Volta is a French–Italian AI-powered platform that digitises and automates B2B sales operations for suppliers and distributors.
ABOUT THE ROLE The Security Engineer, Compliance Focus works as part of Volta's security engineering team, with primary ownership of compliance engineering — turning manual, evidence-gathering compliance work into automated, durable platform capability. You will own the tooling and processes that continuously collect, validate, and surface the evidence Volta needs to demonstrate security and compliance posture across a fast-growing, multi-jurisdiction infrastructure fleet. This is a build-first role within security engineering: rather than managing compliance through spreadsheets and manual audits, you will work with the broader security and platform engineering teams to embed compliance evidence collection directly into the infrastructure stack, so proof of control effectiveness is a byproduct of how the platform runs — not a separate, recurring effort. WHAT YOU WILL BE DOING - Own the design and automation of evidence collection for security and compliance controls across Volta's infrastructure - Build tooling that continuously and automatically gathers, validates, and organises compliance evidence from platform, network, and infrastructure systems - Partner with the wider security engineering team to translate control requirements and audit frameworks into automated, testable checks - Work with platform engineering to embed compliance evidence collection into Kubernetes operators, CI/CD pipelines, and infrastructure automation - Reduce manual audit burden by replacing point-in-time evidence gathering with continuous, always-current compliance state - Own compliance tooling roadmap and prioritisation within security engineering, balancing near-term audit needs with longer-term platform investment - Support external audits and certifications by ensuring evidence is accurate, complete, and readily accessible - Track and report on compliance posture and control coverage across the fleet as it scales into new sites and jurisdictions - Identify gaps in current compliance automation and lead the engineering effort to close them - Collaborate with legal, risk, and external auditors as needed to align technical evidence with regulatory and contractual requirements WHAT YOU BRING - Strong software engineering background, with experience building automation, tooling, or backend services in a production environment - Experience working within or closely with a security or compliance function, ideally in an infrastructure or cloud environment - Familiarity with common compliance frameworks (e.g. SOC 2, ISO 27001, or equivalent) and what "evidence" means in an audit context - Comfortable working close to infrastructure systems — Kubernetes, cloud/data centre environments, and CI/CD pipelines - Track record turning manual, recurring processes into automated, scalable systems - Strong communication skills — able to work across security, engineering, legal, and audit stakeholders - Self-directed, with the judgement to prioritise across audit deadlines and longer-term platform investment NICE TO HAVE - Direct experience in a compliance-focused security engineering role - Familiarity with policy-as-code or automated control-testing frameworks - Experience supporting audits for infrastructure or data centre businesses specifically - Exposure to multi-jurisdiction regulatory requirements (UK, EU, US) - Background in broader security engineering beyond compliance-specific work