At a Glance
- Tasks: Lead assurance programs across EMEA, ensuring compliance with regional regulations and standards.
- Company: Join Scale, a leader in generative AI, driving innovation in the public sector.
- Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
- Other info: Dynamic role with significant autonomy and collaboration across global teams.
- Why this job: Make a real impact in the fast-paced world of AI and cybersecurity.
- Qualifications: 7+ years in cybersecurity compliance with experience in EMEA markets.
The predicted salary is between 80000 - 100000 £ per year.
Scale is powering the generative AI wave by providing the data and infrastructure for companies to build large‑scale foundation models. AI is rapidly changing the world, and Scale is growing to meet that rapid demand across global markets, including accelerating public sector business across EMEA. Scale seeks an EMEA Assurance Lead to drive assurance programs across Scale’s EMEA public sector and commercial business. Reporting to the Head of Global Assurance, this is a hands‑on individual‑contributor role with significant autonomy.
You will independently design and own EMEA‑specific controls within Scale’s global assurance framework, while staying tightly aligned with the global controls library and reporting cadences. You will be part of the global GRC team and work across Global Public Sector, Enterprise, Security, Engineering, Product, and Legal to deliver region‑specific authorizations, certifications and customer assurance outcomes across EMEA, with a focus on the GCC, UK and EU markets.
You Will
- Lead region‑specific assurance programs across the GCC and UK, including Qatar NCSA National Information Assurance (NIA), KSA NCA Essential Cybersecurity Controls (ECC), UAE DESC Information Security Regulation (ISR), and UK Cyber Essentials Plus, Defence Cyber Certification (DCC), and NCSC Secure by Design (SdB).
- Own controls mapping, evidence collection, gap analysis, certification timelines and submission management for each, working with accredited external assessors where required.
- Work with the global GRC team to maintain and renew Scale’s existing certifications and obtain new ones, including SOC 2, ISO 27001, ISO 42001 and ISO 9001.
- Own their extension to EMEA and international operations, including for NATO‑aligned defence tenders.
- Design and maintain EMEA‑specific controls, adapting Scale’s global controls framework to sovereign regulatory and customer requirements, including data residency and sector‑specific requirements (e.g., health sector), identifying where existing controls satisfy local standards and where new controls or evidence artifacts are needed.
- Set priorities and operating cadences for EMEA assurance workflows, including intake, evidence collection, control owner follow‑up, remediation tracking and deadline management, reporting progress through Scale’s global assurance dashboards.
- Support EMEA public sector customer assurance activities, including security questionnaires, compliance due diligence responses, customer‑facing assurance discussions and compliance input to bid and capture processes where assurance readiness is a procurement gate.
- Partner with Legal on EMEA contract‑driven assurance obligations, data protection and AI governance compliance intersections (e.g., GDPR, Qatar PDPPL, EU AI Act) and sensitive escalations involving sovereign regulators.
- Manage relationships with EMEA‑based external auditors, assessors, certification bodies and regulatory counterparts.
- Support internal and external audits across EMEA and report into the Head of Global Assurance on program health, key risks, certification timelines and regional regulatory developments.
Ideally, You’d Have
- 7+ years of experience in cybersecurity compliance, GRC, public sector assurance, IT audit, cloud security or related roles, with meaningful exposure to EMEA markets.
- Experience executing government or public sector assurance programs in the UK, EU or GCC, including working with external certification bodies, government assessors or authorizing officials.
- Deep familiarity with one or more of: UK Cyber Essentials/Cyber Essentials+, ISO 27001, ISO 9001, ISO 42001, SOC 2 or equivalent frameworks, and with sovereign security regimes in the GCC (e.g., Qatar NCSA NIA, KSA SCCC/NCA, UAE DESC/NESA).
- Familiarity with relevant EMEA data protection and AI governance requirements (e.g., GDPR, PDPPL, EU AI Act) and how they translate into technical and organisational controls.
- Experience managing controls mapping, evidence collection, remediation tracking and audit coordination across distributed engineering and infrastructure teams.
- Experience with cloud environments (one or more of: AWS, Azure, GCP) and the ability to assess cloud architecture against compliance requirements.
- Strong communication skills, sound judgment on escalation and the ability to operate autonomously in a region while maintaining alignment with a global program.
Nice to Have
- Relevant certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor, ISO 42001 Internal Auditor or CCSP.
- Experience with NATO information assurance standards or defence procurement prerequisites.
- Familiarity with EMEA health‑sector or medical‑device regulatory requirements, particularly in the GCC and the UK.
- Working knowledge of Arabic.
- UK SC or DV clearance, or eligibility for equivalent EMEA government security clearances.
- Experience at a Big 4 firm or in a high‑growth technology company.
We comply with the United States Department of Labor’s Pay Transparency provision. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability status, gender identity or Veteran status. We are committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. If you need assistance and/or a reasonable accommodation in the application or recruiting process due to a disability, please contact us at accommodations@scale.com.
EMEA Assurance Lead employer: Scale AI
At Scale, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration in the rapidly evolving field of generative AI. Our EMEA Assurance Lead role provides significant autonomy and the opportunity to drive impactful assurance programs across diverse markets, while our commitment to employee growth is reflected in our supportive environment and focus on professional development. With a strong emphasis on inclusivity and equal opportunity, we ensure that every team member can thrive and contribute meaningfully to our mission.