At a Glance
- Tasks: Lead security assurance for AI infrastructure and manage audit readiness across global operations.
- Company: Join Nscale, a cutting-edge GPU cloud provider for AI innovation.
- Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
- Other info: Diverse and inclusive workplace with a focus on innovation and accountability.
- Why this job: Shape the future of AI technology while ensuring security and compliance.
- Qualifications: 5+ years in security assurance with hands-on experience in SOC 2 and ISO standards.
The predicted salary is between 80000 - 100000 £ per year.
About Nscale
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers.
Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development.
Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency.
As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work.
If you join our team, you’ll be contributing to building the technology that powers the future.
About The Role
Nscale is hiring a Staff Engineer, Security Assurance & Audit to lead a high-rigor, audit-ready assurance function across Nscale's global AI infrastructure.
This is a hands-on senior individual contributor role with significant scope.
You will own the operating model that allows Nscale to meet customer commitments, expand certification scope, maintain audit readiness, and produce defensible evidence for external auditors and enterprise customers.
As Nscale scales global AI infrastructure, we need a technical assurance leader who can turn customer commitments, certification requirements, and control obligations into durable programs, clear ownership, strong evidence, and repeatable execution.
This role sits at the intersection of security, audit, compliance, infrastructure, physical security, engineering, customer trust, and legal.
You will partner directly with control owners across the company to ensure controls are scoped, implemented, evidenced, tested, and defensible.
- What You'll be Doing
- Assurance Program Leadership
- Own security assurance execution across SOC 2 Type II, the ISO family of standards, and other applicable frameworks.
- Lead certification and audit-readiness planning for new sites, systems, services, and customer commitments.
- Build and maintain an integrated audit calendar across certification bodies, readiness assessments, customer deadlines, surveillance audits, and scope expansions.
- Drive cross-functional readiness for audit fieldwork, evidence submission, auditor walkthroughs, and control-owner interviews.
- Scope Expansion and Site Readiness
- Lead assurance planning for new launches and site-scope expansions.
- Translate site launch commitments into control requirements, evidence requirements, readiness trackers, and audit-response packs.
- Partner with Physical & Data Center Security, Enterprise Security, Infrastructure, Legal, and Customer Trust to define boundaries, control ownership, and evidence expectations.
- Support customer-specific readiness efforts.
- Control Framework and Evidence Quality
- Partner with compliance engineering and control-mapping owners to maintain a unified control framework across SOC 2, ISO, NIST, and customer-specific obligations.
- Define evidence standards for control design, operating effectiveness, sampling, retention, traceability, and audit defensibility.
- Review evidence for sufficiency, accuracy, timeliness, and relevance before submission to auditors or customers.
- Identify evidence gaps, control weaknesses, and repeat failure patterns.
- Ensure audit findings are routed into remediation workflows with accountable owners and due dates.
- External Audit and Customer Audit Support
- Manage external auditor engagement, including request lists, evidence submissions, control narratives, walkthrough preparation, and issue follow-up.
- Serve as a primary assurance representative during external audits and customer security reviews.
- Translate technical controls into clear, defensible audit narratives.
- Partner with Customer Trust to prepare audit-backed responses to customer security reviews and enterprise customer assurance requests.
- Automation and Continuous Readiness
- Partner with GRC Engineering to automate evidence collection, control monitoring, and audit-readiness reporting.
- Support the implementation and operationalization of a modern GRC platform, including evidence integrations and automated workflows.
- Help define continuous control monitoring requirements and control health indicators.
- Use automation and AI-assisted workflows where they improve evidence quality, audit preparation, control validation, or remediation tracking.
- Reduce manual audit preparation by building repeatable workflows, templates, and source-of-truth systems.
- KPIs
- Audit-readiness status across in-scope certifications and sites
- Evidence completeness, quality, and traceability
- On-time completion of audit requests and readiness milestones
- Control ownership and evidence maintenance coverage across in-scope frameworks
- Closure rates for evidence gaps and audit findings
- Certification / audit milestone attainment
- Time required to prepare site-specific audit-response packs
- Control-mapping coverage across required frameworks and customer commitments
About You
- Required
- 5+ years of experience in security assurance, security compliance, GRC, external audit, technical program management, or related security functions.
- Hands-on experience with SOC 2 Type II and ISO 27001.
- Experience managing external audits, certification engagements, readiness assessments, or audit-response programs.
- Strong understanding of control design, operating effectiveness, audit evidence, evidence sampling, and audit defensibility.
- Ability to work directly with engineering, infrastructure, security, physical security, IT, HR, legal, and operations teams.
- Experience translating framework requirements into control-owner actions and evidence requirements.
- Strong program-management skills, including operating cadences, timelines, dependencies, executive reporting, and escalation.
- Excellent written communication skills for audit narratives, scope statements, control explanations, and executive updates.
- Comfort operating in ambiguous, fast-growth environments with high customer expectations.
- Strong Preferences
- Experience with HITRUST, NIST 800-53, Cyber Essentials Plus, or UK government security frameworks (such as the NCSC Cyber Assessment Framework).
- Experience supporting data center, cloud infrastructure, bare-metal, sovereign cloud, AI infrastructure, or critical infrastructure environments.
- Hands-on experience with modern GRC platforms such as Drata, Vanta, Service Now GRC, One Trust, Hyperproof, or similar.
- Experience building audit-readiness programs that use automation, continuous control monitoring, or evidence integrations.
- Experience working with physical and environmental controls, facility security, or data center operations.
- Experience working across multiple geographies and certification scopes.
- Nice to Have
- Relevant certifications such as CISSP, CISM, ISO 27001 Lead Auditor, ISO 42001 Lead Implementer, CISA, or equivalent.
- Prior experience as an external auditor, certification-body assessor, or audit consultant.
- Experience scaling security assurance programs in high-growth startups or infrastructure companies.
- What We Can Offer You
You’ll have the opportunity to help shape the operating standards behind a next-generation AI cloud platform, working on complex infrastructure challenges with real ownership and impact.
This is a chance to play a meaningful role in scaling high-performance, sustainable data centre operations in a fast-moving environment.
Equal Opportunities Statement
We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.
If there’s anything we can do to accommodate your specific situation, please let us know.
The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position.
The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.
For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice:
Here.
Staff engineer, Security Assurance & Audit employer: Nscale
At Nscale, we pride ourselves on fostering a culture of relentless innovation and accountability, making us an exceptional employer for those looking to make a meaningful impact in the AI sector. Our collaborative environment encourages personal growth and offers tailored progression plans, ensuring that every team member can thrive while contributing to cutting-edge technology. With a highly competitive compensation package and a commitment to human-first flexibility, Nscale is the ideal place for passionate individuals ready to shape the future of AI.
StudySmarter Expert Advice🤫
We think this is how you could land Staff engineer, Security Assurance & Audit
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Nscale, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Nscale
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Nscale. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Staff engineer, Security Assurance & Audit
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Nscale insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Nscale that you’re committed to staying ahead in the game.
How to prepare for a job interview at Nscale
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Nscale to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Nscale.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.