Senior Risk & Audit Specialist

Posted Yesterday
Be an Early Applicant
2 Locations
In-Office or Remote
Senior level
Cloud • Information Technology
A flexible cloud platform for responsibly building, running, and scaling fleets of websites and applications.
The Role
Coordinate and support external and internal audits (ISO 27001, SOC 2, PCI DSS, HIPAA), manage risk assessments, third-party risk reviews, evidence collection, control monitoring, remediation tracking, and compliance documentation. Collaborate cross-functionally to respond to customer security questions, improve processes, and report audit status and risks to leadership.
Summary Generated by Built In
About Upsun (formerly Platform.sh) 

Upsun is the cloud application platform humans and robots love. It is built for today’s hybrid teams, where AI agents write and test code and humans focus on solving the problems that really matter. Developers, DevOps engineers, and platform teams use Upsun to build, ship, and scale confidently without wrestling with backend infrastructure. We give you your time back. You get:

  • Predictable performance, even at scale
  • Secure, compliant environments by default 
  • Real-time observability and profiling built in
  • Cloning, configuration, and provisioning in seconds 
  • AI-ready features that plug directly into your stack

The name says it all. "Up" means uptime, reliability, and acceleration. "Sun" reflects our follow-the-sun-support, a 24x7, globally distributed support team keeping the lights on while you rest. Our core belief is that software should power brighter solutions and greater innovation.

Upsunners are a remote, global workforce, and we thrive in a multicultural team. We are committed to open source and an open, welcoming environment. Our team spans the globe and the experience spectrum.

What's our commonality, our cultural fabric? A curious spirit and a thirst for knowledge; an eagerness for innovative ideas and cultures. We believe we can build anything together in an environment that frees you to do your best work.

Our values: 

🌿 We make a positive impact.

✨ We aim for the stars.

💚 We care for each other. 

Impact of a Senior Risk & Audit Specialist 

As a Senior Risk & Audit Specialist at Upsun, you help keep our security, risk, audit, and compliance work moving with clarity, care, and consistency. Reporting to the Director, Risk & Audit, you'll work closely with teams across Security, Engineering, IT, Legal, Product, and Sales to keep key audits and certifications (including ISO 27001, SOC 2, PCI DSS, and HIPAA) on track and our global business audit-ready.

You're practical, organized, and curious; someone who enjoys making complex requirements easier to understand and thrives when balancing planned work with time-sensitive audit and customer requests. You partner with control owners across the business to coordinate evidence, monitor risk, and turn complex requirements into guidance that's easy to act on.

Beyond keeping audits on track, you contribute to the long-term evolution of our risk and compliance program by supporting readiness for new and expanding assurance needs, simplifying repeatable processes, and improving evidence quality. Your attention to detail, cross-functional mindset, and clear communication help leadership stay informed and give our customers confidence in our security posture.

What to expect
  • Audit & Certification Support: Support active and upcoming audits, including ISO 27001, SOC 2, PCI DSS, HIPAA, and other relevant assurance work by coordinating evidence collection, reviewing evidence quality, scheduling walkthroughs, and following up with control owners.

  • Risk & Control Management: Support risk assessments, risk register updates, control monitoring, issue tracking, and risk treatment follow-up by working with teams to identify control gaps, agree on practical actions, and track remediation through to completion.

  • Third-Party Risk Management: Conduct third-party risk management reviews to support a comprehensive view of organizational risk.

  • Compliance Program Support: Support ongoing compliance activities across established frameworks and emerging readiness work (including Australia ISM/IRAP/HCF, NIS2, and ISO 42001/AIM) while maintaining policies, procedures, control narratives and supporting documentation.

  • Customer & Stakeholder Support: Respond to customer and prospect security or compliance questions in partnership with Sales, Legal, Security, and Product, and support updates to the Trust Center and other trust documentation.

  • Reporting & Continuous Improvement: Prepare clear updates on audit status, risks, blockers, metrics, and remediation progress for leadership and look for opportunities to simplify repeatable processes and reduce audit friction for control owners.

  • Tooling & Process Management: Use risk, audit, and compliance tools to keep work organized, traceable, and easy to report on.

  • Internal Audit Support: Support internal audit and review activities as needed.

What you bring
  • Risk & Compliance Experience: 5+ years of experience in risk, audit, compliance, governance, security assurance, or a closely related area.

  • Audit Experience: Hands-on experience supporting audits, evidence collection, control testing or monitoring, and remediation tracking.

  • Framework Knowledge: Working knowledge of security and compliance frameworks such as ISO 27001, SOC 2, PCI DSS, HIPAA, ISO 42001, GDPR, PIPEDA or similar standards.

  • Communication Skills: Ability to explain requirements clearly to both technical and non-technical audiences.

  • Organization & Prioritization: Strong organization and prioritization skills, especially when managing several deadlines at once.

  • Judgment & Problem-Solving: Good judgement, attention to detail, and a practical approach to solving problems.

  • Remote & Cross-Functional Collaboration: Comfort working in a remote, global environment with cross-functional teams across varied timezones.


