EMEA Assurance Lead

Scale AI · Doha, Qatar; London, UK; Dubai, UAE · Legal & GRC · listed June 26, 2026

The shape of it

Seniority
Senior
Experience asked
7+ years
Where
Not stated
Requirements listed
8
Length
1,140 words

In the posting’s own words

Scale seeks an EMEA Assurance Lead to drive assurance programs across Scale's EMEA public sector and commercial business. Reporting to the Head of Global Assurance, this is a hands-on individual contributor role with significant autonomy. You will independently design and own EMEA-specific controls within Scale's global assurance framework, while staying tightly aligned with the global controls library and reporting cadences. You will be part of the global GRC team and work across Global Public Sector, Enterprise, Security, Engineering, Product, and Legal to deliver region-specific authorizations, certifications, and customer assurance outcomes across EMEA, with a focus on the GCC, UK, and EU markets.

What it asks for · 8

  • 7+ years of experience in cybersecurity compliance, GRC, public sector assurance, IT audit, cloud security, or related roles, with meaningful exposure to EMEA markets.
  • Deep familiarity with one or more of: UK Cyber Essentials/Cyber Essentials+, ISO 27001, ISO 9001, ISO 42001, SOC 2, or equivalent frameworks, and with sovereign security regimes in the GCC (e.g., Qatar NCSA NIA, KSA SCCC/NCA, UAE DESC/NESA).
  • Familiarity with relevant EMEA data protection and AI governance requirements (e.g., GDPR, PDPPL, EU AI Act) and how they translate into technical and organisational controls.
  • Experience with cloud environments (one or more of: AWS, Azure, GCP) and the ability to assess cloud architecture against compliance requirements.
  • Strong communication skills, sound judgment on escalation, and the ability to operate autonomously in a region while maintaining alignment with a global program.
  • Experience with NATO information assurance standards or defence procurement prerequisites.
  • Familiarity with EMEA health-sector or medical-device regulatory requirements, particularly in the GCC and the UK.
  • Working knowledge of Arabic.

Also a plus

  • Relevant certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor, ISO 42001 Internal Auditor, or CCSP.
  • Experience with NATO information assurance standards or defence procurement prerequisites.
  • Familiarity with EMEA health-sector or medical-device regulatory requirements, particularly in the GCC and the UK.
  • Working knowledge of Arabic.
  • UK SC or DV clearance, or eligibility for equivalent EMEA government security clearances.
  • Experience at a Big 4 firm or in a high-growth technology company.

Tools and skills named

Security & compliance
  • Security7×
  • Regulatory4×
  • Audit2×
  • GDPR2×
  • SOC 22×
Cloud & infra
  • AWS
  • Azure
  • GCP
Ways of working
  • Technical writing

Words the posting leans on

  • assurance17×
  • emea13×
  • controls11×
  • global11×
  • certification8×
  • iso8×
  • compliance6×
  • experience6×
  • public sector6×
  • qatar6×
  • security6×
  • gcc5×
  • information5×
  • requirements5×
  • data4×
  • e.g4×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Scale AI

every open role at Scale AI

How this page was made

An automated read of a public job posting, fetched August 26, 2026 and last changed by Scale AI on August 17, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.