← All jobs
Senior Audit Program Manager, Security Assurance
Houston; New York; San Francisco; Seattle · On-site · Security & Corporate Engineering
$140K – $180K
Apply well, not just fast
Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.
About the role
ISO 27001SOC 2ComplianceSQLKubernetesIAMAuditing
About Nscale
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.
About the role
We're hiring a Senior Audit Program Manager, Security Assurance to lead security audits and certification programs as Nscale scales its global AI infrastructure. This is a senior individual contributor role reporting to the Director, Security Risk & Compliance. You'll lead assigned SOC 2 and ISO 27001 engagements across cloud services, data centers, and corporate functions, from scoping and readiness through external assessment, remediation, and final reporting.
You'll join our existing Audit and Assurance team, sharing a growing portfolio of audits, certification activities, and scope expansions. You'll own your assigned engagements and workstreams while maintaining a consistent approach to controls, evidence, and auditor engagement across the portfolio.
We're looking for an experienced assurance practitioner who can work directly with engineers, understand how controls operate, and substantiate those controls to external auditors. You'll investigate gaps, bring sound judgment to ambiguous requirements, and recommend practical solutions. You'll also help us scale assurance through reusable evidence, automation, and well-designed workflows.
What you'll be doing
Audit and Certification Delivery
- Lead assigned SOC 2 and ISO 27001 engagements, including readiness assessments, scope expansions, ongoing assessments, and remediation.
- Establish audit plans with clear boundaries, control owners, evidence requirements, milestones, and dependencies. Coordinate observation periods, fieldwork, and report or certificate delivery with external auditors.
- Serve as the primary auditor contact for your engagements. Lead control walkthroughs, prepare technical teams for interviews, and resolve evidence requests and interpretation questions.
Audit Coordination and Reporting
- Manage audit requests, schedules, and status reviews across concurrent engagements. Assign owners, set deadlines, review submissions, document decisions, and drive follow-through on blockers and recovery plans.
- Prepare audit documentation, including application letters, scoping questionnaires, evidence request lists, and management responses. Review draft reports and certification documents for factual accuracy, scope, and consistency with evidence, and coordinate approvals and signatures.
- Maintain an organized, version-controlled record of evidence, correspondence, approvals, and final deliverables. Surface delivery risks early with practical recommendations.
Technical Controls and Evidence Quality
- Assess control design and operating effectiveness with engineering, security, IT, and business owners. Translate assessment criteria into clear implementation and evidence requirements.
- Review technical evidence across identity and access management, GPU/compute infrastructure configuration, change management, logging, vulnerability management, backup and recovery, and physical security.
- Validate evidence before submission, including its source, completeness, relevant population, period, and connection to the control being tested.
- Investigate discrepancies between documented controls and actual operations. Work with owners to correct the control, documentation, or evidence, and maintain accurate control narratives, framework mappings, and relevant Statement of Applicability inputs.
Scope Expansion and Shared Responsibilities
- Assess how new services, sites, entities, and operating models affect audit boundaries and certification coverage. Establish readiness criteria for scope expansion and make coverage gaps and their business implications clear.
- Work with cloud, infrastructure, data center, and colocation teams to distinguish Nscale-operated controls from provider responsibilities and inherited controls.
- Evaluate provider reports and certificates for relevant services, locations, periods, exceptions, and customer responsibilities. Identify where additional evidence or assessment is needed.
- Partner with Customer Trust and Legal to translate validated customer obligations into assurance requirements, and with the SRC TPM to connect them to delivery dependencies.
Findings and Continuous Assurance
- Turn audit findings and readiness gaps into remediation plans with accountable owners, root causes, due dates, and closure criteria.
- Challenge incomplete fixes, verify remediation evidence, and coordinate retesting and auditor acceptance where required.
- Track overdue actions, recurring control failures, and changes that could affect upcoming assessments. Support ISMS reviews and internal assurance activities with accurate audit results, control performance, and improvement recommendations.
Automation and Program Improvement
- Partner with Compliance Automation to define evidence requirements, identify reliable source systems, and validate automated collection and monitoring outputs.
- Build reusable evidence and control mappings that reduce repeated requests while preserving each assessment's scope and period requirements.
- Improve audit workflows in Drata and connected delivery tools so owners, evidence, findings, and decisions remain traceable.
- Use AI tools to streamline repeatable assurance work, with appropriate data handling and verification of generated outputs.
KPIs
- Audit and certification milestone delivery against agreed plans
- Evidence submission readiness, avoidable rework, auditor-query resolution time, and accuracy and completeness of scope records, control ownership, and evidence mappings
- Remediation closure against agreed criteria, overdue findings, and recurring issues
- Reduction in duplicated evidence requests and manual effort against a defined baseline
About You
Required
- 7+ years of experience in security assurance, technology audit, compliance, or related disciplines, including independently leading external audit or certification engagements in technical environments.
- Substantial hands-on experience with both SOC 2 and ISO 27001, with accountability for delivering audits or assessments through final reports or certification outcomes.
- Experience working directly with external auditors, leading walkthroughs, resolving control and evidence questions, and managing findings through verified closure.
- Technical fluency in cloud infrastructure and security controls. You can discuss how a control is implemented with engineers and assess whether the evidence supports its claimed design and operation.
- Experience defining assessment scope and understanding shared responsibilities across internal teams, cloud providers, and other service providers.
- Strong program execution across concurrent engagements, including dependency management, prioritization, and timely escalation with practical recommendations.
- Ability to investigate unfamiliar issues independently, distinguish facts from assumptions, and communicate a clear recommendation with supporting evidence.
- Clear written communication, including control narratives, remediation requirements, and concise leadership reporting.
Strong Preferences
- Security assurance experience at a cloud service provider, hyperscaler, infrastructure platform, or data center operator.
- Experience expanding audit or certification scope across multiple services, sites, or entities.
- Experience with common control frameworks, evidence reuse, continuous monitoring, and reducing the effort audits require from engineering teams.
- Strong familiarity with AI tools to automate repeatable processes and streamline workflows, with practical examples of improvements to quality or efficiency.
- Hands-on experience with Drata or a comparable GRC platform, including control mapping, evidence workflows, and findings management.
- Experience building effective assurance processes in a fast-growing organization with evolving systems and ownership.
Nice to Have
- Prior experience as an external technology auditor or ISO 27001 auditor.
- CISA, CISSP, ISO 27001 Lead Auditor, or equivalent practical expertise.
- Ability to use SQL, scripting, or APIs to inspect evidence and improve reporting.
- Experience with GPU infrastructure, Kubernetes, or infrastructure as code.
What we can offer you
At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.
- Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months. 🚀
- Join one of the fastest-growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed. ✨
- Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy — always with our full support.
- Human-First Flexibility: We treat you as humans first. 🫶🏽 Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.
Equal Opportunities Statement
We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.
If there’s anything we can do to accommodate your specific situation, please let us know.
The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.
For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.
The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.
Salary Range
$140,000—$180,000 USD
For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.
Nscale does not accept unsolicited candidate submissions from recruitment agencies.