Source Job

Global

  • Own global certification programs like ISO 27001 and SOC 2, and advise engineering teams on secure development.
  • Collaborate directly with engineers to audit cloud infrastructure, CI/CD pipelines, and AI-driven security controls.
  • Assess risks of emerging technologies and drive continuous compliance improvements across the organization.

IT Audit ISO 27001 SOC 2 Cloud Security Risk Management

20 jobs similar to Senior Technology Risk & Audit Specialist

Jobs ranked by similarity.

Global

  • Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
  • Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
  • Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.

Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.

$139,200–$189,000/yr
North America Unlimited PTO

  • Own risk identification, analysis, and prioritization across third-party risk and security risk assessments using established frameworks.
  • Translate technical vulnerabilities and risk findings into clear, quantified risk statements for non-security stakeholders and leadership.
  • Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal.

GitLab is an intelligent orchestration platform for DevSecOps, helping organizations increase developer productivity and improve security. With over 50 million users, GitLab is trusted by more than 50% of the Fortune 100 and fosters a high-performance culture driven by values and continuous knowledge exchange.

US

  • Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
  • Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
  • Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.

A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.

Germany 6w PTO

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end, owning compliance and audit.
  • Own customer trust by responding to security questionnaires and representing InfoSec to enterprise clients.
  • Drive risk management, vendor security, and incident response while building AI-assisted workflows.

We are the first AI-native Employee Experience Platform, helping organizations unlock inspirational communication. Our diverse team of 550+ employees supports over 1,500 customers, and we are a unicorn company valued at over $1 billion.

$180,000–$220,000/yr
US

  • Drive SOC 2, ISO 27001, and PCI 4.0 compliance audit cycles: gather evidence, design controls, and coordinate with auditors.
  • Own the compliance automation platform Vanta: monitor control status, chase failing checks, and update risk register.
  • Run vendor and third-party risk reviews, security assessments, and respond to customer security questionnaires.

AssemblyAI builds the best-in-class Voice AI models powering the next generation of voice applications. With under 100 people, it is a capital-efficient AI company generating roughly $500K ARR per employee and operating as a true meritocracy with no bureaucracy.

Global

  • Own the compliance function as its sole occupant, reporting to the Head of Engineering and partnering with the Security Lead on policies, audits, and evidence.
  • Manage the Q&A library, customer security reviews, audit calendar, and third-party risk to keep Duvo reviewable for buyers and auditors.
  • Deliver precise, evidenced answers that stand up to hostile reviewers and keep the trust center and subprocessor list current.

Duvo builds an AI operations platform for large enterprises, enabling customers to create AI agents that automate business-critical processes across systems like SAP, spreadsheets, and supplier portals. The company is growing fast and values velocity, direct feedback, autonomy, and heavy use of AI tools.

$160,000–$180,000/yr
US

  • Lead and mature cybersecurity compliance programs including SOC 2 Type 2 and ISO 27001 readiness.
  • Drive cloud and application security across AWS and Azure, integrating secure SDLC and DevSecOps practices.
  • Manage corporate IT operations, identity and access, and build the cybersecurity team as the organization grows.

Genea is a leader in property technology, providing cloud-based physical security, submeter billing, and on-demand HVAC solutions to over 1 million users across 39 countries. It has been recognized as a Top Workplace from 2021-2025 with a 4.3 Glassdoor rating, fostering a team-oriented and transparent culture.

Global 4w PTO

  • Act as part vCISO and account manager, guiding clients through security and compliance programs.
  • Assess security posture, provide recommendations, and design programs using NIST, SOC 2, and ISO 27001.
  • Liaise with auditors and internal teams to translate programs into policies, procedures, and configurations.

Oneleet provides a platform for companies to build, manage, and monitor cybersecurity programs and achieve SOC 2 and ISO 27001. It raised a $33M Series A and is a fast-growing, remote-first team with an opinionated culture.

US 3w PTO

  • Own and mature internal and Managed GRC programs, including federal SSPs, POA&Ms, audits, and risk assessments.
  • Collaborate with CISOs, engineers, and control owners to translate compliance requirements into practical technical controls.
  • Lead and develop a GRC team while introducing automation and AI to improve scalability and consistency.

