Lead Security & Compliance Analyst
IT, Compliance / Regulatory
United Kingdom
Posted on Jul 31, 2026
About ev.energy
We are building the world's largest EV-centric virtual power plant (VPP). By connecting to vehicles, chargers, batteries, solar, and other distributed energy resources, we turn households into flexible grid assets that balance supply and demand, preventing blackouts and reducing reliance on fossil fuels.
We are scaling rapidly across North America and Europe. We are moving fast, we are AI-first, and we are looking for builders who want to power the grid of the future.
About the role
Security and compliance are foundational to ev.energy's ability to operate a large-scale, AI-first EV platform and Virtual Power Plant: we handle sensitive data on tens of thousands of EV drivers and chargers, we work globally within regulated utility and enterprise partnerships, and we're adopting AI tooling faster than most companies our size. We're looking for a Lead Security & Compliance Analyst to own security and compliance for the business - setting the strategy, building the frameworks, and making sure the rest of engineering can build fast without introducing unacceptable risk.You'll be a hands-on technical leader: part security architect, part compliance owner, working across our AWS infrastructure, codebase, and an increasingly agentic engineering organisation.
You'll be part of the engineering leadership team and work closely with People, Legal, and every engineering team at ev.energy.
Who you are
We are building the world's largest EV-centric virtual power plant (VPP). By connecting to vehicles, chargers, batteries, solar, and other distributed energy resources, we turn households into flexible grid assets that balance supply and demand, preventing blackouts and reducing reliance on fossil fuels.
We are scaling rapidly across North America and Europe. We are moving fast, we are AI-first, and we are looking for builders who want to power the grid of the future.
About the role
Security and compliance are foundational to ev.energy's ability to operate a large-scale, AI-first EV platform and Virtual Power Plant: we handle sensitive data on tens of thousands of EV drivers and chargers, we work globally within regulated utility and enterprise partnerships, and we're adopting AI tooling faster than most companies our size. We're looking for a Lead Security & Compliance Analyst to own security and compliance for the business - setting the strategy, building the frameworks, and making sure the rest of engineering can build fast without introducing unacceptable risk.You'll be a hands-on technical leader: part security architect, part compliance owner, working across our AWS infrastructure, codebase, and an increasingly agentic engineering organisation.
You'll be part of the engineering leadership team and work closely with People, Legal, and every engineering team at ev.energy.
- Proven experience leading or working with security and/or compliance for a SaaS or infrastructure business (nice to have: hands-on ownership of a SOC 2 (Type I or II) or similar compliance programme)
- Strong hands-on knowledge of AWS security tooling and general cloud security best practice
- Experience assessing and governing AI tooling and/or agentic systems from a security perspective (e.g. prompt injection, data exfiltration, access control for AI agents)
- Track record of building security frameworks, policies and processes from the ground up in a fast-moving environment
- Strong written and verbal communication skills, with the ability to influence engineers and leadership alike
- Experience managing or mentoring engineers
- Nice to have: experience with OCPP, EV charging infrastructure, or critical infrastructure/OT security standards (e.g. NIST IR 7628, UL 2900)
Who you are
- You think like an attacker and a builder at the same time; you can identify real risk without becoming a blocker to shipping product
- You're comfortable owning ambiguous, cross-cutting problems and turning them into clear frameworks, policies and roadmaps
- You communicate security and compliance concepts clearly to engineers, executives and auditors alike
- You're genuinely curious about how AI tooling is changing the security landscape, and want to help define what "secure AI-first engineering" looks like in practice
- You care about enabling the business to move quickly and safely, not compliance for its own sake
- Own and evolve ev.energy's overall security strategy, translating it into concrete policies, controls and roadmaps
- Own endpoint security (our employee laptop estate), infrastructure security, and product security, monitoring and continuously reducing our attack surface
- Design and run security frameworks for an AI-first organisation, including risk assessments, RBAC and agent access control models, and credential governance for AI tools running on local machines and in production
- Design and run business continuity and incident response exercises to pressure-test our resilience, and own annual penetration testing
- Own SOC 2 Type II compliance end-to-end: control design, evidence collection, audit management and remediation tracking, plus starting to get us ready for ISO27001
- Build and maintain compliance automation so evidence gathering and audit readiness scale with the business rather than becoming a manual burden each cycle
- Produce and maintain supporting documentation (e.g. bridge letters, control narratives, RFP cyber-security responses, annual InfoSec policy reviews) for customers, partners and auditors
- Evaluate the security posture of AI tools and agentic platforms adopted across the business (e.g. prompt injection risk, data exfiltration vectors, audit traceability gaps) before they're rolled out
- Define and implement controls and policies for AI tooling
- Partner with engineering teams to establish secure-by-default patterns for building and deploying internal agents and MCP servers
- Partner closely with Technology, People, Legal and Sales to embed security and compliance thinking into the wider business, including client-facing security and compliance content for prospective partners
- Communicate security posture, risk and progress clearly to both technical and non-technical stakeholders, including leadership