Staff engineer, Security Assurance & Audit
Listed on 2026-07-19
-
Quality Assurance - QA/QC
Regulatory Compliance Specialist
Location: Kingston upon Hull
Staff engineer, Security Assurance & Audit
UK
About Nscale
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.
About The Role
Nscale is hiring a Staff Engineer, Security Assurance & Audit to lead a high‑rigor, audit‑ready assurance function across Nscale's global AI infrastructure.
This is a hands‑on senior individual contributor role with significant scope. You will own the operating model that allows Nscale to meet customer commitments, expand certification scope, maintain audit readiness, and produce defensible evidence for external auditors and enterprise customers.
As Nscale scales global AI infrastructure, we need a technical assurance leader who can turn customer commitments, certification requirements, and control obligations into durable programs, clear ownership, strong evidence, and repeatable execution.
This role sits at the intersection of security, audit, compliance, infrastructure, physical security, engineering, customer trust, and legal. You will partner directly with control owners across the company to ensure controls are scoped, implemented, evidenced, tested, and defensible.
What You’ll be Doing
Assurance Program Leadership
- Own security assurance execution across SOC 2 Type II, the ISO family of standards, and other applicable frameworks.
- Lead certification and audit‑readiness planning for new sites, systems, services, and customer commitments.
- Build and maintain an integrated audit calendar across certification bodies, readiness assessments, customer deadlines, surveillance audits, and scope expansions.
- Drive cross‑functional readiness for audit fieldwork, evidence submission, auditor walkthroughs, and control‑owner interviews.
Scope Expansion and Site Readiness
- Lead assurance planning for new launches and site‑scope expansions.
- Translate site launch commitments into control requirements, evidence requirements, readiness trackers, and audit‑response packs.
- Partner with Physical & Data Center Security, Enterprise Security, Infrastructure, Legal, and Customer Trust to define boundaries, control ownership, and evidence expectations.
- Support customer‑specific readiness efforts.
Control Framework and Evidence Quality
- Partner with compliance engineering and control‑mapping owners to maintain a unified control framework across SOC 2, ISO, NIST, and customer‑specific obligations.
- Define evidence standards for control design, operating effectiveness, sampling, retention, traceability, and audit defensibility.
- Review evidence for sufficiency, accuracy, timeliness, and relevance before submission to auditors or customers.
- Identify evidence gaps, control weaknesses, and repeat failure patterns.
- Ensure audit findings are routed into remediation workflows with accountable owners and due dates.
External Audit and Customer Audit Support
- Manage external auditor engagement, including request lists, evidence submissions, control narratives, walkthrough preparation, and issue follow‑up.
- Serve as a primary assurance representative during external audits and customer security reviews.
- Translate technical controls into clear, defensible audit narratives.
- Partner with Customer Trust to prepare audit‑backed responses to customer security reviews and enterprise customer assurance requests.
Automation and Continuous Readiness
- Partner with GRC Engineering to automate evidence collection, control monitoring, and audit‑readiness reporting.
- Support the implementation and…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: