远程工作雷达

信任与保障负责人

Trust & Assurance Lead

AI开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Sysdig
薪资$160,000 - $200,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间4 天前
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

在Sysdig,我们相信云安全不是一种妥协,而是一种承诺。从一开始,我们的使命就很明确:帮助组织以正确的方式保障云中的创新。

我们创建了Falco,这是云威胁检测的开源标准,并继续通过运行时洞察、开放创新和代理AI引领云安全市场。由超过60%的财富500强企业信任的技术创造者,Sysdig为团队提供实时的清晰度,让他们快速行动并保护最重要的东西。

文化在这里至关重要。我们认为多样性能激发更强大的想法,开放对话能推动更精准的决策。连续五年被列为最佳工作场所之一,并且是德勤增长最快的公司之一,我们致力于提升云安全和职场文化的标杆。

如果你有深入挖掘的热情,有挑战传统愿望,以及有构建更好事物的好奇心,那么Sysdig就是适合你的地方。

你将负责证明Sysdig的安全主张——向审计师、企业客户和监管机构证明,并将该功能从文件工作转变为工程实现。你还将从零开始构建一个项目:AI保证,涵盖我们自己的AI系统以及现在每个企业交易中出现的AI问题。
我们维护ISO 27001、ISO 27701和SOC 2 Type II认证,并且正在完全摆脱基于特定时间点的评估。目前,这些认证的大部分证据仍由人工收集。你的工作是将其变为管道输出:能够报告自身状态的控制措施,持续在生产环境中进行验证,并使审计变成对已运行系统的查询。
这个职位具有客户面向性,这在大多数合规职位中并不常见。当交易取决于安全答案时,你就是房间里的那个人。并且它位于安全工程部门,直接向安全工程总监汇报,而不是进入治理职能,因为我们认为控制问题的通常解决方法是修复控制。
这是一个高级个人贡献者角色,拥有设计和构建你所期望存在的项目的自由度。首席信息安全官办公室运作透明,我们希望安全团队能够发布和演讲,因此你在这里的工作将成为行业可以使用的成果。

将保证重新构造成工程。对控制措施进行监控,使其能够报告自身状态,将策略表达为代码,并在接近实时的时间内检测控制偏差。将故障路由到...

查看英文原文

At Sysdig, we believe cloud security isn't a compromise - it's a promise. From the start, our mission has been clear: to help organizations secure innovation in the cloud, the right way.
 
We created Falco, the open standard for cloud threat detection, and continue to lead the cloud security market with runtime insights, open innovation, and agentic Al. Creators of technology trusted by over 60% of the Fortune 500, Sysdig gives teams the real-time clarity to move fast and defend what matters most.
 
Culture matters here. We believe diversity fuels stronger ideas, and open dialogue drives sharper decisions. Recognized as a Best Place to Work and one of Deloitte's fastest-growing companies for the past 5 years, we're here to raise the standard for what cloud security and workplace culture should be.
 
If you have the passion to dig deeper, the desire to challenge convention, and the curiosity to build something better, Sysdig is the right place for you.

What you will do
You'll own how Sysdig proves its security claims — to auditors, to enterprise customers, and to regulators — and you'll rebuild that function as engineering rather than paperwork. You'll also build one program from nothing: AI assurance, covering both our own AI systems and the AI questions now arriving in every enterprise deal.
We maintain ISO 27001, ISO 27701, and SOC 2 Type II, and we're moving entirely off point-in-time assessments. Today, most evidence for those certifications is still collected by hand. Your job is to make it a pipeline output: controls that report their own state, validation running continuously against production, and an audit that becomes a query against something already running.
This role is customer-facing in a way most compliance roles are not. When a deal turns on a security answer, you're the person in the room. And it sits in Security Engineering deliberately, reporting to the Director of Security Engineering rather than into a governance function, because we think the answer to a control problem is usually to fix the control.
This is a senior individual contributor role with the latitude to design and build the program you wished existed. The Office of the CISO operates transparently, and we want our security team to publish and speak, so the work you do here becomes work the industry can use.

