EMEA Assurance Lead
Scale AI · Doha, Qatar; London, UK; Dubai, UAE · Legal & GRC · listed June 26, 2026
The shape of it
Seniority
Senior
Experience asked
7+ years
Where
Not stated
Requirements listed
8
Length
1,140 words
In the posting’s own words
Scale seeks an EMEA Assurance Lead to drive assurance programs across Scale's EMEA public sector and commercial business. Reporting to the Head of Global Assurance, this is a hands-on individual contributor role with significant autonomy. You will independently design and own EMEA-specific controls within Scale's global assurance framework, while staying tightly aligned with the global controls library and reporting cadences. You will be part of the global GRC team and work across Global Public Sector, Enterprise, Security, Engineering, Product, and Legal to deliver region-specific authorizations, certifications, and customer assurance outcomes across EMEA, with a focus on the GCC, UK, and EU markets.
What it asks for · 8
- 7+ years of experience in cybersecurity compliance, GRC, public sector assurance, IT audit, cloud security, or related roles, with meaningful exposure to EMEA markets.
- Deep familiarity with one or more of: UK Cyber Essentials/Cyber Essentials+, ISO 27001, ISO 9001, ISO 42001, SOC 2, or equivalent frameworks, and with sovereign security regimes in the GCC (e.g., Qatar NCSA NIA, KSA SCCC/NCA, UAE DESC/NESA).
- Familiarity with relevant EMEA data protection and AI governance requirements (e.g., GDPR, PDPPL, EU AI Act) and how they translate into technical and organisational controls.
- Experience with cloud environments (one or more of: AWS, Azure, GCP) and the ability to assess cloud architecture against compliance requirements.
- Strong communication skills, sound judgment on escalation, and the ability to operate autonomously in a region while maintaining alignment with a global program.
- Experience with NATO information assurance standards or defence procurement prerequisites.
- Familiarity with EMEA health-sector or medical-device regulatory requirements, particularly in the GCC and the UK.
- Working knowledge of Arabic.
Also a plus
- Relevant certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor, ISO 42001 Internal Auditor, or CCSP.
- Experience with NATO information assurance standards or defence procurement prerequisites.
- Familiarity with EMEA health-sector or medical-device regulatory requirements, particularly in the GCC and the UK.
- Working knowledge of Arabic.
- UK SC or DV clearance, or eligibility for equivalent EMEA government security clearances.
- Experience at a Big 4 firm or in a high-growth technology company.
Tools and skills named
Security & compliance
- Security7×
- Regulatory4×
- Audit2×
- GDPR2×
- SOC 22×
Cloud & infra
- AWS
- Azure
- GCP
Ways of working
- Technical writing
Words the posting leans on
- assurance17×
- emea13×
- controls11×
- global11×
- certification8×
- iso8×
- compliance6×
- experience6×
- public sector6×
- qatar6×
- security6×
- gcc5×
- information5×
- requirements5×
- data4×
- e.g4×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.
More open at Scale AI
- AI Advisory ConsultantSan Francisco, CA; New York, NY
- AI Advisory PrincipalSan Francisco, CA; New York, NY
- AI Applications Ops Manager, GPSDoha, Qatar
- AI Builder InternSan Francisco, CA
- AI Infrastructure Engineer, Model Serving PlatformSan Francisco, CA; New York, NY
- AI Infrastructure Engineer, Sandbox PlatformSan Francisco, CA; Seattle, WA; New York, NY