Responsibilities
- Respond to security questionnaires, vendor risk assessments, and RFIs from EMEA customers.
- Lead Customer Trust operations across EMEA.
- Manage questionnaire triage, completion, and queue management for EMEA customers.
- Work closely with EMEA sales teams.
- Understand regional compliance requirements including GDPR, EU data protection, and sector-specific frameworks.
- Ensure Smartsheet maintains a strong reputation for responsiveness and technical credibility in EMEA markets.
Requirements
- 5+ years of experience in customer trust, vendor risk management, security assessment, or customer-facing security roles at SaaS or cloud platform companies.
- Proven experience completing and responding to customer security questionnaires, vendor assessments, and RFIs.
- Strong understanding of GDPR, EU data protection, and regional compliance requirements.
- Familiarity with data residency, data processing agreements, DPIAs, and how cloud services operate within EU regulatory frameworks.
- Knowledge of GRC frameworks: Working knowledge of SOC 2, ISO 27001, and compliance standards commonly referenced in EMEA assessments.
- Solid technical security foundation: Understanding of cloud architecture, access controls, encryption, incident response, data handling, and security best practices sufficient to provide credible responses to technical questions.
- A degree in Computer Science, Computer Engineering, Cybersecurity or a related field or equivalent practical experience.
- Excellent written and verbal communication: Ability to explain technical security concepts clearly to both technical and non-technical stakeholders, and to adapt communication style for different audiences.
- Queue and project management skills: Comfort with ticketing systems, SLA tracking, and managing multiple concurrent questionnaires and customer interactions.
- Eligible to work in the United Kingdom.
Nice to Have
- Fluency in an additional European language.
- Ability to respond to technical security questions in multiple languages.
- Professional security certifications: CISSP, CCSK, CISM, CompTIA Security+, or equivalent.
- Background in SaaS customer trust or security operations in European companies.
- Experience with industry-specific EMEA compliance requirements (financial services, healthcare, government contracting).
- Familiarity with tools and platforms used for questionnaire management and vendor risk (Targhee, OneTrust, SAFE, or similar).
Benefits
- Employer-paid Private Medical and Dental, additional cost for family members
- Monthly contributions toward your pension
- Monthly stipend to support your work and productivity
- 25 days paid Holiday + Bank Holidays + Flexible Time Away Program
- 20 weeks fully paid Maternity Leave
- 12 weeks fully paid Paternity/Adoption Leave
- Personal paid Volunteer Day to support our community
- Opportunities for professional growth and development, including access to Udemy online courses
- Company Funded Perks, including a counselling membership, salary sacrifice options, and your own personal Smartsheet account.
- Teleworking options from any registered location in the UK (role-specific)
Work Arrangement
Remote (Country) — United Kingdom
Team
Reports to: Sr. Director, GRC Engineering, based in the US
Additional Information
- Remote work eligible from the UK
- Reports to Sr. Director, GRC Engineering, based in the US
- Equal Opportunity Employer: committed to fostering an inclusive environment
- Candidates can request accommodations for a comfortable and positive interview experience