Senior Security Engineer I, Customer Trust EMEA
Job description
About the role
This role supports security assessment operations for EMEA while Smartsheet integrates human teams with AI agents. The position manages questionnaires and vendor risk for European, Middle Eastern, and African customers. Director, GRC Engineering, based in the US.
Security professionals protect systems, data, and users. They review code, run tests, monitor threats, and respond to incidents. The field spans application security, infrastructure security, and governance. Security work is careful, evidence based, and constantly evolving. Security teams work in a landscape of constant change, with new threats and new rules every year. Most companies invest heavily in training and tooling for their teams.
Key facts
What you'll do
Triage, complete, and manage security questionnaires for EMEA customers to ensure timely and accurate responses.
Organize workflows and monitor service levels so multiple concurrent assessments progress on schedule.
Interpret regional compliance requirements such as GDPR, EU data protection, and sector-specific frameworks to answer customer questions.
Use familiarity with GRC frameworks such as SOC 2 and ISO 27001 when evaluating and documenting compliance.
Communicate in additional European languages when needed to respond to security questions.
Requirements
The posting states a minimum of 20 years of experience.
5+ years of experience in customer trust, vendor risk management, security assessment, or customer-facing security roles at SaaS or cloud platform companies.
Proven experience completing and responding to customer security questionnaires, vendor assessments, and RFIs.
Strong understanding of GDPR, EU data protection regulations, data residency, data processing agreements, DPIAs, and how cloud services operate within EU regulatory frameworks.
Working knowledge of SOC 2, ISO 27001, and other compliance standards commonly referenced in EMEA assessments.
Solid technical security foundation covering cloud architecture, access controls, encryption, incident response, data handling, and security best practices.
A degree in Computer Science, Computer Engineering, Cybersecurity or a related field or equivalent practical experience.
Excellent written and verbal communication skills to adapt explanations for technical and non-technical audiences.
Comfort with ticket systems, SLA tracking, and managing multiple concurrent questionnaires and customer interactions.
Eligibility to work in the United Kingdom.
Nice to have
Fluency in an additional European language to respond to security questions in multiple languages.
Professional security certifications such as CISSP, CCSK, CISM, or CompTIA Security+.
Background in SaaS customer trust or security operations in European companies.
Experience with EMEA industry-specific compliance requirements in financial services, healthcare, or government contracting.
Familiarity with questionnaire management and vendor risk tools such as Targhee, OneTrust, SAFE, or similar platforms.
Practical notes
This role is based in the UK and requires eligibility to work in the country.
Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.
Good to know
Roles in Customer Trust focus on compliance, security assessments, and client communication in regulated markets.
The company is integrating AI agents with human teams to automate manual tasks and uncover insights at scale.
Security professionals in this role rely on frameworks such as SOC 2 and ISO 27001 when evaluating controls.
Cloud security topics such as identity, encryption, and data handling are central to day-to-day work.