Skip to content

Open nowPosted 5 hours ago

Senior Audit Program Manager, Security Assurance

Nscale282 open roles

Pay
$140,000 – $180,000 a year
Where
Houston; New York; San Francisco; Seattle
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Audit Program Manager, Security AssuranceNscale · Houston; New York; San Francisco; Seattle
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Nscale's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Nscale postings stay open a median of 5 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.0%14 days
  5. 33.9%30 days
This job: posted 5 hours ago

Nscale median: 5 days open

The posting

About Nscale

Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.

We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.

About the role

We're hiring a Senior Audit Program Manager, Security Assurance to lead security audits and certification programs as Nscale scales its global AI infrastructure. This is a senior individual contributor role reporting to the Director, Security Risk & Compliance. You'll lead assigned SOC 2 and ISO 27001 engagements across cloud services, data centers, and corporate functions, from scoping and readiness through external assessment, remediation, and final reporting.

You'll join our existing Audit and Assurance team, sharing a growing portfolio of audits, certification activities, and scope expansions. You'll own your assigned engagements and workstreams while maintaining a consistent approach to controls, evidence, and auditor engagement across the portfolio.

We're looking for an experienced assurance practitioner who can work directly with engineers, understand how controls operate, and substantiate those controls to external auditors. You'll investigate gaps, bring sound judgment to ambiguous requirements, and recommend practical solutions. You'll also help us scale assurance through reusable evidence, automation, and well-designed workflows.

What you'll be doing

Audit and Certification Delivery

  • Lead assigned SOC 2 and ISO 27001 engagements, including readiness assessments, scope expansions, ongoing assessments, and remediation.
  • Establish audit plans with clear boundaries, control owners, evidence requirements, milestones, and dependencies. Coordinate observation periods, fieldwork, and report or certificate delivery with external auditors.
  • Serve as the primary auditor contact for your engagements. Lead control walkthroughs, prepare technical teams for interviews, and resolve evidence requests and interpretation questions.

Audit Coordination and Reporting

  • Manage audit requests, schedules, and status reviews across concurrent engagements. Assign owners, set deadlines, review submissions, document decisions, and drive follow-through on blockers and recovery plans.
  • Prepare audit documentation, including application letters, scoping questionnaires, evidence request lists, and management responses. Review draft reports and certification documents for factual accuracy, scope, and consistency with evidence, and coordinate approvals and signatures.
  • Maintain an organized, version-controlled record of evidence, correspondence, approvals, and final deliverables. Surface delivery risks early with practical recommendations.

Technical Controls and Evidence Quality

  • Assess control design and operating effectiveness with engineering, security, IT, and business owners. Translate assessment criteria into clear implementation and evidence requirements.
  • Review technical evidence across identity and access management, GPU/compute infrastructure configuration, change management, logging, vulnerability management, backup and recovery, and physical security.
  • Validate evidence before submission, including its source, completeness, relevant population, period, and connection to the control being tested.
  • Investigate discrepancies between documented controls and actual operations. Work with owners to correct the control, documentation, or evidence, and maintain accurate control narratives, framework mappings, and relevant Statement of Applicability inputs.

Scope Expansion and Shared Responsibilities

  • Assess how new services, sites, entities, and operating models affect audit boundaries and certification coverage. Establish readiness criteria for scope expansion and make coverage gaps and their business implications clear.
  • Work with cloud, infrastructure, data center, and colocation teams to distinguish Nscale-operated controls from provider responsibilities and inherited controls.
  • Evaluate provider reports and certificates for relevant services, locations, periods, exceptions, and customer responsibilities. Identify where additional evidence or assessment is needed.
  • Partner with Customer Trust and Legal to translate validated customer obligations into assurance requirements, and with the SRC TPM to connect them to delivery dependencies.

Findings and Continuous Assurance

  • Turn audit findings and readiness gaps into remediation plans with accountable owners, root causes, due dates, and closure criteria.
  • Challenge incomplete fixes, verify remediation evidence, and coordinate retesting and auditor acceptance where required.
  • Track overdue actions, recurring control failures, and changes that could affect upcoming assessments. Support ISMS reviews and internal assurance activities with accurate audit results, control performance, and improvement recommendations.

Automation and Program Improvement

  • Partner with Compliance Automation to define evidence requirements, identify reliable source systems, and validate automated collection and monitoring outputs.
  • Build reusable evidence and control mappings that reduce repeated requests while preserving each assessment's scope and period requirements.
  • Improve audit workflows in Drata and connected delivery tools so owners, evidence, findings, and decisions remain traceable.
  • Use AI tools to streamline repeatable assurance work, with appropriate data handling and verification of generated outputs.

KPIs

  • Audit and certification milestone delivery against agreed plans
  • Evidence submission readiness, avoidable rework, auditor-query resolution time, and accuracy and completeness of scope records, control ownership, and evidence mappings
  • Remediation closure against agreed criteria, overdue findings, and recurring issues
  • Reduction in duplicated evidence requests and manual effort against a defined baseline

About You

Required

  • 7+ years of experience in security assurance, technology audit, compliance, or related disciplines, including independently leading external audit or certification engagements in technical environments.
  • Substantial hands-on experience with both SOC 2 and ISO 27001, with accountability for delivering audits or assessments through final reports or certification outcomes.
  • Experience working directly with external auditors, leading walkthroughs, resolving control and evidence questions, and managing findings through verified closure.
  • Technical fluency in cloud infrastructure and security controls. You can discuss how a control is implemented with engineers and assess whether the evidence supports its claimed design and operation.
  • Experience defining assessment scope and understanding shared responsibilities across internal teams, cloud providers, and other service providers.
  • Strong program execution across concurrent engagements, including dependency management, prioritization, and timely escalation with practical recommendations.
  • Ability to investigate unfamiliar issues independently, distinguish facts from assumptions, and communicate a clear recommendation with supporting evidence.
  • Clear written communication, including control narratives, remediation requirements, and concise leadership reporting.

Strong Preferences

  • Security assurance experience at a cloud service provider, hyperscaler, infrastructure platform, or data center operator.
  • Experience expanding audit or certification scope across multiple services, sites, or entities.
  • Experience with common control frameworks, evidence reuse, continuous monitoring, and reducing the effort audits require from engineering teams.
  • Strong familiarity with AI tools to automate repeatable processes and streamline workflows, with practical examples of improvements to quality or efficiency.
  • Hands-on experience with Drata or a comparable GRC platform, including control mapping, evidence workflows, and findings management.
  • Experience building effective assurance processes in a fast-growing organization with evolving systems and ownership.

Nice to Have

  • Prior experience as an external technology auditor or ISO 27001 auditor.
  • CISA, CISSP, ISO 27001 Lead Auditor, or equivalent practical expertise.
  • Ability to use SQL, scripting, or APIs to inspect evidence and improve reporting.
  • Experience with GPU infrastructure, Kubernetes, or infrastructure as code.

What we can offer you

At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.

  • Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months. 🚀
  • Join one of the fastest-growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed. ✨
  • Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy — always with our full support.
  • Human-First Flexibility: We treat you as humans first. 🫶🏽 Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

Equal Opportunities Statement

We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.

If there’s anything we can do to accommodate your specific situation, please let us know.

The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

Salary Range

$140,000—$180,000 USD

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.

Nscale does not accept unsolicited candidate submissions from recruitment agencies.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Nscale's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Nscale's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Nscale's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.