Bonus Points
  • Experience with governance, risk, and compliance tools or audit management platforms

  • Experience supporting customer assurance, security questionnaires, or trust documentation

  • Working knowledge of Third-party risk management (TPRM)

  • Relevant certifications such as CISA, CRISC, CISSP, CC, CISM, CGEIT, ISO 27001, ISO 42001 or similar

Where we hire

At Upsun, remote work isn't just a trend - it's our foundation. The freedom of remote work with the support of a diverse, global team has been our successful model for over a decade. Our culture celebrates flexibility and collaboration, and while we have team members in over 30 countries around the globe, we are currently focused on hiring for this role in Canada, Spain, Germany, France, or the United Kingdom. Although we’re unable to provide visa sponsorship at this time, we welcome applications from all qualified candidates who are legally authorized to work in these countries. 

How we hire

We know that a great hire won’t meet every requirement that we’ve outlined. If you can see yourself elevating the team, we want to hear your story. Few of us would be here had we not taken a chance.
You can expect 5 interviews
to follow the order below. Should you successfully move through the entire process you will have the opportunity to meet with a variety of Upsunners. Our goal is to ensure you can make the most informed decision on whether this role, and our culture aligns with what you’re looking for in your future working environment. 

  1. 45 Minutes with Talent Acquisition 
  2. 60 Minutes with Hiring Manager (Director, Risk & Audit)
  3. 60 Minutes with Team (IC's)
  4. 60 Minutes Cross Team (Leaders)
  5. 45 Minutes with Executive (CFO)

All roles require background checks.

What we offer

💡 A product you can believe in - Join us in transforming how businesses build and manage web applications, driven making a positive impact as a proud B Corp.

🏆 An Award-Winning Workplace - We’ve been recognized by Forbes’ Top 30 Companies for Remote Jobs and France’s Best Workplaces for Women.

🗣️ A culture that values your voice - Join a flexible, open, and inclusive work environment where your voice is encouraged, and your ideas shape our growth and evolution.

🌎 A global team - Collaborate with colleagues from diverse backgrounds across the world, embracing different perspectives

🎉 Benefits and perks - Make the most of what matters to you

🏝 Flexible PTO

🩺 Comprehensive healthcare coverage (UK, Canada, France, Spain, USA)

📈 Company stock options

🧠 Professional development budget

💻 Office equipment budget

💆‍♀️ Wellness budget

🧳 Annual team gatherings

🛜 Internet reimbursement

👶 Inclusive parental leave

✈️ Remote work travel program

You belong here

At Upsun, we celebrate diversity in all its forms and are committed to fostering an inclusive, equitable, and supportive workplace where everyone can thrive. We embrace and value different perspectives, backgrounds, and experiences, because they make us stronger as a team. Whoever you are, wherever you're from, and whatever path you've taken, you are welcome here. We encourage you to bring your whole self to work, connect with others, and share your passion. If you need accommodations at any stage of our hiring process, please let us know. We're here to ensure an accessible and comfortable experience for you.

Skills Required

  • 5+ years experience in risk, audit, compliance, governance, or security assurance
  • Hands-on experience supporting audits, evidence collection, control testing/monitoring, and remediation tracking
  • Working knowledge of security and compliance frameworks (ISO 27001, SOC 2, PCI DSS, HIPAA, ISO 42001, GDPR, PIPEDA, etc.)
  • Ability to explain requirements clearly to technical and non-technical audiences
  • Strong organization and prioritization skills to manage multiple deadlines
  • Good judgment, attention to detail, and practical problem-solving skills
  • Comfort working remotely in a global, cross-functional environment across time zones
  • Willingness to complete background checks
  • Legal authorization to work in Canada, Spain, Germany, France, or the United Kingdom (no visa sponsorship)
  • Experience with governance, risk, and compliance (GRC) tools or audit management platforms
  • Experience supporting customer assurance, security questionnaires, or trust documentation
  • Working knowledge of third-party risk management (TPRM)
  • Relevant certifications (CISA, CRISC, CISSP, CISM, CGEIT, ISO 27001, ISO 42001 or similar)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Köln
396 Employees
Year Founded: 2015

What We Do

Platform.sh is an end-to-end cloud application Platform as a Service to build, run and scale fleets of websites and applications. Founded in 2015, the company is headquartered in Paris and San Francisco. Platform.sh employs nearly 400 people across 38 countries and is available in Europe, the United States and Asia, through global partnerships with AWS, GCP, Azure, Orange and OVHcloud. A member of the FrenchTech 120 and Gaia-X, Platform.sh was recently included in the FT1000 list of fastest-growing European companies. Offering a 100% remote working environment the company is a certified "Great Place to Work". Customers include prestigious brands such as Adobe Magento, Gap, Nestlé, Orange, The British Council, The Financial Times and Unicef.

Why Work With Us

Platform.sh runs on three core pillars that set us apart from other companies: We strive for positive impact, we care for each other, and we’re here to help our customers thrive. Our focus lies on the environment as a whole, our employees, and our customers. We are human-centric and take actionable steps to unlock the full potential of our values.

Gallery

Gallery

Similar Jobs

PwC Logo PwC

Consultant

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
65 Locations
370000 Employees
124K-280K Annually

PwC Logo PwC

Salesforce Consulting Senior Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
63 Locations
370000 Employees
124K-280K Annually

PwC Logo PwC

Finance & Accounting - Custom App Dev - Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
65 Locations
370000 Employees
99K-232K Annually

Block Logo Block

Account Manager

Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
In-Office or Remote
London, Greater London, England, GBR
12000 Employees

Similar Companies Hiring

Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account