# EMEA Assurance Lead

**Company:** [Scale AI](https://hotfix.jobs/companies/scale-ai)
**Location:** Doha, Qatar, London, United Kingdom, Dubai, United Arab Emirates
**Role:** Security Engineering
**Experience:** 7+ years
**Skills:** Cybersecurity Compliance, SOC 2, ISO 27001, Iso 42001, Iso 9001, Cyber Essentials Plus, GDPR, Eu Ai Act, AWS, Microsoft Azure, GCP, Controls Mapping, Audit Coordination, Cloud Security
**Posted:** 2026-08-04

> Leads EMEA cybersecurity assurance programs for public-sector and commercial operations, owning regional controls, certifications, audits, and customer assurance outcomes. Requires 7+ years in cybersecurity compliance, GRC, IT audit, cloud security, or related work, with experience across UK, EU, or GCC frameworks.

## Job Description

## Responsibilities
- Lead region-specific assurance programs across the GCC and UK, including Qatar NCSA National Information Assurance (NIA), KSA NCA Essential Cybersecurity Controls (ECC), UAE DESC Information Security Regulation (ISR), UK Cyber Essentials Plus, Defence Cyber Certification (DCC), and NCSC Secure by Design (SdB).
- Own controls mapping, evidence collection, gap analysis, certification timelines, and submission management, working with accredited external assessors where required.
- Maintain and renew SOC 2, ISO 27001, ISO 42001, and ISO 9001 certifications, including extensions to EMEA and international operations and NATO-aligned defence tenders.
- Design and maintain EMEA-specific controls for sovereign regulatory, data residency, and sector-specific requirements.
- Manage assurance intake, evidence collection, control-owner follow-up, remediation tracking, deadlines, dashboards, and reporting.
- Support public-sector customer assurance activities, including security questionnaires, compliance due diligence, assurance discussions, and bid and capture processes.
- Partner with Legal on contract-driven assurance, data protection, AI governance, GDPR, Qatar PDPPL, and EU AI Act matters.
- Manage relationships with auditors, assessors, certification bodies, and regulatory counterparts.
- Support internal and external audits and report program health, risks, timelines, and regulatory developments.

## Requirements
- 7+ years of experience in cybersecurity compliance, GRC, public-sector assurance, IT audit, cloud security, or related roles, with meaningful EMEA exposure.
- Experience executing government or public-sector assurance programs in the UK, EU, or GCC.
- Familiarity with UK Cyber Essentials/Cyber Essentials+, ISO 27001, ISO 9001, ISO 42001, SOC 2, and GCC sovereign security regimes.
- Familiarity with EMEA data protection and AI governance requirements, including GDPR, PDPPL, and the EU AI Act.
- Experience managing controls mapping, evidence collection, remediation tracking, and audit coordination across distributed engineering and infrastructure teams.
- Experience with AWS, Azure, or Google Cloud and assessing cloud architecture against compliance requirements.
- Strong communication, judgment, autonomy, and escalation skills.

## Nice to Have
- CISSP, CISM, CISA, ISO 27001 Lead Auditor, ISO 42001 Internal Auditor, or CCSP certification.
- NATO information assurance or defence procurement experience.
- EMEA health-sector or medical-device regulatory experience.
- Working knowledge of Arabic.
- UK SC or DV clearance, or eligibility for equivalent EMEA government security clearances.
- Big Four or high-growth technology company experience.

## Compensation and Benefits
- Qatar-based applicants may require residency and employment permissions, visas, and permits from Qatari authorities.

## Similar jobs

- [Senior Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e6f5289c-9cb8-4a13-b321-e0ecc9a54c96) - Docker - Remote - €119k – €170k/yr
- [Security Engineer, Detection and Response](https://hotfix.jobs/jobs/02ff0cde-e8e1-4f38-9c48-d8149d22a95b) - Writer - London, United Kingdom
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Security Engineer, Research & Engineering](https://hotfix.jobs/jobs/f9156020-d99c-45aa-8dba-fcd0035e45b4) - Trail of Bits - Remote
- [Senior Security Engineer, Security Incident Response Team - EMEA](https://hotfix.jobs/jobs/33cbe57c-bb91-44ff-8901-3cde1ac976a7) - GitLab - Remote

**Apply:** https://hotfix.jobs/jobs/dd61dc28-4ade-4197-95b6-e9c09f6446af
**Canonical:** https://hotfix.jobs/jobs/dd61dc28-4ade-4197-95b6-e9c09f6446af