Own the complete internal audit lifecycle, from initial kickoff through final reporting.
Review and assess customer evidence against ISO 27001 controls.
Conduct customer discussions to explain audit findings and provide recommendations.
The company provides security compliance services, helping organizations achieve and maintain industry-leading standards. It operates as a remote-first environment where ownership, expertise, and clear communication are highly valued.
Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
Review information security requirements in customer contracts and lead responses to complex security questionnaires.
We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.
Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.
Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.
Identify, implement, and integrate security tools to strengthen AWS and Kubernetes security posture and support threat modeling.
Identify and mitigate security issues and misconfigurations across infrastructure and microservices.
Support audits, compliance initiatives, and security certifications such as ISO 27001 and SOC 2.
Ecosio is a fast-growing provider of B2B integration solutions, specializing in EDI, Web EDI, and e-invoicing. As part of Vertex, Inc., they foster an inclusive, technology-driven culture with a focus on innovation and strong connections.
Manage internal audits and support external compliance assessments across business functions.
Perform gap analyses and track remediation actions for compliance frameworks.
Maintain and improve compliance documentation, policies, and risk registers.
Our partner is a growing SaaS organization serving global industries. It fosters a collaborative and inclusive culture with a focus on employee development and well-being.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Own and continuously improve the company's compliance program across SOC 2, GDPR, ISO 27001, and other frameworks.
Lead external audits, develop security policies, and partner with engineering teams to implement controls.
Manage third-party risk, respond to customer security questionnaires, and build compliance metrics for executive reporting.
10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They are a high-growth technology company with a collaborative culture, operating in a fast-moving environment.
Own and run the ISMS, lead ISO 27001 certification, and manage risk, policies, and audits end-to-end.
Handle customer security questionnaires, RFIs, and supplier audits independently as the sole security expert.
Manage GDPR compliance, including DPAs, subprocessor lists, vendor reviews, and DSARs with operational ownership.
Cosuno is a fast-growing tech startup revolutionizing the construction industry through a digital platform for tenders and procurement, using AI to analyze price data and create efficient bids. They are a lean, 100-person team with a culture of high autonomy, pragmatism, and AI-first thinking, offering a remote-first work environment.
Partner with Sales, Customer Success, and Marketing on strategic enterprise opportunities, bringing security and GRC expertise into customer conversations.
Lead executive briefings and CISO-to-CISO conversations to build trust and confidence in Drata's platform.
Represent Drata at industry conferences, CISO dinners, and roundtables across the Americas, EMEA, and APAC, building relationships and credibility.
Drata helps companies earn and keep trust by providing a proof layer that shows they deserve it. The company has over 600 employees worldwide and fosters a culture built on trust, speed, and continuous growth.
Lead implementation and maintenance of enterprise cybersecurity programs across cloud and corporate environments.
Manage compliance initiatives aligned with frameworks such as NYDFS Cybersecurity Regulation 500 and ISO 27001.
Conduct vulnerability assessments, coordinate penetration testing, and drive timely remediation of identified risks.
Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. They operate with a remote team and use technology to streamline the application process.
Own internal audits end to end for customers, from kickoff to final report.
Review evidence against ISO 27001 controls and identify non-conformities.
Write clear findings for non-technical founders and keep multiple audits on schedule.
Secfix automates security compliance for companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 certification. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised $12M Series A, and are backed by top VCs.
Define and execute short- and long-term security strategy, governance, and operations across the organization.
Lead security initiatives covering monitoring, incident response, cloud protection, and application security.
Collaborate with engineering, compliance, and leadership teams to balance strong protection with seamless experiences.
A fast-growing global technology organization in the fintech sector. The company fosters a collaborative international environment with talented teams across multiple regions.
Manage the Compliance and Security workstream within a telecom transformation program, coordinating SOC 2, ISO/IEC 27001, and GDPR readiness activities.
Build and maintain the workstream plan with milestones, deliverables, and RAID logs, while driving evidence collection and control-owner alignment.
Facilitate workshops, track remediation across multiple domains, and ensure alignment with adjacent program streams and governance forums.
Miratech helps visionaries change the world as a global IT services and consulting company supporting digital transformation for large enterprises. With nearly 1000 professionals operating across 25+ countries and a 99% project success rate, their culture emphasizes relentless performance and growth.
Manage and conduct internal and external compliance audits for frameworks like ISO, SOC, and NIST.
Work with global teams to implement and update compliance controls, policies, and training.
Stay updated on regulatory changes and perform gap analysis to maintain certifications.
QAD is building a world-class SaaS company that solves real-world problems in manufacturing and supply chain. They are a growing, virtual-first company with a collaborative culture that values idea-sharing and growth.
Own cybersecurity strategy and operations across all AIOS entities.
Lead identity, access, endpoint, application, and infrastructure security.
Drive risk and compliance for HIPAA, GDPR, SOC 2, and ISO 27001.
AIOS is building the world's first full-stack AI doctor, serving 150k monthly patients through Bolt Pharmacy. We're a profitable, founder-led company scaling from $10M to $350M ARR in 12 months, with a culture of extreme ownership and speed.
Act as a regional anchor for security compliance, managing controls and audits.
Develop and maintain security documentation, including policies and metrics.
Implement AI and automation to streamline compliance and security work.
Airwallex provides a unified payments and financial platform for global businesses, empowering over 250,000 companies with integrated solutions. With over 2,300 employees across 27 global offices, the company values innovation and ambitious work.
Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.
Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.
Own delivery for standard-framework GRC engagements including ISO 27001, SOC 2, GDPR, and PCI DSS.
Build and maintain reusable IP such as templates, control-mapping libraries, and AI-assisted playbooks.
Own commercial outcomes including pricing, utilization, margin, and delivery forecasting for your own engagement book.
Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, they have raised $31.8M in funding and are trusted by over 3,000 organizations across 75 countries, with a remote culture organized around problems rather than job titles.
Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
Develop and execute security awareness programs including training and phishing simulations.
Support governance and control management by maintaining policies and control libraries.
Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.
Consult clients on creation, implementation, and review of security concepts in a project-leading role.
Conduct IT risk analyses and implement security standards and processes.
Proactively identify client needs, document and evaluate processes, and design tailored solutions.
SITS Group is a leading IT security group providing holistic security solutions. With over 700 employees, the company fosters an open, respectful, and team-oriented culture that values individual contributions.