Own and drive the compliance roadmap across multiple frameworks like ISO 27001, TISAX, and SOC 2.
Implement ISO 27001 end-to-end for customers and mentor junior compliance specialists.
Act as the senior compliance voice for customers, auditors, and product, partnering with CS and founders.
Secfix automates security compliance in Europe, helping companies achieve ISO 27001, GDPR, TISAX, and SOC 2 quickly and easily. We are a 100% remote team with hubs in Munich, Berlin, and London, backed by top VCs with a high-performing, ownership-driven culture.
Lead security compliance initiatives across ISO 27001, SOC 2, GDPR, and more.
Conduct internal audits and mentor junior specialists.
Collaborate with product teams to integrate compliance requirements.
Our partner is a fast-growing technology company specializing in security compliance and automation for European businesses. They have a startup culture with a focus on innovation and collaboration.
Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.
Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.
Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
Review information security requirements in customer contracts and lead responses to complex security questionnaires.
We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.
Own the complete internal audit lifecycle, from initial kickoff through final reporting.
Review and assess customer evidence against ISO 27001 controls.
Conduct customer discussions to explain audit findings and provide recommendations.
The company provides security compliance services, helping organizations achieve and maintain industry-leading standards. It operates as a remote-first environment where ownership, expertise, and clear communication are highly valued.
Partner with Sales, Customer Success, and Marketing on strategic enterprise opportunities, bringing security and GRC expertise into customer conversations.
Lead executive briefings and CISO-to-CISO conversations to build trust and confidence in Drata's platform.
Represent Drata at industry conferences, CISO dinners, and roundtables across the Americas, EMEA, and APAC, building relationships and credibility.
Drata helps companies earn and keep trust by providing a proof layer that shows they deserve it. The company has over 600 employees worldwide and fosters a culture built on trust, speed, and continuous growth.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Take ownership of building and scaling comprehensive security, privacy, and compliance programs that protect customer data.
Lead compliance initiatives such as SOC 2 Type 2 audits and evaluate additional frameworks like ISO 27001 and HIPAA.
Build scalable automated security processes by replacing manual tasks with scripts, APIs, and AI-powered solutions.
Our partner is a technology company focused on building secure, scalable systems. They operate with a remote, collaborative culture emphasizing ownership, transparency, and continuous improvement, with around 50–300 employees.
Act as a regional anchor for security compliance, managing controls and audits.
Develop and maintain security documentation, including policies and metrics.
Implement AI and automation to streamline compliance and security work.
Airwallex provides a unified payments and financial platform for global businesses, empowering over 250,000 companies with integrated solutions. With over 2,300 employees across 27 global offices, the company values innovation and ambitious work.
Own cybersecurity strategy and operations across all AIOS entities.
Lead identity, access, endpoint, application, and infrastructure security.
Drive risk and compliance for HIPAA, GDPR, SOC 2, and ISO 27001.
AIOS is building the world's first full-stack AI doctor, serving 150k monthly patients through Bolt Pharmacy. We're a profitable, founder-led company scaling from $10M to $350M ARR in 12 months, with a culture of extreme ownership and speed.
Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.
Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.
Act as a trusted advisor to business leaders, bridging security risks and business priorities.
Lead security assessments, risk reviews, and remediation planning for new products and enterprise changes.
Maintain clear visibility of security risk, control health, metrics, and dashboards, escalating when needed.
Experian is a global data and technology company, powering opportunities for people and businesses around the world. With a team of 25,200 people in 32 countries, they foster an inclusive, purpose-driven culture and have been recognized as a World's Best Workplace in 2025.
Own and run the ISMS, lead ISO 27001 certification, and manage risk, policies, and audits end-to-end.
Handle customer security questionnaires, RFIs, and supplier audits independently as the sole security expert.
Manage GDPR compliance, including DPAs, subprocessor lists, vendor reviews, and DSARs with operational ownership.
Cosuno is a fast-growing tech startup revolutionizing the construction industry through a digital platform for tenders and procurement, using AI to analyze price data and create efficient bids. They are a lean, 100-person team with a culture of high autonomy, pragmatism, and AI-first thinking, offering a remote-first work environment.
Lead security discovery workshops and translate high-level architectural requirements into actionable security roadmaps.
Design end-to-end cloud security frameworks and document controls for SOC 2 and HITRUST compliance.
Establish governance and security processes for AI and manage vulnerability remediation with development teams.
Ollion is a global technology partner that helps organizations solve their toughest business challenges in AI, data, and cloud. They are a remote-first, globally distributed team focused on making a world of difference through innovation and collaboration.
Own IRAP and ISMAP program strategy and execution across Australia and Japan.
Coordinate with regional assessors and government agencies to maintain compliance.
Design and maintain compliance documentation and manage continuous monitoring.
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. They are now uniting human teams with AI agents to automate tasks and uncover insights.
Own and continuously improve the company's compliance program across SOC 2, GDPR, ISO 27001, and other frameworks.
Lead external audits, develop security policies, and partner with engineering teams to implement controls.
Manage third-party risk, respond to customer security questionnaires, and build compliance metrics for executive reporting.
10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They are a high-growth technology company with a collaborative culture, operating in a fast-moving environment.
Manage IT security systems, identify and close cybersecurity risks.
Ensure compliance with ISO 27001 and SOC2, and develop IT policies.
Lead IT management, collaborate across teams, and promote a security culture.
Laminar Projects is an award-winning consultancy implementing technology to improve construction project delivery, with a product team developing construction management software. They have grown from 2 to over 170 people since 2017, focusing on human flourishing with core values of growth, care, execution, and building civilisation.
Consult on ISMS building, implementation, and improvement according to standards such as ISO 27001, NIS-2, and TISAX.
Conduct security analyses, gap analyses, and risk assessments to identify vulnerabilities and optimize processes.
Prepare and support internal audits, manage security policies, and collaborate with data protection and product development teams.
DDSK GmbH is a specialized information security consulting firm that helps companies build and implement ISMS according to standards like ISO 27001, NIS-2, and TISAX. They work with SMEs to large corporations and have a team of IT and security professionals in an audit-oriented, collaborative environment.
Serve as the Information Systems Security Officer for assigned systems, maintaining security documentation and supporting authorization activities.
Coordinate security control implementation with Engineering, DevOps, and IT teams, managing Plans of Action and Milestones.
Support continuous monitoring, vulnerability management, and incident response for FedRAMP and GovRAMP environments.
Keeper Security is a cybersecurity software company that protects organizations and individuals globally with zero-trust and zero-knowledge solutions. It is a fast-growing company with FedRAMP and GovRAMP high authorizations, recognized in the Gartner Magic Quadrant for PAM.
Own technical strategy and solutioning for complex enterprise opportunities across regulated industries.
Build trusted relationships with senior CISOs and executive stakeholders by discussing security architecture and compliance frameworks.
Drive technical wins, design proof-of-concepts, and influence product roadmap with enterprise customer insights.
Sprinto is an autonomous trust platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors like Accel and Elevation, Sprinto has raised $31.8M and is trusted by over 3,000 organizations across 75 countries.