About this role.
Smartsheet is seeking a Senior Security Engineer I to lead Customer Trust operations across EMEA, focusing on responding to security questionnaires, managing vendor risk assessments, and building trusted relationships with enterprise customers. This remote role, based in the UK, requires deep knowledge of GDPR and EU data protection regulations, as well as experience with GRC frameworks like SOC 2 and ISO 27001. The engineer will collaborate closely with EMEA sales teams to ensure high responsiveness and technical credibility. The position demands excellent communication skills and the ability to manage multiple concurrent assessments efficiently.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
4/5Pace & Pressure
3/5Autonomy Level
4/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Cover letter sample
Dear Hiring Manager,
I am excited to apply for the Senior Security Engineer I, Customer Trust EMEA role at Smartsheet. With over 5 years of experience in customer-facing security assessments and vendor risk management, including deep expertise in GDPR and EU data protection frameworks, I am well-prepared to lead your EMEA Customer Trust operations. My background includes successfully responding to complex security questionnaires and managing vendor risk for cloud platforms, ensuring both responsiveness and technical credibility. I thrive in remote environments and enjoy collaborating with sales teams to build trust with enterprise customers. I look forward to contributing to Smartsheet's mission of uniting human teams with AI agents by fostering security confidence across the EMEA region.
Sample interview questions
I have worked on multiple GDPR assessments, including drafting DPIAs and responding to detailed security questionnaires. For example, at my last company, I led the completion of a comprehensive GDPR assessment for a major financial client, ensuring all data processing activities were mapped and risks mitigated. My approach involves collaborating with legal, security, and engineering teams to gather precise information and clearly communicate our compliance posture.
I use a ticketing system to track all incoming requests and categorize them based on urgency, complexity, and customer tier. I set internal deadlines ahead of SLAs and communicate proactively with stakeholders if any risks arise. By maintaining a repository of pre-approved responses and collaborating with subject matter experts, I can streamline completion without compromising accuracy.
SOC 2 Type I evaluates the design of controls at a specific point in time, while Type II assesses the operational effectiveness of controls over a period, usually 6-12 months. For SaaS customers, Type II is generally more relevant because it provides assurance that controls are not just designed but also functioning over time. Most enterprise customers require Type II as evidence of ongoing security posture.
I would use simple analogies and visual aids, focusing on business outcomes rather than technical jargon. For instance, I would compare encryption to a secure lockbox with keys held by authorized personnel only. I would also reference familiar concepts like data residency and access controls, demonstrating how our architecture aligns with local regulations without overwhelming the audience with technical details.
I have hands-on experience with OneTrust for vendor risk management, including automating questionnaire distribution and tracking assessment workflows. I also used Targhee to manage security assessment requests and maintain a centralized knowledge base. These tools helped me reduce turnaround time by 30% and ensured consistent, audit-ready responses.
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.
Smartsheet’s customers in Europe, the Middle East, and Africa expect our Customer Trust team to understand their compliance challenges, speak their language, and respond quickly to security assessments. We’re looking for a Sr. Security Engineer I to lead Customer Trust operations across EMEA—responding to security questionnaires, managing vendor risk assessments, and building trusted relationships with enterprise customers in these regions. You will be responsible for questionnaire triage, completion, and queue management for EMEA customers. You’ll work closely with EMEA sales teams, understand regional compliance requirements (GDPR, EU data protection, sector-specific frameworks), and ensure Smartsheet maintains a strong reputation for responsiveness and technical credibility in these high-value markets.
You will work remotely from the UK and report to our Sr. Director, GRC Engineering, based in the US
You Have
- 5+ years of experience in customer trust, vendor risk management, security assessment, or customer-facing security roles at SaaS or cloud platform companies.
- Proven experience completing and responding to customer security questionnaires, vendor assessments, and RFIs.
- Strong understanding of GDPR, EU data protection, and regional compliance requirements: Familiarity with data residency, data processing agreements, DPIAs, and how cloud services operate within EU regulatory frameworks.
- Knowledge of GRC frameworks: Working knowledge of SOC 2, ISO 27001, and compliance standards commonly referenced in EMEA assessments.
- Solid technical security foundation: Understanding of cloud architecture, access controls, encryption, incident response, data handling, and security best practices sufficient to provide credible responses to technical questions.
- A degree in Computer Science, Computer Engineering, Cybersecurity or a related field or equivalent practical experience.
- Excellent written and verbal communication: Ability to explain technical security concepts clearly to both technical and non-technical stakeholders, and to adapt communication style for different audiences.
- Queue and project management skills: Comfort with ticketing systems, SLA tracking, and managing multiple concurrent questionnaires and customer interactions.
- Eligible to work in the United Kingdom.
Nice to Have
- Fluency in an additional European language. Ability to respond to technical security questions in multiple languages.
- Professional security certifications: CISSP, CCSK, CISM, CompTIA Security+, or equivalent.
- Background in SaaS customer trust or security operations in European companies.
- Experience with industry-specific EMEA compliance requirements (financial services, healthcare, government contracting).
- Familiarity with tools and platforms used for questionnaire management and vendor risk (Targhee, OneTrust, SAFE, or similar).
Perks & Benefits:
- Employer-paid Private Medical and Dental, additional cost for family members
- Monthly contributions toward your pension
- Monthly stipend to support your work and productivity
- 25 days paid for Holiday + Bank Holidays + Flexible Time Away Program
- 20 weeks fully paid Maternity Leave
- 12 weeks fully paid Paternity/Adoption Leave
- Personal paid Volunteer Day to support our community
- Opportunities for professional growth and development, including access to Udemy online courses
- Company Funded Perks, including a counselling membership, salary sacrifice options, and your own personal Smartsheet account.
- Teleworking options from any registered location in the UK (role-specific)
Get to Know Us:
At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.
Equal Opportunity Employer:
Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, India, and Singapore. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.
If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.
#LI-Remote
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.



