Security Engineer, Compliance Focus
Listed on 2026-08-13
-
Security
Cybersecurity
About Volta
Volta is the category-defining, fully vertically integrated AI infrastructure platform – from capital to clusters to software, under a founder-led enterprise. Our mission is The Utility of Compute™: AI infrastructure as dependable and available as electricity, for every organization that needs it. Launched with a $10B strategic partnership with one of the leading frontier AI labs, a Series A led by Andreessen Horowitz, and a $5B AI Infrastructure Fund, Volta is building the infrastructure layer of the AI era from the ground up.
We are 100+ people across London, Palo Alto, and New York, with rapid growth expectations to hundreds.
Volta builds and operates large scale GPU compute infrastructure for frontier AI customers. Those customers hold us to real security obligations, written into contracts with dates attached, and our lenders and investors examine our security posture as part of financing. Compliance here is not a paperwork exercise at the edge of the business. It is a condition of doing business.
We are working toward ISO 27001 certification and SOC 2 Type II attestation across a company that is scaling quickly, operating multi-tenant infrastructure in several countries, and deploying into partner data centers. The Senior Manager, Cyber Security Engineering owns that program, its scope, and its direction. You are the engineer who makes it work in practice: implementing and evidencing controls, keeping the GRC platform accurate, preparing what auditors and customers ask for, and chasing the details that decide whether an audit goes well.
This is a compliance role on an engineering team. You will spend as much time with platform and infrastructure engineers as with documents, and you will need to be able to tell whether a control is actually working or only described.
What You Will Be DoingCompliance Execution
Implement and maintain the control set defined for our ISO 27001 and SOC 2 Type II programs, tracking status, owners, and gaps against the certification timeline.
Operate our GRC platform (Vanta) day to day: configure and maintain integrations, monitor automated control checks, and resolve drift and failing controls.
Collect, organize, and quality-check evidence so that it is complete, current, and defensible when an auditor asks for it.
Maintain ISMS documentation to the standard the Senior Manager sets: policies and procedures, the risk register, and records of corrective actions.
Support internal audit and management review with the data and analysis they need.
Audit Support
Prepare evidence packages and control walkthroughs ahead of audit fieldwork.
Support auditors during fieldwork, gathering what they request and coordinating the engineers who need to answer.
Track findings through to closure and verify that corrective actions actually took effect.
Customer and Contractual Obligation s
Map the security obligations in customer contracts to specific controls, and flag where we do not yet meet them.
Draft responses to customer security questionnaires and due diligence requests for review, keeping answers consistent with what we actually do.
Prepare material supporting lender and investor due diligence on security and compliance.
Risk and Third Parties
Carry out risk assessments and vendor and third-party security reviews, and document the results.
Maintain the exception register so that accepted risk stays visible, owned, and time-bound.
Support the physical security control set at our sites and offices, working with the local contact at each location.
Regulatory
Maintain the records and reporting needed for regulatory obligations across our footprint, including NIS2 registrations and national authority contacts, and GDPR-related documentation.
Working With Engineering
Turn control requirements into concrete, schedulable work with platform and infrastructure teams, and follow it through to done.
Automate evidence collection wherever possible. Anything depending on someone remembering a quarterly screenshot will eventually fail an audit.
Support security awareness training delivery, business continuity documentation, and DR test evidence.
Handle the compliance side of incidents:…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: