- Company Name
- DigiCert
- Job Title
- Senior Trust Assurance Specialist
- Job Description
-
**Job title:** Senior Trust Assurance Specialist
**Role Summary:** Lead and manage compliance, risk and audit activities for digital trust services, ensuring adherence to global cybersecurity standards (ISO 27001, NIST, WebTrust, etc.). Act as primary liaison with regulators, auditors, and internal stakeholders to maintain and enhance the organization’s trust framework.
**Expectations:**
- Maintain 100 % compliance with all applicable regulations and industry standards.
- Deliver audit readiness and successful outcomes for SOC 2, WebTrust and other external reviews.
- Provide strategic risk insights to executive leadership and influence policy development.
**Key Responsibilities:**
- Define, implement and monitor compliance controls for WebTrust for CAs, ISO 27001, NIST 800‑53 r5, NIST 800‑63, FISMA, FIPS 140‑2/3, and related frameworks.
- Lead preparation and execution of internal and external audits (SOC 2, WebTrust, etc.).
- Advise on risk management initiatives and contribute to the organization’s risk register.
- Draft, review and update internal policies, procedures and control designs to meet security requirements.
- Coordinate cross‑functional collaboration with Security, IT, Legal, Operations, Finance, HR etc. to align compliance objectives.
- Act as primary point of contact for regulatory bodies, auditors and external agencies, managing communications and inspections.
- Monitor emerging regulatory trends, assess impacts and recommend program adjustments.
- Promote a culture of compliance and security organization‑wide.
**Required Skills:**
- Strong analytical, organizational and communication abilities.
- Deep knowledge of PKI, digital certificates, cryptographic principles and security controls.
- Experience managing compliance and risk management software tools.
- Proven ability to engage with auditors, regulators and external stakeholders.
**Required Education & Certifications:**
- Bachelor’s degree in law, compliance, computer science or related field.
- Minimum 5 years experience in compliance, risk management or internal audit, preferably in cybersecurity, PKI or cloud environments.
- Certifications: CISSP, CISM, CISA or CRISC (highly desirable).