Senior Audit Program Manager, Security Assurance Houston San Francisco; Seattle
Listed on 2026-10-10
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Location: New York
Senior Audit Program Manager, Security Assurance
Houston;
New York;
San Francisco;
Seattle
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.
About the roleWe're hiring a Senior Audit Program Manager, Security Assurance to lead security audits and certification programs as Nscale scales its global AI infrastructure. This is a senior individual contributor role reporting to the Director, Security Risk & Compliance. You'll lead assigned SOC 2 and ISO 27001 engagements across cloud services, data centers, and corporate functions, from scoping and readiness through external assessment, remediation, and final reporting.
You’ll join our existing Audit and Assurance team, sharing a growing portfolio of audits, certification activities, and scope expansions. You'll own your assigned engagements and work streams while maintaining a consistent approach to controls, evidence, and auditor engagement across the portfolio.
We're looking for an experienced assurance practitioner who can work directly with engineers, understand how controls operate, and substantiate those controls to external auditors. You'll investigate gaps, bring sound judgment to ambiguous requirements, and recommend practical solutions. You'll also help us scale assurance through reusable evidence, automation, and well-designed workflows.
What you'll be doingAudit and Certification Delivery
- Lead assigned SOC 2 and ISO 27001 engagements, including readiness assessments, scope expansions, ongoing assessments, and remediation.
- Establish audit plans with clear boundaries, control owners, evidence requirements, milestones, and dependencies. Coordinate observation periods, fieldwork, and report or certificate delivery with external auditors.
- Serve as the primary auditor contact for your engagements. Lead control walkthroughs, prepare technical teams for interviews, and resolve evidence requests and interpretation questions.
- Manage audit requests, schedules, and status reviews across concurrent engagements. Assign owners, set deadlines, review submissions, document decisions, and drive follow-through on blockers and recovery plans.
- Prepare audit documentation, including application letters, scoping questionnaires, evidence request lists, and management responses. Review draft reports and certification documents for factual accuracy, scope, and consistency with evidence, and coordinate approvals and signatures.
- Maintain an organized, version-controlled record of evidence, correspondence, approvals, and final deliverables. Surface delivery risks early with practical recommendations.
- Assess control design and operating effectiveness with engineering, security, IT, and business owners. Translate assessment criteria into clear implementation and evidence requirements.
- Review technical evidence across identity and access management, GPU/compute infrastructure configuration, change management, logging, vulnerability management, backup and recovery, and physical security.
- Validate evidence before submission, including its source, completeness, relevant population, period, and connection to the control being tested.
- Investigate discrepancies between documented controls and actual operations. Work with owners to correct the control, documentation, or evidence, and maintain accurate control narratives, framework mappings, and relevant Statement of Applicability inputs.
- Assess how new services, sites, entities, and operating models affect audit boundaries and certification coverage. Establish readiness criteria for scope expansion and make coverage gaps and their business implications clear.
- Work with cloud,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).