Key Notes
Security assurance is being built from the ground up, with responsibility for control testing, evidence-based reporting and continuous validation. Essential experience covers assurance methodology, cloud-native and SaaS environments, control design and operating effectiveness, and stakeholder influence. The London-based GRC Assurance Manager supports TISAX, ISO 21434 and customer commitments through independent assurance and automated evidence collection.
What You'll Work On
- Design and operate Wayve’s security-assurance capability, including risk-based methodologies, structured testing plans and programme-level reporting outputs.
- Assess security-control design and operating effectiveness, documenting objective findings and tracking remediation through independent validation.
- Provide documented evidence for external assessments, security certifications and customer-assurance activity across the wider technology organisation.
- Automate security evidence collection with the Security Analytics Engineer, replacing selected manual reviews with scalable continuous validation.
- Improve the security-control framework by strengthening control design, measurable outcomes, testing consistency and organisation-wide assurance coverage.
Why This Role Matters
- TISAX, ISO 21434 and customer security commitments require evidence that relevant controls are designed and operating effectively, making assurance findings material to certification and contractual reviews.
- Wayve’s security programme is moving from periodic testing towards continuous validation; automated evidence collection expands the consistency and coverage available to technical and business stakeholders.
What They Are Looking For
- Experience: Designing, building or operating security or controls assurance in a modern technology environment is essential.
- Domain: Understanding security controls and evaluating both design and operating effectiveness is essential.
- Technical: Experience in cloud-native, SaaS-heavy environments and collaboration with engineering teams is essential.
- Experience: Assurance methodology, control testing and communication of outcomes to technical and non-technical stakeholders are essential.
- Stakeholder: Independent challenge, collaborative relationships and stakeholder influence are essential.
- Preferred: TISAX, ISO 21434, ISO 27001, SOC 2, continuous assurance or CISA and Lead Auditor certifications are desirable.