Senior Audit Program Manager, Security Assurance

Nscale•Seattle, WA
•$140,000 - $180,000•Hybrid

About The Position

Nscale is seeking a Senior Audit Program Manager, Security Assurance to lead security audits and certification programs as the company scales its global AI infrastructure. This is a senior individual contributor role reporting to the Director, Security Risk & Compliance. The successful candidate will lead assigned SOC 2 and ISO 27001 engagements across cloud services, data centers, and corporate functions, managing the entire process from scoping and readiness through external assessment, remediation, and final reporting. The role involves joining the existing Audit and Assurance team, sharing a portfolio of audits, certification activities, and scope expansions. The individual will own their assigned engagements and workstreams, ensuring a consistent approach to controls, evidence, and auditor engagement. The ideal candidate is an experienced assurance practitioner who can collaborate with engineers, understand control operations, substantiate controls to external auditors, investigate gaps, apply sound judgment to ambiguous requirements, and recommend practical solutions. The role also includes scaling assurance through reusable evidence, automation, and well-designed workflows.

Requirements

  • 7+ years of experience in security assurance, technology audit, compliance, or related disciplines, including independently leading external audit or certification engagements in technical environments.
  • Substantial hands-on experience with both SOC 2 and ISO 27001, with accountability for delivering audits or assessments through final reports or certification outcomes.
  • Experience working directly with external auditors, leading walkthroughs, resolving control and evidence questions, and managing findings through verified closure.
  • Technical fluency in cloud infrastructure and security controls. Ability to discuss control implementation with engineers and assess evidence supporting claimed design and operation.
  • Experience defining assessment scope and understanding shared responsibilities across internal teams, cloud providers, and other service providers.
  • Strong program execution across concurrent engagements, including dependency management, prioritization, and timely escalation with practical recommendations.
  • Ability to investigate unfamiliar issues independently, distinguish facts from assumptions, and communicate a clear recommendation with supporting evidence.
  • Clear written communication, including control narratives, remediation requirements, and concise leadership reporting.

Nice To Haves

  • Security assurance experience at a cloud service provider, hyperscaler, infrastructure platform, or data center operator.
  • Experience expanding audit or certification scope across multiple services, sites, or entities.
  • Experience with common control frameworks, evidence reuse, continuous monitoring, and reducing the effort audits require from engineering teams.
  • Strong familiarity with AI tools to automate repeatable processes and streamline workflows, with practical examples of improvements to quality or efficiency.
  • Hands-on experience with Drata or a comparable GRC platform, including control mapping, evidence workflows, and findings management.
  • Experience building effective assurance processes in a fast-growing organization with evolving systems and ownership.
  • Prior experience as an external technology auditor or ISO 27001 auditor.
  • CISA, CISSP, ISO 27001 Lead Auditor, or equivalent practical expertise.
  • Ability to use SQL, scripting, or APIs to inspect evidence and improve reporting.
  • Experience with GPU infrastructure, Kubernetes, or infrastructure as code.

Responsibilities

  • Lead assigned SOC 2 and ISO 27001 engagements, including readiness assessments, scope expansions, ongoing assessments, and remediation.
  • Establish audit plans with clear boundaries, control owners, evidence requirements, milestones, and dependencies. Coordinate observation periods, fieldwork, and report or certificate delivery with external auditors.
  • Serve as the primary auditor contact for engagements, leading control walkthroughs, preparing technical teams for interviews, and resolving evidence requests and interpretation questions.
  • Manage audit requests, schedules, and status reviews across concurrent engagements, assigning owners, setting deadlines, reviewing submissions, documenting decisions, and driving follow-through on blockers and recovery plans.
  • Prepare audit documentation, including application letters, scoping questionnaires, evidence request lists, and management responses. Review draft reports and certification documents for factual accuracy, scope, and consistency with evidence, and coordinate approvals and signatures.
  • Maintain an organized, version-controlled record of evidence, correspondence, approvals, and final deliverables. Surface delivery risks early with practical recommendations.
  • Assess control design and operating effectiveness with engineering, security, IT, and business owners, translating assessment criteria into clear implementation and evidence requirements.
  • Review technical evidence across identity and access management, GPU/compute infrastructure configuration, change management, logging, vulnerability management, backup and recovery, and physical security.
  • Validate evidence before submission, including its source, completeness, relevant population, period, and connection to the control being tested.
  • Investigate discrepancies between documented controls and actual operations, working with owners to correct the control, documentation, or evidence, and maintaining accurate control narratives, framework mappings, and relevant Statement of Applicability inputs.
  • Assess how new services, sites, entities, and operating models affect audit boundaries and certification coverage, establishing readiness criteria for scope expansion and clarifying coverage gaps and their business implications.
  • Work with cloud, infrastructure, data center, and colocation teams to distinguish Nscale-operated controls from provider responsibilities and inherited controls.
  • Evaluate provider reports and certificates for relevant services, locations, periods, exceptions, and customer responsibilities, identifying where additional evidence or assessment is needed.
  • Partner with Customer Trust and Legal to translate validated customer obligations into assurance requirements, and with the SRC TPM to connect them to delivery dependencies.
  • Turn audit findings and readiness gaps into remediation plans with accountable owners, root causes, due dates, and closure criteria.
  • Challenge incomplete fixes, verify remediation evidence, and coordinate retesting and auditor acceptance where required.
  • Track overdue actions, recurring control failures, and changes that could affect upcoming assessments. Support ISMS reviews and internal assurance activities with accurate audit results, control performance, and improvement recommendations.
  • Partner with Compliance Automation to define evidence requirements, identify reliable source systems, and validate automated collection and monitoring outputs.
  • Build reusable evidence and control mappings that reduce repeated requests while preserving each assessment's scope and period requirements.
  • Improve audit workflows in Drata and connected delivery tools so owners, evidence, findings, and decisions remain traceable.
  • Use AI tools to streamline repeatable assurance work, with appropriate data handling and verification of generated outputs.

Benefits

  • Highly competitive US compensation package (base + bonus + equity)
  • Performance reviews every 12 months
  • Dynamic progression plan tailored to ambitions
  • Flexible workplace
  • Medical, dental, vision
  • Flexible paid time off
  • Parental leave
  • Retirement plan participation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service