The company provides managed Governance, Risk & Compliance (GRC) and security assurance services, with a strong focus on federal security programs and frameworks like NIST, SOC 2, and CMMC. It supports a growing GRC team and emphasizes low-ego collaboration, automation, and AI-enabled approaches to scale delivery.

Europe 5w PTO

  • Build and maintain compliance frameworks in the Secfix platform, including ISO 27001, TISAX, SOC 2, GDPR, and more.
  • Own internal audits end-to-end for customers, ensuring they are prepared for external audits.
  • Collaborate with product and engineering to translate compliance gaps into structured product work and enhance platform quality.

Secfix automates security compliance for European companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 efficiently. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised a $12M Series A, and are backed by top VCs.

$80,208–$83,372/yr
Poland

  • Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
  • Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
  • Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.

Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.

India Unlimited PTO

  • Guide customers through setup and go-live, ensuring they reach their first audit milestone.
  • Collaborate with founders, CTOs, and security teams to map goals to actionable milestones.
  • Own next steps when stuck, partnering with internal teams to keep the project moving.

Sprinto is an autonomous trust platform that centralizes compliance, audits, risk management, and more for organizations worldwide. Backed by top investors, it serves over 4,000 companies in 75+ countries and fosters a remote-first, ownership-driven culture.

US Unlimited PTO

  • Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
  • Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
  • Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.

$180,000–$230,000/yr
US

  • Lead projects from client acquisition to final delivery and oversee client service teams on multiple engagements.
  • Perform technical security assessments, audits, and risk evaluations across applications and infrastructure.
  • Mentor and develop staff while cultivating client relationships and cross-selling firm services.

The Bonadio Group is a leading accounting, advisory, and consulting firm providing next-level solutions to clients across industries. The firm values diversity, innovation, and professional growth, offering mentoring and training programs with a path to partnership.

Europe 4w PTO

  • Lead and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests.
  • Build, develop, and manage the GRC team and improve GRC efficiency through automation and reusable evidence.

JustMarkets is an international FinTech company. It is a growing organization with a focus on information security and compliance.

Hungary

  • Prepare and be part of internal and external audits of a cloud platform within a dedicated team of specialists.
  • Ensure compliance requirements for various IT audits and create and map requirements catalogs of different standards.
  • Act as a trusted advisor to cross-functional teams on information and IT security during audits of the platform.

Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group providing a wide portfolio of IT and telecommunications services. With more than 5,300 employees across four Hungarian sites, it has been recognized as Hungary's most attractive employer in 2025.

India

  • Maintain and enhance Anovia's ISO/IEC 27001 ISMS, including policies, controls, risks, and audit coordination.
  • Support SOC 2, HIPAA, and other compliance programs, including vendor assessments, vulnerability management, and incident response.
  • Lead ambiguous technical and operational initiatives from planning through implementation, coordinating stakeholders and driving completion.

Anovia is an industry-leading technology outsourcing support provider specializing in workflow and knowledge processes, technical support, helpdesk, and multilingual services. With over 200 experts globally, we serve Fortune 500 companies and value growth, learning, and work-life balance.

Slovakia

  • You will prepare and participate in internal/external audits of an Open cloud platform within a dedicated specialist team.
  • You will ensure compliance requirements for various IT audits and map requirements catalogs of different standards such as SOC1, SOC2, C5, and ISO.
  • You will act as a trusted advisor for cross-functional teams on information and IT security during audits, answer stakeholder questions, and escalate risks.

Deutsche Telekom IT Solutions Slovakia provides innovative information and communication technology services. The company has grown to more than 3,900 employees and is the second largest employer in eastern Slovakia.

US Unlimited PTO

  • Execute audits with clients across different industries and around the globe alongside lead auditors.
  • Participate in client calls, walkthroughs, and observations to assess internal controls.
  • Assist with internal projects and engagements involving frameworks like HIPAA and HITRUST.

Aprio is a Top 20 CPA and advisory firm that provides assurance, tax, and consulting services to fast-growing industries. With over 3,200 team members across 40+ U.S. and international offices, Aprio fosters a top-rated culture focused on growth and exceptional client service.

$135,000–$145,000/yr
Global

  • Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
  • Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
  • Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.

Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.