Cyber Risk Lead

Nscale

$180K — $210K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in enterprise security risk management, with experience in risk register and treatment program development.
  • Expertise in risk quantification methodologies like NIST CSF, ISO 27005, or FAIR.
  • Proven track record in driving engineering team remediations, rather than merely recording issues.
  • Proficient with risk data analysis using SQL, scripting, or similar tools.
  • Experience in risk automation and building integrations for scanners, inventories, and GRC platforms.
  • Strong grasp of cloud infrastructure security controls and infrastructure-as-code like Terraform.
  • Background in continuous control monitoring or actuarial risk modeling, particularly in AI and hyperscale environments.

Responsibilities

  • Build and manage a dynamic cyber risk program using technical telemetry for actionable insights.
  • Develop a cyber risk model addressing exposure across technology, data centers, and software supply chains.
  • Model attack scenarios with threat intelligence to prioritize risks effectively.
  • Own the lifecycle of cyber risk treatment, converting risks into measurable engineering tasks.
  • Establish and validate remediation activities that demonstrably reduce cyber risk.
  • Integrate risk into a compliance-as-code platform, ensuring continuous posture monitoring.
  • Report on enterprise risk scenarios and contribute to the development of the GRC program architecture.

Benefits

  • Collaborative and innovative work environment with direct impact on AI infrastructure development.
  • Highly competitive compensation package with performance reviews annually.
  • Opportunity to grow through leading cross-functional initiatives with tailored progression plans.
  • Human-first flexibility that allows autonomy and work-life balance.
Full Job Description
About the Role

We're hiring a Cyber Risk Lead to own enterprise-wide cyber security risk across Nscale's global AI infrastructure and build the risk function from the ground up.

This senior individual contributor role sits at the intersection of risk management, statistical analysis, engineering, and governance. You'll own the cyber risk register, risk treatment, and remediation governance, partnering with control and system owners who execute fixes, the compliance engineering function that provides continuous monitoring, and the enterprise risk team that represents cyber exposure within Nscale's broader enterprise risk register.

We approach risk as an engineering problem. You'll create a dynamic, threat-informed cyber risk program that turns technical telemetry into measured insights and scalable treatment plans, defining how cyber risk is quantified, prioritized, and reduced as Nscale grows.
What you'll be doing

Cyber Risk Engineering & Modeling
  • Build and operate Nscale's continuously measured cyber risk program, transforming technical telemetry into actionable risk insights.
  • Develop and maintain a dynamic cyber risk model that reflects asset exposure across technology, data centers, and software supply chains.
  • Model realistic attack scenarios using threat intelligence, adversary TTPs, historical incidents, and attack path analysis to prioritize risks by likelihood and loss magnitude.
  • Quantify cyber risk using recognized methodologies such as FAIR, NIST SP 800-30, or ISO 27005, adapting them to support engineering decisions rather than compliance reporting.

Risk Treatment & Execution
  • Own the cyber risk treatment lifecycle, translating prioritized risks into actionable engineering work with clear ownership, measurable objectives, and expected risk reduction.
  • Establish measurable risk treatment objectives and engineering service levels.
  • Validate that remediation activities produce demonstrable reductions in cyber risk.
  • Align cyber risk with enterprise risk management through shared taxonomies, scoring models, and reporting that accurately represent enterprise exposure.

Issue Management & Remediation Governance
  • Establish engineering service levels, escalation paths, and governance that drive timely remediation while balancing operational and business priorities.
  • Hold remediation owners accountable for closing risks within agreed service levels.
  • Validate completed remediation through technical evidence rather than administrative closure.
  • Maintain the cyber risk register and closure discipline while control owners resolve identified gaps.

Risk Automation & Continuous Posture
  • Integrate risk into the compliance-as-code platform so posture is continuous and evidence-backed.
  • Apply risk-as-code where it materially improves risk and issue management.
  • Improve the fidelity of cyber risk measurements through engineering automation, analytics, and new data sources.
  • Connect risk, vulnerability, asset, GRC, and engineering workflow data to reduce manual effort and improve visibility.

Program Development & Reporting
  • Report material enterprise risk scenarios using defensible logic and clear, articulate presentations.
  • Provide leadership with measured insights into Nscale's cyber risk posture and treatment progress.
  • Help shape the broader GRC program architecture as it grows.
KPIs
  • Risk register completeness, evidence freshness, and continuous coverage
  • Remediation service-level attainment and reduction in overdue issues
  • High-risk remediation completed within engineering service levels
  • Risks continuously assessed through technical telemetry
About You
  • 8+ years of experience in enterprise security risk management, including building or running a risk register and treatment program.
  • Risk quantification and treatment expertise grounded in a recognized method such as the NIST Cybersecurity Framework, ISO 27005, or FAIR.
  • A track record of driving remediation across engineering teams, not simply logging issues.
  • Comfort working directly with risk data using SQL, scripting, or equivalent tooling to pull and trend risk, vulnerability, and asset data.
  • Experience building risk tooling or automation, including integrations between scanners, asset inventories, GRC platforms, and engineering issue trackers.
  • Ability to use automation and AI-assisted workflows to reduce manual GRC work.
  • Strong understanding of cloud infrastructure and security controls, including the ability to read infrastructure-as-code such as Terraform well enough to assess whether a control is effective.
  • Experience with automation-first risk management, continuous control monitoring, or actuarial approaches to risk modeling.
  • Experience with AI infrastructure, hyperscale, regulated environments, critical infrastructure, data center operations, or sovereign cloud requirements.
  • Relevant certifications such as CISSP or CRISC, and a strong statistics or mathematics background, are advantageous.
What we can offer you

At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.
  • Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.
  • Join one of the fastest-growing AI infrastructure companies - your chance to directly shape how global AI capacity is planned and deployed. •
  • Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy - always with our full support.
  • Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.
Salary Range

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

Salary Range

$180,000-$210,000 USD

Similar Jobs

More Jobs at Nscale

  • Cyber Risk Lead
    $180K — $210K *
    Seattle, WA 98115 (King County)
    Information Technology
    In-Person
  • Cyber Risk Lead
    $180K — $210K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • Cyber Risk Lead
    $180K — $210K *
    Houston, TX 77084 (Harris County)
    Information Technology
    In-Person
  • Cyber Risk Lead
    $180K — $210K *
    San Francisco, CA 94112 (San Francisco County)
    Information Technology
    In-Person
  • Cyber Risk Lead
    $180K — $210K *
    Houston, MN 55943 (Houston County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Cyber Risk Lead jobs: