- Experience
- 7+ yrs
- Salary
- —
- Openings
- 1
- Posted
- há 3 horas
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
Scale AI is at the forefront of generative AI innovation, supplying data and technology for organizations building expansive foundational AI models. With AI reshaping industries worldwide, Scale is rapidly scaling to serve diverse global markets, including expanding its public sector operations across the EMEA region.
Role Summary
The company is seeking an EMEA Assurance Lead to spearhead assurance initiatives for Scale’s public sector and commercial business within the EMEA region. This individual contributor role reports to the Global Assurance Head and entails substantial independence in creating and managing EMEA-specific controls that adhere to Scale's global assurance principles. Collaboration across internal teams such as Global Public Sector, Enterprise, Security, Engineering, Product, and Legal is essential to achieve regional certifications and customer assurance outcomes, primarily focusing on the GCC, UK, and European Union markets.
Key Responsibilities
- Lead assurance projects unique to the GCC and UK markets, including compliance with Qatar NCSA National Information Assurance, KSA NCA Essential Cybersecurity Controls, UAE DESC Information Security Regulation, and UK Cyber Essentials Plus, Defence Cyber Certification, and NCSC Secure by Design programs. Responsibilities include controls mapping, gathering evidence, performing gap analysis, managing certification timelines, and liaising with accredited external assessors.
- Collaborate with the global GRC team to sustain and renew established certifications such as SOC 2, ISO 27001, ISO 42001, and ISO 9001; oversee the adaptation and extension of these certifications for EMEA and international activities, including NATO-related defense contracts.
- Develop and continually update EMEA-specific controls, tailoring the global controls framework to local sovereign regulations, data residency requirements, and sector-specific standards, like those applicable to healthcare.
- Organize priorities and cadence for EMEA assurance processes, covering intake, evidence gathering, follow-up with control owners, remediation progress tracking, deadline management, and reporting to global assurance dashboards.
- Provide support in EMEA public sector customer assurance efforts such as addressing security questionnaires, responding to compliance due diligence, managing assurance-related bid inputs, and leading customer assurance discussions.
- Work closely with Legal to ensure contractual assurance commitments, compliance intersections with data protection laws and AI governance (GDPR, Qatar PDPPL, EU AI Act), and handle sensitive regulatory escalations.
- Maintain strong relations with EMEA-based auditors, certification authorities, assessors, and regulatory stakeholders.
- Assist with various internal and external audits within EMEA and report key metrics and risks, certification timelines, and regulatory changes to the Head of Global Assurance.
Candidate Requirements
- Minimum of seven years in cybersecurity compliance, governance, risk and compliance (GRC), IT audit, public sector assurance, or related fields, with demonstrable experience in EMEA markets.
- Practical experience managing government or public sector assurance initiatives across the UK, EU, or GCC, including collaboration with certification agencies, government auditors, or authorization officers.
- Thorough knowledge of UK Cyber Essentials, ISO 27001, ISO 9001, ISO 42001, SOC 2, or similar standards, plus understanding of GCC sovereign security frameworks like Qatar NCSA NIA, KSA SCCC/NCA, UAE DESC/NESA.
- Understanding of EMEA data privacy and AI regulatory landscapes such as GDPR, Qatar PDPPL, and the EU AI Act, and their translation into technical and organizational controls.
- Proven ability handling controls mapping, evidence aggregation, remediation tracking, and audit coordination across decentralized engineering teams.
- Experience with cloud platforms including AWS, Microsoft Azure, or Google Cloud Platform, and evaluating cloud infrastructures relative to compliance demands.
- Excellent communication abilities, good judgment on escalation matters, and capability to operate independently within a region while syncing with global programs.
Preferred Qualifications
- Certifications like CISSP, CISM, CISA, ISO 27001 Lead Auditor, ISO 42001 Internal Auditor, or CCSP are advantageous.
- Exposure to NATO information assurance standards and defense procurement criteria.
- Knowledge of healthcare or medical device regulatory requirements relevant to the EMEA region, especially GCC and the UK.
- Working proficiency in Arabic language.
- Security clearances such as UK SC or DV or eligibility for equivalent clearances in EMEA.
- Experience garnered at a Big Four consulting firm or within fast-expanding technology enterprises.
Additional Information
Applicants based in Qatar must have appropriate residency and employment permissions from Qatari authorities. The hiring process involves collection of personal details solely for immigration compliance, and visa issuance is conditional upon governmental discretion. Successful applicants will be supported through visa documentation procedures.
Note that Scale maintains a 90-day waiting period between applications for the same position to ensure fair evaluation. The company is dedicated to an inclusive work environment offering equal opportunity and reasonable accommodations for disabilities.
Personal data collected throughout the application process is handled in accordance with internal privacy policies and relevant legal standards, focusing on professional recruitment purposes exclusively.
About Scale AI
Scale AI’s objective is to create trustworthy AI systems that assist vital decision-making globally. By providing premium-quality data and comprehensive tech solutions, Scale supports leading AI models and aids enterprises and governments in deploying impactful AI applications. The company partners with respected organizations such as Meta, Ernst & Young, Mayo Clinic, government entities in Qatar, and several US military agencies, and is expanding rapidly to advance AI development.