Skip to main content
Back to jobs

Senior Risk & Audit Specialist

External
remotewoman logoRemotewoman · The, UK
Full-timeRemoteToday
ComplianceDocumentationGDPRHIPAALeadershipObservability
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


Responsibilities

  • Audit & Certification Support: Support active and upcoming audits, including ISO 27001, SOC 2, PCI DSS, HIPAA, and other relevant assurance work by coordinating evidence collection, reviewing evidence quality, scheduling walkthroughs, and following up with control owners.
  • Risk & Control Management: Support risk assessments, risk register updates, control monitoring, issue tracking, and risk treatment follow-up by working with teams to identify control gaps, agree on practical actions, and track remediation through to completion.
  • Third-Party Risk Management: Conduct third-party risk management reviews to support a comprehensive view of organizational risk.
  • Compliance Program Support: Support ongoing compliance activities across established frameworks and emerging readiness work (including Australia ISM/IRAP/HCF, NIS2, and ISO 42001/AIM) while maintaining policies, procedures, control narratives and supporting documentation.
  • Customer & Stakeholder Support: Respond to customer and prospect security or compliance questions in partnership with Sales, Legal, Security, and Product, and support updates to the Trust Center and other trust documentation.
  • Reporting & Continuous Improvement: Prepare clear updates on audit status, risks, blockers, metrics, and remediation progress for leadership and look for opportunities to simplify repeatable processes and reduce audit friction for control owners.
  • Tooling & Process Management: Use risk, audit, and compliance tools to keep work organized, traceable, and easy to report on.
  • Internal Audit Support: Support internal audit and review activities as needed.
  • What you bring
  • Risk & Compliance Experience: 5+ years of experience in risk, audit, compliance, governance, security assurance, or a closely related area.
  • Audit Experience: Hands-on experience supporting audits, evidence collection, control testing or monitoring, and remediation tracking.
  • Framework Knowledge: Working knowledge of security and compliance frameworks such as ISO 27001, SOC 2, PCI DSS, HIPAA, ISO 42001, GDPR, PIPEDA or similar standards.
  • Communication Skills: Ability to explain requirements clearly to both technical and non-technical audiences.
  • Organization & Prioritization: Strong organization and prioritization skills, especially whe

Benefits

Vision insuranceRemote work options

Additional Information

About Upsun (formerly Platform.sh) Upsun is the cloud application platform humans and robots love. It is built for today's hybrid teams, where AI agents write and test code and humans focus on solving the problems that really matter. Developers, DevOps engineers, and platform teams use Upsun to build, ship, and scale confidently without wrestling with backend infrastructure. We give you your time back. You get: Predictable performance, even at scale Secure, compliant environments by default Real-time observability and profiling built in Cloning, configuration, and provisioning in seconds AI-ready features that plug directly into your stack The name says it all. "Up" means uptime, reliability, and acceleration. "Sun" reflects our follow-the-sun-support, a 24x7, globally distributed support team keeping the lights on while you rest. Our core belief is that software should power brighter solutions and greater innovation. Upsunners are a remote, global workforce, and we thrive in a multicultural team. We are committed to open source and an open, welcoming environment. Our team spans the globe and the experience spectrum. What's our commonality, our cultural fabric? A curious spirit and a thirst for knowledge; an eagerness for innovative ideas and cultures. We believe we can build anything together in an environment that frees you to do your best work. Our values: 🌿 We make a positive impact. ✨ We aim for the stars. 💚 We care for each other. Impact of a Senior Risk & Audit Specialist As a Senior Risk & Audit Specialist at Upsun, you help keep our security, risk, audit, and compliance work moving with clarity, care, and consistency. Reporting to the Director, Risk & Audit, you'll work closely with teams across Security, Engineering, IT, Legal, Product, and Sales to keep key audits and certifications (including ISO 27001, SOC 2, PCI DSS, and HIPAA) on track and our global business audit-ready. You're practical, organized, and curious; someone who enjoys making complex requirements easier to understand and thrives when balancing planned work with time-sensitive audit and customer requests. You partner with control owners across the business to coordinate evidence, monitor risk, and turn complex requirements into guidance that's easy to act on. Beyond keeping audits on track, you contribute to the long-term evolution of our risk and compliance program by supporting readiness for new and expanding assurance needs, simplifying repeatable processes, and improving evidence quality. Your attention to detail, cross-functional mindset, and clear communication help leadership stay informed and give our customers confidence in our security posture.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at remotewoman? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect