CISA, ISO 27001 Lead Auditor, ISO 42001 Internal Auditor, or CCSP certification.
  • NATO information assurance or defence procurement experience.
  • EMEA health-sector or medical-device regulatory experience.
  • Working knowledge of Arabic.
  • UK SC or DV clearance, or eligibility for equivalent EMEA government security clearances.
  • Big Four or high-growth technology company experience.

Compensation and Benefits

  • Qatar-based applicants may require residency and employment permissions, visas, and permits from Qatari authorities.

Skills

Cybersecurity Compliance, SOC 2, ISO 27001, Iso 42001, Iso 9001, Cyber Essentials Plus, GDPR, Eu Ai Act, AWS, Microsoft Azure, GCP, Controls Mapping, Audit Coordination, Cloud Security

Docker

Docker

United Kingdom
Senior Security Engineer, Offensive Security
€119k+/yrRemote5+ YOESecurity Engineering

Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.

Writer

Writer

London, United Kingdom

Security Engineer, Detection and Response
No salary listedHybrid7+ YOESecurity Engineering

Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Trail of Bits

Trail of Bits

United Kingdom

Senior Security Engineer, Research & Engineering
No salary listedRemote5+ YOESecurity Engineering

Senior security engineer who red teams formally verified systems, assesses proof and threat-model boundaries, and builds AI-driven vulnerability discovery and exploit-generation tooling. Requires hands-on offensive security, formal methods, systems expertise, software development, and rigorous technical reporting.

GitLab

GitLab

Israel
Senior Security Engineer, Security Incident Response Team - EMEA
No salary listedRemote5+ YOESecurity Engineering

Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.