SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Volta is a vertically integrated AI infrastructure platform building compute utilities for frontier AI customers. The company operates large-scale GPU infrastructure across multiple countries and data centers, serving customers with strict security and compliance obligations embedded in contracts.
You will be the hands-on engineer executing Volta's ISO 27001 and SOC 2 Type II compliance programs. This is not a documentation-only role—you will spend significant time with platform and infrastructure engineers, translating control requirements into concrete work and verifying that controls actually function in practice.
Key responsibilities include:
**Compliance Execution**: Implement and maintain the control set for ISO 27001 and SOC 2 Type II, tracking status and gaps against certification timelines. Operate the GRC platform (Vanta) day-to-day, configuring integrations, monitoring automated checks, and resolving control drift. Collect, organize, and quality-check evidence for auditors. Maintain ISMS documentation including policies, procedures, risk registers, and corrective action records.
**Audit Support**: Prepare evidence packages and control walkthroughs before audit fieldwork. Support auditors during fieldwork by gathering requested materials and coordinating with engineers. Track findings through closure and verify corrective actions.
**Customer & Contractual Obligations**: Map customer contract security obligations to specific controls and flag gaps. Draft responses to security questionnaires and due diligence requests. Prepare materials for lender and investor security reviews.
**Risk & Third Parties**: Conduct risk assessments and vendor security reviews. Maintain the exception register for accepted risks. Support physical security controls across office and data center locations.
**Regulatory**: Maintain records and reporting for regulatory obligations including NIS2 registrations and GDPR documentation across Volta's geographic footprint.
**Engineering Partnership**: Convert control requirements into schedulable work with engineering teams. Automate evidence collection to eliminate manual, error-prone processes. Support security awareness training, business continuity documentation, and incident compliance handling.
You bring 3+ years in information security with meaningful compliance, GRC, or audit-facing experience. You have hands-on experience within ISO 27001 or SOC 2 programs, including evidence preparation and external audit support. You understand technical controls in cloud and infrastructure environments well enough to assess whether a control is real by reading system designs. You have practical GRC platform experience (Vanta, Drata, or equivalent), including integration maintenance. Strong writing skills, organizational discipline, and the ability to partner with engineers rather than act as a gate are essential. You are comfortable building a compliance program from scratch in a rapidly scaling company.