Rebuild assurance as engineering. Instrument controls so they report their own state, express policy as code, and detect control drift in near real time. Route failures to the team that owns the system, not a spreadsheet.
Own the certification program end-to-end. ISO 27001:2022, ISO 27701:2019, and SOC 2 Type II: scope, readiness, fieldwork, population and sampling requests, and remediation. You own the ISMS and PIMS artifacts and the quarterly security objectives, and you run the independent internal audit and the external assessors.
Drive down the cost of proof. Labor per audit cycle should fall year over year. That number shows the engineering work is real, and it is the one we will hold you to.
Build AI assurance from nothing. ISO 42001, the NIST AI RMF, and the EU AI Act obligations that actually apply to us, treated as an engineering problem rather than a documentation exercise. Define and instrument controls for model and agent behavior, for data handling inside AI systems, and for AI-assisted development in our own engineering organization.
Own AI third-party risk. Most new vendor risk now arrives wearing an AI label. Decide what we accept, and be able to show why.
Run customer and partner assurance. The trust profile, questionnaire pipeline, intake channel, and frequently requested document library. Lead the high-consequence engagements yourself: regulated financial services, pharmaceutical, aviation, and sovereign or region-specific programs, including third-party audits routed through a partner.
Write the specifications that settle hard questions. Access paths, separation of duties, administrative transparency, tenant isolation. In writing, and defensible under audit rather than persuasive on a call.
Enable the field. Sales engineers and account teams should answer most security questions without you in the room. Build for that, then measure whether it happened.
Own the integrity of our public claims. The certifications page, the trust center, marketplace listings, and anything a customer can cite back to us. Catch stale reports and overstated scope before a customer does. This is a brand-risk control, not compliance administration.
Push risk into engineering. Turn findings into commitments with owners and dates, or into a formal management response when the answer is to accept the risk. Escalate when the answer should be no.
Be customer zero for assurance. Where Sysdig's own platform can produce the evidence, use it in production before customers do, then tell product where it falls short. You'll have as much roadmap influence as you're willing to take.
Use agents to scale the function itself. Evidence generation, questionnaire drafting, control validation, gap analysis. If an assurance task is repeatable, it should run without you.
Represent Sysdig externally. Engage customer security teams on matters of significance, and publish and speak on the work — encouraged, resourced, and supported.

What you will bring with you
Have run a certification and audit program end-to-end for a cloud or SaaS company, owning the outcome rather than the coordination
Have shipped code or automation in service of a control objective — Python, Go, Terraform, CI pipelines, or an API wired into a compliance platform. We are not hiring a software engineer, and we are not hiring someone who has never opened a terminal
Have genuine depth in at least two of SOC 2, ISO 27001, ISO 27701, ISO 42001, with working knowledge of the rest
Have sat across from an enterprise customer's security team, or an auditor, and been able to demonstrate compliance with operational evidence rather than only with a policy document
Have a cloud-native technical foundation: Kubernetes, containers, at least one major cloud, and enough understanding of runtime security to ask a good question about it
Are already building with agentic tooling and have opinions about where it fails
Can tell a finding that matters from one that only matters to an auditor, and are willing to say so in the room
Are credible with a customer's CISO and with the engineers you're asking to change how they work, without changing register much between them
Are energized rather than unsettled by problems where established principles don't fully apply

What we look for
Built an assurance or compliance function that didn't exist before, at a company where much of it was theirs to define
Worked on AI governance frameworks — ISO 42001, the EU AI Act, NIST AI RMF — while the requirements were still moving
Built continuous controls monitoring or GRC engineering tooling, including cases where you concluded the tooling was the wrong answer
Worked assurance at a security vendor, where the customer's security team reads the answers closely
Experience with public sector requirements, regulated financial services, or EU data protection
A track record of conference speaking, published research, or contribution to a control framework or open standard

When you join Sysdig, you can expect
Extra days off to prioritize your well-being
401(k) Retirement Savings Plan with a 3% company match
Maternity and Parental Leave
Mental health support for you and your family through the Modern Health app
Full health benefits package for you and your family

The U.S. annual salary range for this full-time position is between 160,000 and 200,000 USD/year. Actual offers may be higher or lower than this range based on a variety of factors, including your work location, job-related experience and education.
 
We would love for you to join us! Please reach out even if your experience doesn't perfectly match the job description. We can always explore other options after starting the conversation. Your background and passion will set you apart, especially if your career path is different.
 
Sysdig values a diverse workplace and encourages women, people of color, LGBTQIA+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply. Sysdig is an equal-opportunity employer. Sysdig does not discriminate on the basis of race, color, religion, sex, national origin, age, disability, genetic information, sexual orientation, gender identity, or any other legally protected status.
 
#LI-FP1
#LI-Remote

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

AI平台工程师

SysdigUnited States$123,000 - $154,000/年permanent昨天
AI开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

初级AI与产品赋能专员

SysdigSpain、Costa Ricapermanent4 天前
AI限定地区(需当地身份)日间重叠约 2 小时,需偶尔早起或晚睡

安全研究总监

SysdigUnited States$245,000 - $307,000/年permanent4 天前
AI开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

内部销售代表

SysdigUnited Kingdompermanent4 天前
市场运营职能支持限定地区(需当地身份)日间重叠仅 1 小时,需熬夜配合

赋能与学习项目经理

SysdigUnited States$128,000 - $160,000/年permanent5 天前
市场运营职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位