Upsun is the cloud application platform humans and robots love. It is built for today's hybrid teams, where AI agents write and test code and humans focus on solving the problems that really matter. Developers, DevOps engineers, and platform teams use Upsun to build, ship, and scale confidently without wrestling with backend infrastructure. We give you your time back. You get:
- Predictable performance, even at scale
- Secure, compliant environments by default
- Real-time observability and profiling built in
- Cloning, configuration, and provisioning in seconds
- AI-ready features that plug directly into your stack
The name says it all. "Up" means uptime, reliability, and acceleration. "Sun" reflects our follow-the-sun-support, a 24x7, globally distributed support team keeping the lights on while you rest. Our core belief is that software should power brighter solutions and greater innovation.
Upsunners are a remote, global workforce, and we thrive in a multicultural team. We are committed to open source and an open, welcoming environment. Our team spans the globe and the experience spectrum.
What's our commonality, our cultural fabric? A curious spirit and a thirst for knowledge; an eagerness for innovative ideas and cultures. We believe we can build anything together in an environment that frees you to do your best work.
Our values:
We make a positive impact.
✨ We aim for the stars.
We care for each other.
As a Senior Risk & Audit Specialist at Upsun, you help keep our security, risk, audit, and compliance work moving with clarity, care, and consistency. Reporting to the Director, Risk & Audit, you'll work closely with teams across Security, Engineering, IT, Legal, Product, and Sales to keep key audits and certifications (including ISO 27001, SOC 2, PCI DSS, and HIPAA) on track and our global business audit-ready.
You're practical, organized, and curious; someone who enjoys making complex requirements easier to understand and thrives when balancing planned work with time-sensitive audit and customer requests. You partner with control owners across the business to coordinate evidence, monitor risk, and turn complex requirements into guidance that's easy to act on.
Beyond keeping audits on track, you contribute to the long-term evolution of our risk and compliance program by supporting readiness for new and expanding assurance needs, simplifying repeatable processes, and improving evidence quality. Your attention to detail, cross-functional mindset, and clear communication help leadership stay informed and give our customers confidence in our security posture.
Audit & Certification Support: Support active and upcoming audits, including ISO 27001, SOC 2, PCI DSS, HIPAA, and other relevant assurance work by coordinating evidence collection, reviewing evidence quality, scheduling walkthroughs, and following up with control owners.
Risk & Control Management: Support risk assessments, risk register updates, control monitoring, issue tracking, and risk treatment follow-up by working with teams to identify control gaps, agree on practical actions, and track remediation through to completion.
Third-Party Risk Management: Conduct third-party risk management reviews to support a comprehensive view of organizational risk.
Compliance Program Support: Support ongoing compliance activities across established frameworks and emerging readiness work (including Australia ISM/IRAP/HCF, NIS2, and ISO 42001/AIM) while maintaining policies, procedures, control narratives and supporting documentation.
Customer & Stakeholder Support: Respond to customer and prospect security or compliance questions in partnership with Sales, Legal, Security, and Product, and support updates to the Trust Center and other trust documentation.
Reporting & Continuous Improvement: Prepare clear updates on audit status, risks, blockers, metrics, and remediation progress for leadership and look for opportunities to simplify repeatable processes and reduce audit friction for control owners.
Tooling & Process Management: Use risk, audit, and compliance tools to keep work organized, traceable, and easy to report on.
Internal Audit Support: Support internal audit and review activities as needed.
Risk & Compliance Experience: 5+ years of experience in risk, audit, compliance, governance, security assurance, or a closely related area.
Audit Experience: Hands-on experience supporting audits, evidence collection, control testing or monitoring, and remediation tracking.
Framework Knowledge: Working knowledge of security and compliance frameworks such as ISO 27001, SOC 2, PCI DSS, HIPAA, ISO 42001, GDPR, PIPEDA or similar standards.
Communication Skills: Ability to explain requirements clearly to both technical and non-technical audiences.
Organization & Prioritization: Strong organization and prioritization skills, especially when managing several deadlines at once.
Judgment & Problem-Solving: Good judgement, attention to detail, and a practical approach to solving problems.
Remote & Cross-Functional Collaboration: Comfort working in a remote, global environment with cross-functional teams across varied timezones.
Experience with governance, risk, and compliance tools or audit management platforms
Experience supporting customer assurance, security questionnaires, or trust documentation
Working knowledge of Third-party risk management (TPRM)
Relevant certifications such as CISA, CRISC, CISSP, CC, CISM, CGEIT, ISO 27001, ISO 42001 or similar
At Upsun, remote work isn't just a trend - it's our foundation. The freedom of remote work with the support of a diverse, global team has been our successful model for over a decade. Our culture celebrates flexibility and collaboration, and while we have team members in over 30 countries around the globe, we are currently focused on hiring for this role in Canada, Spain, Germany, France, or the United Kingdom. Although we're unable to provide visa sponsorship at this time, we welcome applications from all qualified candidates who are legally authorized to work in these countries.
We know that a great hire won't meet every requirement that we've outlined. If you can see yourself elevating the team, we want to hear your story. Few of us would be here had we not taken a chance.
You can expect 5 interviews to follow the order below. Should you successfully move through the entire process you will have the opportunity to meet with a variety of Upsunners. Our goal is to ensure you can make the most informed decision on whether this role, and our culture aligns with what you're looking for in your future working environment.
- 45 Minutes with Talent Acquisition
- 60 Minutes with Hiring Manager (Director, Risk & Audit)
- 60 Minutes with Team (IC's)
- 60 Minutes Cross Team (Leaders)
- 45 Minutes with Executive (CFO)
All roles require background checks.
A product you can believe in - Join us in transforming how businesses build and manage web applications, driven making a positive impact as a proud B Corp.
An Award-Winning Workplace - We've been recognized by Forbes' Top 30 Companies for Remote Jobs and France's Best Workplaces for Women.
️ A culture that values your voice - Join a flexible, open, and inclusive work environment where your voice is encouraged, and your ideas shape our growth and evolution.
A global team - Collaborate with colleagues from diverse backgrounds across the world, embracing different perspectives
Benefits and perks - Make the most of what matters to you
Flexible PTO
Comprehensive healthcare coverage (UK, Canada, France, Spain, USA)
Company stock options
Professional development budget
Office equipment budget
️ Wellness budget
Annual team gatherings
Internet reimbursement
Inclusive parental leave
✈️ Remote work travel program
At Upsun, we celebrate diversity in all its forms and are committed to fostering an inclusive, equitable, and supportive workplace where everyone can thrive. We embrace and value different perspectives, backgrounds, and experiences, because they make us stronger as a team. Whoever you are, wherever you're from, and whatever path you've taken, you are welcome here. We encourage you to bring your whole self to work, connect with others, and share your passion. If you need accommodations at any stage of our hiring process, please let us know. We're here to ensure an accessible and comfortable experience for you.