Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
Review information security requirements in customer contracts and lead responses to complex security questionnaires.
We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.
Own and drive the compliance roadmap across multiple frameworks like ISO 27001, TISAX, and SOC 2.
Implement ISO 27001 end-to-end for customers and mentor junior compliance specialists.
Act as the senior compliance voice for customers, auditors, and product, partnering with CS and founders.
Secfix automates security compliance in Europe, helping companies achieve ISO 27001, GDPR, TISAX, and SOC 2 quickly and easily. We are a 100% remote team with hubs in Munich, Berlin, and London, backed by top VCs with a high-performing, ownership-driven culture.
Lead the design and evolution of a multi-framework compliance offering for European businesses.
Drive end-to-end ISO 27001 implementations and manage a team of compliance specialists.
Act as a senior security partner to customers, sales, and product teams.
This company provides a security and compliance platform that helps modern businesses achieve certifications across frameworks like ISO 27001 and SOC 2. It is a fast-growing, remote-first technology environment with a strong emphasis on collaboration and team connection.
Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.
Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.
Own and continuously improve the company's compliance program across SOC 2, GDPR, ISO 27001, and other frameworks.
Lead external audits, develop security policies, and partner with engineering teams to implement controls.
Manage third-party risk, respond to customer security questionnaires, and build compliance metrics for executive reporting.
10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They are a high-growth technology company with a collaborative culture, operating in a fast-moving environment.
Lead security compliance initiatives across ISO 27001, SOC 2, GDPR, and more.
Conduct internal audits and mentor junior specialists.
Collaborate with product teams to integrate compliance requirements.
Our partner is a fast-growing technology company specializing in security compliance and automation for European businesses. They have a startup culture with a focus on innovation and collaboration.
Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
Oversee preparation and execution of external compliance audits, including facilitating security assessments.
Support mapping of compliance requirements to security control implementation using agile development processes.
Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Take ownership of building and scaling comprehensive security, privacy, and compliance programs that protect customer data.
Lead compliance initiatives such as SOC 2 Type 2 audits and evaluate additional frameworks like ISO 27001 and HIPAA.
Build scalable automated security processes by replacing manual tasks with scripts, APIs, and AI-powered solutions.
Our partner is a technology company focused on building secure, scalable systems. They operate with a remote, collaborative culture emphasizing ownership, transparency, and continuous improvement, with around 50–300 employees.
Own the complete internal audit lifecycle, from initial kickoff through final reporting.
Review and assess customer evidence against ISO 27001 controls.
Conduct customer discussions to explain audit findings and provide recommendations.
The company provides security compliance services, helping organizations achieve and maintain industry-leading standards. It operates as a remote-first environment where ownership, expertise, and clear communication are highly valued.
Serve as the Information Systems Security Officer for assigned systems, maintaining security documentation and supporting authorization activities.
Coordinate security control implementation with Engineering, DevOps, and IT teams, managing Plans of Action and Milestones.
Support continuous monitoring, vulnerability management, and incident response for FedRAMP and GovRAMP environments.
Keeper Security is a cybersecurity software company that protects organizations and individuals globally with zero-trust and zero-knowledge solutions. It is a fast-growing company with FedRAMP and GovRAMP high authorizations, recognized in the Gartner Magic Quadrant for PAM.
Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.
Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.
Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
Develop and execute security awareness programs including training and phishing simulations.
Support governance and control management by maintaining policies and control libraries.
Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.
Manage IT security systems, identify and close cybersecurity risks.
Ensure compliance with ISO 27001 and SOC2, and develop IT policies.
Lead IT management, collaborate across teams, and promote a security culture.
Laminar Projects is an award-winning consultancy implementing technology to improve construction project delivery, with a product team developing construction management software. They have grown from 2 to over 170 people since 2017, focusing on human flourishing with core values of growth, care, execution, and building civilisation.
Own IRAP and ISMAP program strategy and execution across Australia and Japan.
Coordinate with regional assessors and government agencies to maintain compliance.
Design and maintain compliance documentation and manage continuous monitoring.
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. They are now uniting human teams with AI agents to automate tasks and uncover insights.
Lead compliance initiatives across commercial and federal lines, driving FedRAMP, CMMC, ISO 27001, SOC 2, and HITRUST programs.
Coordinate internal and external audits, ensuring stakeholder readiness and timely remediation of findings.
Manage program roadmaps, risk registers, and cross-functional execution to translate regulatory requirements into actionable plans.
We provide an AI-infused scenario planning and analysis platform to optimize business decision-making. We serve over 2,400 global customers including Fortune 50 companies and foster a Winning Culture focused on innovation, diversity, and leadership.
Consult on ISMS building, implementation, and improvement according to standards such as ISO 27001, NIS-2, and TISAX.
Conduct security analyses, gap analyses, and risk assessments to identify vulnerabilities and optimize processes.
Prepare and support internal audits, manage security policies, and collaborate with data protection and product development teams.
DDSK GmbH is a specialized information security consulting firm that helps companies build and implement ISMS according to standards like ISO 27001, NIS-2, and TISAX. They work with SMEs to large corporations and have a team of IT and security professionals in an audit-oriented, collaborative environment.
You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
You will run the vulnerability management program and remediate security findings across AWS.
You will support security incident response, fraud investigations, and third-party risk assessments.
We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.
Act as a regional anchor for security compliance, managing controls and audits.
Develop and maintain security documentation, including policies and metrics.
Implement AI and automation to streamline compliance and security work.
Airwallex provides a unified payments and financial platform for global businesses, empowering over 250,000 companies with integrated solutions. With over 2,300 employees across 27 global offices, the company values innovation and ambitious work.
Partner with Sales, Customer Success, and Marketing on strategic enterprise opportunities, bringing security and GRC expertise into customer conversations.
Lead executive briefings and CISO-to-CISO conversations to build trust and confidence in Drata's platform.
Represent Drata at industry conferences, CISO dinners, and roundtables across the Americas, EMEA, and APAC, building relationships and credibility.
Drata helps companies earn and keep trust by providing a proof layer that shows they deserve it. The company has over 600 employees worldwide and fosters a culture built on trust, speed, and continuous growth.