Senior Technical Program Manager, Security Risk & Compliance
Summary
Leads Nscale’s human risk security program, building awareness training, behavioral analytics, and insider risk governance to reduce security incidents across AI infrastructure teams.
About Nscale
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.
About the Role
We're hiring a Senior Technical Program Manager to drive delivery across Nscale's Security Risk & Compliance programs as we scale our global AI infrastructure. This is a senior individual contributor role, reporting to the Director, Security Risk & Compliance. You'll turn security requirements, customer commitments, and program priorities into executable plans across engineering, infrastructure, security, and business teams.
You'll own the delivery plans, dependencies, and operating cadence that connect our compliance programs to the teams implementing controls. You'll also own policy adoption: translating approved policies into practical guidance, coordinating rollout, and verifying that required changes are embedded in day-to-day work.
This role requires technical judgment and hands-on execution. You can understand a system boundary, challenge an incomplete implementation plan, and establish what evidence demonstrates completion. You'll work alongside specialists who own audit and assurance, cyber risk, customer trust, third-party risk, and compliance engineering. Those specialists retain ownership of their disciplines; you own integrated program delivery and make dependencies, decisions, and delivery risks visible early.
What you'll be doing
Cross-Functional Compliance Delivery
- Build and drive integrated delivery plans for compliance initiatives, including certification scope expansion, control implementation, automation, evidence tracking, metrics, and remediation programs across cloud services and data center environments.
- Translate requirements into workstreams with clear owners, milestones, dependencies, acceptance criteria, and evidence expectations.
- Work with technical and assurance owners to understand architecture, control boundaries, and evidence sources so plans reflect how systems and operations actually work.
- Resolve blockers across teams, negotiate delivery commitments, and escalate tradeoffs with clear options and impacts.
- Verify completion against agreed acceptance criteria with the responsible technical and assurance owners.
Customer Commitment Dependencies
- Partner with customer trust, assurance, Legal, and delivery teams to turn validated security and compliance commitments into coordinated execution plans.
- Connect customer milestones to control readiness, supporting evidence, audit dependencies, and site or service delivery schedules.
- Track obligations that depend on colocation providers, suppliers, and internal teams, establishing owners and lead times for each dependency.
- Identify when scope or schedule changes put a commitment at risk, and drive the decisions and recovery plans needed to address it.
- Maintain traceability between the validated requirement, delivery work, and evidence of completion.
SRC Planning and Execution Cadence
- Establish and run the team's planning, scheduling, delivery reviews, dependency tracking, and decision follow-through.
- Maintain an integrated view of priorities, capacity, milestones, and delivery risks in Linear and connected reporting tools.
- Prepare concise leadership updates that explain what shipped, what is at risk, and which decisions are needed.
- Help the overall program sequence competing priorities and make capacity tradeoffs explicit.
- Use automation and AI-assisted workflows to reduce manual coordination, improve reporting quality, and keep delivery information current.
- Partner with cross-functional teams to establish clear process ownership, track owner commitments, and drive agreed actions through completion.
Policy Adoption
- Partner with policy owners to translate approved security policies and standards into actionable guidance for affected teams.
- Own adoption plans covering stakeholder readiness, communications, targeted enablement, acknowledgments where required, and integration into operational workflows.
- Coordinate policy changes with the teams responsible for implementing controls and maintaining supporting procedures.
- Measure whether policies are understood and applied through implementation evidence, user feedback, and recurring gaps.
- Route adoption barriers and exception requests to the accountable policy or control owner, and track agreed actions through completion.
KPIs
- Delivery reliability against agreed milestones, with scope changes and rebaselining visible.
- Coverage of priority programs and customer commitments with named owners, mapped dependencies, acceptance criteria, and evidence expectations.
- Age of unresolved critical dependencies and decisions, and lead time between identifying delivery risk and the affected deadline.
- Completion of agreed control and remediation milestones with evidence accepted by the responsible technical or assurance owner.
About You
Required
- 8+ years in technical program management, security, infrastructure, or related disciplines, including substantial experience leading complex programs across engineering and business teams.
- A record of delivering security, compliance, or infrastructure programs with multiple owners, competing priorities, and external commitments.
- Technical fluency in cloud infrastructure and security controls: you can work through architecture and data flows with engineers, identify dependencies, and define verifiable delivery criteria.
- Experience translating security or compliance requirements into implementation plans with clear ownership and measurable outcomes.
- Strong program judgment: you surface delivery risks early, drive decisions, and hold teams to agreed commitments through influence.
- Experience driving adoption of policies, standards, or technical process changes across an organization.
- Strong written communication, including concise executive reporting and clear guidance for non-technical audiences.
- Practical use of data, automation, and AI-assisted workflows to improve program execution and reporting.
Strong Preferences
- Experience delivering ISO 27001 or SOC 2 readiness and audits, scope expansion, or remediation programs alongside assurance specialists.
- Experience with cloud platforms, data centers, colocation providers, or infrastructure deployments involving shared control responsibilities.
- Experience coordinating customer security commitments across technical, commercial, and Legal stakeholders.
- Experience building a program operating cadence in a high-growth technology or infrastructure organization.
- Hands-on experience with Linear or similar engineering delivery tools and GRC platforms such as Drata.
- Strong familiarity with AI tools, with demonstrated experience automating repeatable processes and streamlining workflows.
Nice to Have
- Background in engineering, security engineering, or technical operations.
- Ability to use SQL, scripting, or APIs to connect delivery data and automate reporting.
- Relevant certifications such as CISSP, CISM, or PMP, or equivalent practical experience.
What we can offer you
Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.
- Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months. 🚀
- Join one of the fastest-growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed. ✨
- Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy — always with our full support.
- Human-First Flexibility: We treat you as humans first. 🫶🏽 Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.
Equal Opportunities Statement
We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.
If there’s anything we can do to accommodate your specific situation, please let us know.
The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.
For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.
The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.
For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.
Skills
As published by greenhouse · 5 questions
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
Short answers (4)
- LinkedIn Profile optional
- Website optional
- What is your current or most recent employer? optional
- What is your preferred name?
Pick from a list (1)
- Do you have the legal right to work in the country in which this job is located, without requiring visa sponsorship?