# Technical Assurance Lead

**Company**: Scale
**Location**: Washington, DC
**Experience**: senior
**Job type**: full-time
**Category**: IT
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/scaleai/jobs/4711741005?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_ac77f252-928

## Description

Scale is seeking a Technical Assurance Lead to drive assurance programs across its public sector and commercial business. The successful candidate will report to the Head of Global Assurance and be part of the global GRC team.

The Technical Assurance Lead will:

- Lead public sector compliance programs, including FedRAMP HIGH, DoD SRG IL4/IL5/IL6, NIST 800-53/800-171, CMMC, and RMF

- Oversee Security Risk Management A&A processes, including cloud system risk assessments and vulnerability management

- Drive cross-functional control implementation with product, engineering, security, operations, legal, and people ops

- Set priorities and cadences for intake, evidence collection, remediation tracking, and deadline management

- Manage external relationships with auditors, assessors, certification bodies, and regulatory counterparts

- Maintain system security documentation and GRC tooling

- Lead compliance reviews for new products and features

- Maintain and expand Scale's certification portfolio, including SOC 2, ISO 27001, ISO 42001, and ISO 9001

- Support customer and stakeholder assurance activities

The ideal candidate will have:

- An active US Top Secret security clearance with minimum IAT Level 2 certification

- 7+ years of experience in security compliance, technology audit, GRC, cloud security, or related roles

- Experience implementing and maintaining frameworks and standards such as FedRAMP, DoD Cloud Computing SRG, NIST 800-171, and NIST 800-53

- Deep familiarity with STIG/RMF policy knowledge & implementation, ISO 27001, ISO 9001, ISO 42001, SOC 2, or equivalent frameworks

- Experience in project management and taking projects from conception to launch

- Ability to translate between business and technical risk and communicate clearly to leadership

- Experience managing controls mapping, evidence collection, remediation tracking, and audit coordination across distributed engineering and infrastructure teams

- Experience with cloud environments (AWS, Azure, GCP) and assessing cloud architecture against compliance requirements

## Skills

### Required
- FedRAMP
- DoD SRG
- NIST 800-53
- NIST 800-171
- CMMC
- RMF
- Cloud security
- GRC
- Security compliance
- Risk management
- Audit
- Cloud environments (AWS, Azure, GCP)
- Project management

### Nice to have
- CISSP
- CISM
- CISA
- ISO 27001 Lead Auditor
- ISO 42001 Internal Auditor
- CCSP
- Bachelor's degree in accounting, information systems, computer science, or a related field

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/scaleai/jobs/4711741005?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
