E

Lead Security & Compliance Analyst (AI-First VPP Platform)

ev.energy • United Kingdom
Remote
Apply
AI Summary

Lead security and compliance strategy for ev.energy’s AI-first EV virtual power plant platform, balancing rapid innovation with robust risk mitigation. Oversee SOC 2 Type II compliance, AI tooling governance, and cross-functional security frameworks while enabling engineering agility. Partner with leadership, legal, and engineering teams to embed security best practices globally.

Key Highlights
Own end-to-end security and compliance strategy for a fast-growing AI-first EV platform with global regulatory exposure
Lead SOC 2 Type II compliance and ISO 27001 readiness, including risk assessments, RBAC, and incident response
Hands-on governance of AI tooling security (e.g., prompt injection, data exfiltration) and agentic systems in production
Key Responsibilities
Define and evolve ev.energy’s security strategy, translating it into policies, controls, and roadmaps for AWS infrastructure, endpoint security, and product security
Lead SOC 2 Type II compliance (control design, evidence collection, audit management) and initiate ISO 27001 preparation
Design security frameworks for AI-first systems, including risk assessments, RBAC for AI agents, and credential governance for local/production AI tools
Conduct annual penetration testing and business continuity/incident response exercises to test resilience
Govern AI tooling security pre-deployment (e.g., prompt injection, data exfiltration) and establish secure-by-default patterns for internal agents
Partner with engineering, legal, and sales teams to embed security/compliance in product development and client-facing communications
Technical Skills Required
AWS Security SOC 2 Compliance AI Security Governance
Benefits & Perks
Salary range: £85,900–£105,200 GBP
Up to 10% monthly salary for EV purchase/lease
Equity through share options program
Healthcare (Bupa & Medicash), life assurance (4x salary), co-working access (WeWork)
Annual Team Week offsite, £1,000 learning & development allowance
Fully remote work with optional co-working support
Nice to Have
OCPP or EV charging infrastructure experience
Critical infrastructure/OT security standards (e.g., NIST IR 7628, UL 2900)
Hands-on SOC 2 Type I/II ownership
Mentorship of engineers in security practices

Job Description


About ev.energy

We are building the world's largest EV-centric virtual power plant (VPP). By connecting to vehicles, chargers, batteries, solar, and other distributed energy resources, we turn households into flexible grid assets that balance supply and demand, preventing blackouts and reducing reliance on fossil fuels.

We are scaling rapidly across North America and Europe. We are moving fast, we are AI-first, and we are looking for builders who want to power the grid of the future.


About the role

Security and compliance are foundational to ev.energy's ability to operate a large-scale, AI-first EV platform and Virtual Power Plant: we handle sensitive data on tens of thousands of EV drivers and chargers, we work globally within regulated utility and enterprise partnerships, and we're adopting AI tooling faster than most companies our size. We're looking for a Lead Security & Compliance Analyst to own security and compliance for the business - setting the strategy, building the frameworks, and making sure the rest of engineering can build fast without introducing unacceptable risk.You'll be a hands-on technical leader: part security architect, part compliance owner, working across our AWS infrastructure, codebase, and an increasingly agentic engineering organisation.


You'll be part of the engineering leadership team and work closely with People, Legal, and every engineering team at ev.energy.


What we're looking for

  • Proven experience leading or working with security and/or compliance for a SaaS or infrastructure business (nice to have: hands-on ownership of a SOC 2 (Type I or II) or similar compliance programme)
  • Strong hands-on knowledge of AWS security tooling and general cloud security best practice
  • Experience assessing and governing AI tooling and/or agentic systems from a security perspective (e.g. prompt injection, data exfiltration, access control for AI agents)
  • Track record of building security frameworks, policies and processes from the ground up in a fast-moving environment
  • Strong written and verbal communication skills, with the ability to influence engineers and leadership alike
  • Experience managing or mentoring engineers
  • Nice to have: experience with OCPP, EV charging infrastructure, or critical infrastructure/OT security standards (e.g. NIST IR 7628, UL 2900)


