Lead Security & Compliance Analyst
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Role Overview
Job requirements
• Proven experience leading or working with security and/or compliance for a SaaS or infrastructure business (nice to have: hands-on ownership of a SOC 2 (Type I or II) or similar compliance programme)
• Strong hands-on knowledge of AWS security tooling and general cloud security best practice
• Experience assessing and governing AI tooling and/or agentic systems from a security perspective (e.g. prompt injection, data exfiltration, access control for AI agents)
• Track record of building security frameworks, policies and processes from the ground up in a fast-moving environment
• Strong written and verbal communication skills, with the ability to influence engineers and leadership alike
• Experience managing or mentoring engineers
• Nice to have: experience with OCPP, EV charging infrastructure, or critical infrastructure/OT security standards (e.g. NIST IR 7628, UL 2900)
• You think like an attacker and a builder at the same time; you can identify real risk without becoming a blocker to shipping product
• You're comfortable owning ambiguous, cross-cutting problems and turning them into clear frameworks, policies and roadmaps
• You communicate security and compliance concepts clearly to engineers, executives and auditors alike
• You're genuinely curious about how AI tooling is changing the security landscape, and want to help define what "secure AI-first engineering" looks like in practice
• You care about enabling the business to move quickly and safely, not compliance for its own sake
Job responsibilities
• Own and evolve ev.energy's overall security strategy, translating it into concrete policies, controls and roadmaps
• Own endpoint security (our employee laptop estate), infrastructure security, and product security, monitoring and continuously reducing our attack surface
• Design and run security frameworks for an AI-first organisation, including risk assessments, RBAC and agent access control models, and credential governance for AI tools running on local machines and in production
• Design and run business continuity and incident response exercises to pressure-test our resilience, and own annual penetration testing
• Own SOC 2 Type II compliance end-to-end: control design, evidence collection, audit management and remediation tracking, plus starting to get us ready for ISO27001
• Build and maintain compliance automation so evidence gathering and audit readiness scale with the business rather than becoming a manual burden each cycle
• Produce and maintain supporting documentation (e.g. bridge letters, control narratives, RFP cyber-security responses, annual InfoSec policy reviews) for customers, partners and auditors
• Evaluate the security posture of AI tools and agentic platforms adopted across the business (e.g. prompt injection risk, data exfiltration vectors, audit traceability gaps) before they're rolled out
• Define and implement controls and policies for AI tooling
• Partner with engineering teams to establish secure-by-default patterns for building and deploying internal agents and MCP servers
• Partner closely with Technology, People, Legal and Sales to embed security and compliance thinking into the wider business, including client-facing security and compliance content for prospective partners
• Communicate security posture, risk and progress clearly to both technical and non-technical stakeholders, including leadership
Job benefits
• Cash amount of up to 10% of your monthly salary, to cover the cost of buying or leasing an EV
• Equity - you'll own a part of the business through our share options program
• Healthcare options - to help keep you and your family in tip-top condition (provided by Bupa & Medicash)
• Life assurance of 4x your salary
• Co-working access via WeWork (if you'd like it)
• Annual 'Team Week' whole company offsite
• L&D allowance of £1,000 per year - everyone is learning, developing and challenging themselves so we have a professional development fund per year for you to learn new skills
Key Skills for This Role
Full Job Posting
Job requirements
- Proven experience leading or working with security and/or compliance for a SaaS or infrastructure business (nice to have: hands-on ownership of a SOC 2 (Type I or II) or similar compliance programme)
- Strong hands-on knowledge of AWS security tooling and general cloud security best practice
- Experience assessing and governing AI tooling and/or agentic systems from a security perspective (e.g. prompt injection, data exfiltration, access control for AI agents)
- Track record of building security frameworks, policies and processes from the ground up in a fast-moving environment
- Strong written and verbal communication skills, with the ability to influence engineers and leadership alike
- Experience managing or mentoring engineers
- Nice to have: experience with OCPP, EV charging infrastructure, or critical infrastructure/OT security standards (e.g. NIST IR 7628, UL 2900)
- You think like an attacker and a builder at the same time; you can identify real risk without becoming a blocker to shipping product
- You're comfortable owning ambiguous, cross-cutting problems and turning them into clear frameworks, policies and roadmaps
- You communicate security and compliance concepts clearly to engineers, executives and auditors alike
- You're genuinely curious about how AI tooling is changing the security landscape, and want to help define what "secure AI-first engineering" looks like in practice
- You care about enabling the business to move quickly and safely, not compliance for its own sake
Job responsibilities
- Own and evolve ev.energy's overall security strategy, translating it into concrete policies, controls and roadmaps
- Own endpoint security (our employee laptop estate), infrastructure security, and product security, monitoring and continuously reducing our attack surface
- Design and run security frameworks for an AI-first organisation, including risk assessments, RBAC and agent access control models, and credential governance for AI tools running on local machines and in production
- Design and run business continuity and incident response exercises to pressure-test our resilience, and own annual penetration testing
- Own SOC 2 Type II compliance end-to-end: control design, evidence collection, audit management and remediation tracking, plus starting to get us ready for ISO27001
- Build and maintain compliance automation so evidence gathering and audit readiness scale with the business rather than becoming a manual burden each cycle
- Produce and maintain supporting documentation (e.g. bridge letters, control narratives, RFP cyber-security responses, annual InfoSec policy reviews) for customers, partners and auditors
- Evaluate the security posture of AI tools and agentic platforms adopted across the business (e.g. prompt injection risk, data exfiltration vectors, audit traceability gaps) before they're rolled out
- Define and implement controls and policies for AI tooling
- Partner with engineering teams to establish secure-by-default patterns for building and deploying internal agents and MCP servers
- Partner closely with Technology, People, Legal and Sales to embed security and compliance thinking into the wider business, including client-facing security and compliance content for prospective partners
- Communicate security posture, risk and progress clearly to both technical and non-technical stakeholders, including leadership
Job benefits
- Cash amount of up to 10% of your monthly salary, to cover the cost of buying or leasing an EV
- Equity - you'll own a part of the business through our share options program
- Healthcare options - to help keep you and your family in tip-top condition (provided by Bupa & Medicash)
- Life assurance of 4x your salary
- Co-working access via WeWork (if you'd like it)
- Annual 'Team Week' whole company offsite
- L&D allowance of £1,000 per year - everyone is learning, developing and challenging themselves so we have a professional development fund per year for you to learn new skills
About ev.energy
ev.energy is a private smart-charging software company helping utilities manage EVs and other flexible energy loads.
Visit company websiteApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at ev.energy
Senior Product Engineer
, USA
Senior Data Engineer
, USA
Principal Product Engineer
, USA
Technical Program Manager
, USA
Senior Data Engineer
, CAN
Senior Product Engineer
, GBR
Senior Data Engineer
, GBR
Principal Product Engineer
, GBR