Who you are

  • You think like an attacker and a builder at the same time; you can identify real risk without becoming a blocker to shipping product
  • You're comfortable owning ambiguous, cross-cutting problems and turning them into clear frameworks, policies and roadmaps
  • You communicate security and compliance concepts clearly to engineers, executives and auditors alike
  • You're genuinely curious about how AI tooling is changing the security landscape, and want to help define what "secure AI-first engineering" looks like in practice
  • You care about enabling the business to move quickly and safely, not compliance for its own sake


What you’ll do

Security strategy & governance

  • Own and evolve ev.energy's overall security strategy, translating it into concrete policies, controls and roadmaps
  • Own endpoint security (our employee laptop estate), infrastructure security, and product security, monitoring and continuously reducing our attack surface
  • Design and run security frameworks for an AI-first organisation, including risk assessments, RBAC and agent access control models, and credential governance for AI tools running on local machines and in production
  • Design and run business continuity and incident response exercises to pressure-test our resilience, and own annual penetration testing

Compliance & audit

  • Own SOC 2 Type II compliance end-to-end: control design, evidence collection, audit management and remediation tracking, plus starting to get us ready for ISO27001
  • Build and maintain compliance automation so evidence gathering and audit readiness scale with the business rather than becoming a manual burden each cycle
  • Produce and maintain supporting documentation (e.g. bridge letters, control narratives, RFP cyber-security responses, annual InfoSec policy reviews) for customers, partners and auditors

AI tooling governance

  • Evaluate the security posture of AI tools and agentic platforms adopted across the business (e.g. prompt injection risk, data exfiltration vectors, audit traceability gaps) before they're rolled out
  • Define and implement controls and policies for AI tooling
  • Partner with engineering teams to establish secure-by-default patterns for building and deploying internal agents and MCP servers

Leadership & cross-functional partnership

  • Partner closely with Technology, People, Legal and Sales to embed security and compliance thinking into the wider business, including client-facing security and compliance content for prospective partners
  • Communicate security posture, risk and progress clearly to both technical and non-technical stakeholders, including leadership


Salary, benefits & how we work

The salary range for this role is £85,900-£105,200 GBP.


Key benefits include:

  • Cash amount of up to 10% of your monthly salary, to cover the cost of buying or leasing an EV
  • Equity - you'll own a part of the business through our share options program
  • Healthcare options - to help keep you and your family in tip-top condition (provided by Bupa & Medicash)
  • Life assurance of 4x your salary
  • Co-working access via WeWork (if you'd like it)
  • Annual 'Team Week' whole company offsite
  • L&D allowance of £1,000 per year - everyone is learning, developing and challenging themselves so we have a professional development fund per year for you to learn new skills

You can find out more about our full range of perks and benefits here.


Location & how we work

This role is fully remote in the UK.

The majority of people at ev.energy work on a fully remote basis, with a small number of roles based on-site in our testing sites.

This means that most of our people work from home, but we're happy to provide co-working subscriptions if you'd like to spend time at a WeWork (or other co-working space close to you).

We balance our remote set up by getting everyone together once a year for an offsite, as we know that spending time together IRL is super important.


Belonging at ev.energy

We are an equal opportunity employer and value diversity: we do not discriminate based on race, religion, colour, national origin, gender, sexual orientation, age, marital status, veteran status or disability status. If you'd like a copy of our DE&I policy you can reach us at [email protected]. We'll always do our best to accommodate reasonable adjustments to the interview process if needed - just let us know.


Similar Jobs

Explore other opportunities that match your interests

Security Operations Analyst (AI Training)

Cyber Security
•
13h ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Not Applicable

Alignerr

United Kingdom

OT Engineer

Cyber Security
•
20h ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

X4 Technology

United Kingdom

Cyber Security Intern (Remote, UK)

Cyber Security
•
1d ago
Visa Sponsorship Relocation Remote
Job Type Internship
Experience Level Not Applicable

staffline solutions

United Kingdom

Subscribe our newsletter

New Things Will Always Update Regularly